W3C home > Mailing lists > Public > public-web-security@w3.org > December 2009

Re: What is the same-origin policy for (was Re: The Origin header)

From: Ian Hickson <ian@hixie.ch>
Date: Mon, 7 Dec 2009 07:28:06 +0000 (UTC)
To: "sird@rckc.at" <sird@rckc.at>
Cc: Devdatta <dev.akhawe@gmail.com>, public-web-security@w3.org
Message-ID: <Pine.LNX.4.62.0912070727240.5629@hixie.dreamhostps.com>
On Mon, 7 Dec 2009, sird@rckc.at wrote:
> 
> a.example.com/mozbind.html
> 
> or
> 
> b.example.net/binding.xml

Both. a.example.com/mozbind.html has to reference 
b.example.net/binding.xml, and b.example.net/binding.xml has to opt-in to 
supporting a.example.com.

-- 
Ian Hickson               U+1047E                )\._.,--....,'``.    fL
http://ln.hixie.ch/       U+263A                /,   _.. \   _\  ;`._ ,.
Things that are impossible just take longer.   `._.-(,_..'--(,_..'`-.;.'
Received on Monday, 7 December 2009 07:28:42 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Sunday, 19 December 2010 00:16:01 GMT