Featured post
firefox - Is it possible (with user permission) to do cross site requests with JavaScript in a webpage in the same way as you would do in an extension? -
google release pc , os. you'll able code machine browser technologies - i.e. javascript. expect tools available already.
on web javascript has same origin policy prevent xss attacks. in extensions free wander around.
so question is: can write page or (if prefer) online app authorized (after user confirmation, of course) cross site requests feels needed? know possible when write extension, i'd prefer doesn't stick in user's browser. [edit] know there solutions if have control of both sites involved. i'm asking if possible access, instance, google or yahoo apis: sites i've no control over.
for instance want write frontend api (rest, json, xml: not script tag, cross-site compatible api): need host somewhere (a different host api provider) need make unrestricted calls domain , read responses too. understand security risks, i'm talking asking user's permission first (as when install extensions).
if need have browser , server agree access data can cors: http://www.w3.org/tr/cors
https://developer.mozilla.org/en/http_access_control
basically add header on server on requests tells browser server aware of cross origin , ok it.
it surprisingly simple. there few gotchas. 1 being so-called preflight dialog browser , server engage in when there non-standard header. frameworks insert such header triggers dialog. means in practise need server add cors headers responses including options header!
if you later mention, want request privileges user bypass security restrictions, need signed scripts: http://www.mozilla.org/projects/security/components/signed-scripts.html
- Get link
- X
- Other Apps
Comments
Post a Comment