November 2011
Intermediate to advanced
320 pages
10h 18m
English
This concludes our overview of the basic security policies and consent isolation mechanisms. If there is one observation to be made, it’s that most of these mechanisms depend on the availability of a well-formed, canonical hostname from which to derive the context for all the subsequent operations. But what if this information is not available or is not presented in the expected form?
Well, that’s when things get funny. Let’s have a look at some of the common corner cases, even if just for fleeting amusement.
Due to the failure to account for IP addresses when designing HTTP cookies and the same-origin policy, almost all browsers have historically permitted documents loaded from, say, http://1.2.3.4/ ...
Read now
Unlock full access