Re: [XHR][XHR2] Same-origin policy protection

On 6/15/11 4:08 PM, David Bruant wrote:
>>>> 2)  XHR in the web browser gives (at the moment, at least) sites that are outside a firewall that your browser is behind the ability to make requests to hosts that are behind the firewall.

> You wrote "at the moment, at least". Is there some planned change that
> could question this?

Perhaps.  There are issues that arise with firewalled intranets even in 
the absence of XHR, so there is ongoing work to put other mitigations in 
place too.  https://bugzilla.mozilla.org/show_bug.cgi?id=354493 for example.

-Boris

Received on Wednesday, 15 June 2011 20:16:04 UTC