Alex Rivera | Logout

What is the rationale behind AJAX cross-domain security?

Asked 2012-05-30T17:03:38.887
8

Given the simplicity of writing a server side proxy that fetches data across domains, I'm at a loss as to what the initial intention was in preventing client side AJAX from making calls across domains. I'm not asking for speculation, I'm looking for documentation from the language designers (or people close to them) for what they thought they were doing, other than simply creating a mild inconvenience for developers.

TIA

Edit
Report

1 Answer

2

If you're the author for myblog.com and you make an XHR to facebook.com, should the request send your facebook cookie credentials? No, that would mean that you could request users' private facebook information from your blog.

If you create a proxy service to do it, your proxy can't access the facebook cookies.

You may also be questioning why JSONP is OK. The reason is that you're loading a script you didn't write, so unless facebook's script decides to send you the information from their JS code, you won't have access to it

answered 2012-05-30T17:14:16.213

Your Answer