W3C home > Mailing lists > Public > public-webapi@w3.org > September 2007

Re: XHR: definition of same-origin

From: Boris Zbarsky <bzbarsky@MIT.EDU>
Date: Fri, 21 Sep 2007 09:40:39 -0500
Message-ID: <46F3D7E7.7060206@mit.edu>
To: Anne van Kesteren <annevk@opera.com>
CC: "Web API WG (public)" <public-webapi@w3.org>

Anne van Kesteren wrote:
> I think HTML5 needs to define this as my understanding is that 
> document.domain is also relevant in deciding whether or not a request is 
> same-origin.

Actually, I don't think it is.  I know IE and Gecko ignore document.domain for 
the existing same-origin checks...  Gecko used to take it into account, but of 
course that broke sites given that IE ignores it.

-Boris
Received on Friday, 21 September 2007 14:41:12 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Tuesday, 8 January 2008 14:18:58 GMT