Web App
Taxonomy
data:image/s3,"s3://crabby-images/34ae4/34ae4ab8ed1739dccd372fb0e0d0be4671873dad" alt="Client-side Static
Mash-up"
- Commonly known as "widgets"
- Require a separate
"download" step before runtime
- Trust often established between
widget and widget platform (by means of crypto signatures)
- Trust
often proxied by use of an "app-store" model
data:image/s3,"s3://crabby-images/4e266/4e26680fe7379f1377b0f8fef64a013ea75763e7" alt="Server-side Static
Mash-up"
- Widgets on the server-side
- No separate download
step, but often requires installation of content to a "container"
- One
website combines content from multiple other websites, often by means
of iFrames
- External content validated statically by (for
example) Caja, FBJS
- DNS-based trust, proxied by "container" site
data:image/s3,"s3://crabby-images/44269/4426992dc65fc3ced5e6e44b2c5e68f3b2b344c5" alt="Client-side Dynamic
Mash-up"
- One site creates content which includes requests for
content to other sites, or for information provided by the client
- Content
is assembled dynamically on the client, based on content from multiple
places
- Trust based on a combination of "user grant", enforcement
of restrictions such as SOP, and other techniques (CORS, UMP, OAuth et
al)