W3C home > Mailing lists > Public > whatwg@whatwg.org > April 2012

[whatwg] File based permission files?

From: Tyler Larson <talltyler@gmail.com>
Date: Wed, 25 Apr 2012 16:01:26 -0400
Message-ID: <66A1F54C-0040-4E44-80FA-198B22296113@gmail.com>
> You can do cross-domain permission via IFRAME and postMessage.
> Now that transfer semantics are widely accepted, you can efficiently send an array buffer across frames.
> 
> So you setup something like trampoline.html, you connect to it via iframe and send it a message, then trampoline.html does an XHR request (in its own domain) and sends back the data.
> It's better than a .xml file because it's scriptable.
> 
> -Charles
> 

Good to know, I haven't used this before but it still seems to be intended for a different use case. 
I'm basing my knowledge on write ups like this, https://developer.mozilla.org/en/DOM/window.postMessage
>From my understanding the pixel data would need to be loaded into the iframes page, that page would then get the pixel data and post that data back so that I could then use it.

I can get around my issue a bunch of different ways and people will be forced to create all forms of hacks and proxy servers to make their applications work but based on the things I have seen, what you are suggesting is far more complicated than a standard crossdomain.xml setup. Setting something up once and moving on, rather than needing to script a communication layer between what files you want to load and sending that information across a messing system. 

I still think that my proposal is valid. 
Lets say I am building anything using the canvas that loads images from anywhere else on the internet and then wants to manipulate them. 
If javascript used the same setup, a crossdomain.xml file would be loaded without the developer needing to do anything as soon as they requested something that needed the permissions. An event would be fired if this you tried to do something that you didn't have permissions to do, otherwise everything would just work. 

The current COR setup is also transparent which I like, what I don't like about it is simply that system admins will fight needing to reconfigure their servers to add these headers leaving developers unable to use these features. If we make use of the security files already in place we can get going on canvas based image manipulation today without anyone needing to change anything.  

-Tyler Larson
Received on Wednesday, 25 April 2012 13:01:26 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Wednesday, 30 January 2013 18:48:07 GMT