Alex Rivera | Logout

Is it safe to use $.support.cors = true; in jQuery?

Asked 2011-10-21T16:10:59.020
52

I was trying to hit a web service on a different domain using jQuery's ajax method. After doing some research it looks like it does not allow this is by design to prevent cross site scripting.

I came across a work around which was to include this line:

$.support.cors = true;

at the top of my javascript code. From what I understand this enables cross site scripting in jQuery.

Does having this line of code make my site more vulnerable to attack? I've always heard XSS discussed as a security issue, are there legitimate uses for XSS?

Edit
Report

1 Answer

11

It can help only if you have CORS enabled in your browser but it isn't supported by jQuery yet:

To enable cross-domain requests in environments that do not support cors yet but do allow cross-domain XHR requests (windows gadget, etc), set $.support.cors = true;. CORS WD

Just setting this property to true can't cause security vulnerability.

answered 2011-10-21T16:23:40.637

Your Answer