Skip to Content
JavaScript® Programmer's Reference
book

JavaScript® Programmer's Reference

by Alexei White
August 2009
Intermediate to advanced
1030 pages
21h 39m
English
Wrox
Content preview from JavaScript® Programmer's Reference

Chapter 17. JavaScript Security

The browser is one of the most rigidly controlled development environments you can imagine. It has to be this way. Neither Microsoft nor Netscape really ever trusted the web. They also know that if users ever develop a legitimate fear of surfing for what a web page could do to their computer, that browser would be dumped faster than you can say "Firefox." In an intense browser war that's lasted for a decade, it's natural for vendors to be cautious about rolling out new features and capabilities. No wonder it took years for Ajax to take off. Still, the browser has a long and unfortunate history of security holes that for a long time gave JavaScript a bad reputation, partly deserved, partly wrongly attributed. There's some stability now, but the rules for developers are constantly changing. Mostly these changes are subtle refinements to a fairly coherent security policy that has been adopted more or less across the board. This chapter introduces the main issues in browser-based JavaScript security, including the Same Origin Policy, signed scripts, policies and zones, and miscellaneous other issues to be aware of.

Security Models

For any embedded scripting technology in a web page like Flash, Silverlight, or JavaScript, the vendor does a balancing act between freedom for the developer (and consequently for the user) and security. There are two ways to go with it too: Either warn the user every single time a page uses scripting, or just limit the functionality ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Speaking JavaScript

Speaking JavaScript

Axel Rauschmayer
Dojo: The Definitive Guide

Dojo: The Definitive Guide

Matthew A. Russell
Web Developer's Reference Guide

Web Developer's Reference Guide

Joshua Johanan, Talha Khan, Ricardo Zea

Publisher Resources

ISBN: 9780470344729Purchase book