November 2011
Intermediate to advanced
320 pages
10h 18m
English
Although this chapter has focused on areas where the limitations of the same-origin policy have a clear, negative impact on the security or privacy of online browsing, there are several accidental gaps in the scheme that in most cases seem to be of no special consequence. For example, in many versions of Internet Explorer, it was possible to manipulate the value of window.opener or window.name of an unrelated window. Meanwhile in Firefox, there are currently no constraints on setting location.hash across domains, even though all other partial location properties are restricted.
The primary significance of these mechanisms is that they are often repurposed to build cross-domain communication channels in browsers ...
Read now
Unlock full access