官术网_书友最值得收藏!

  • CORS Essentials
  • Rajesh Gunasundaram Randall Goya
  • 156字
  • 2021-07-09 19:53:41

Permissions required by JavaScript

Let's consider content scraping. You can write a content scraping script that reads the rendered DOM of an external URI and creates local DOM elements with the same content, without any special configurations.

But what if you first need to run a script on the external URI, for example, to find out whether the user is the same as on your local site? You cannot trigger that external script and return the results without cross-origin sharing via CORS or a similar method to get around the same-origin policy.

JavaScript data storage access is strictly limited by origin

JavaScript data stored in the browser as Local Storage, or in IndexedDB, is separated by origin. Each origin has distinct storage, and JavaScript in one origin cannot read from or written to storage belonging to another origin unless it is given explicit access to a script on another domain by CORS or a similar method.

主站蜘蛛池模板: 荣昌县| 巧家县| 嘉定区| 渝北区| 新竹市| 江都市| 五常市| 蓝田县| 武穴市| 双峰县| 临城县| 任丘市| 泾源县| 郯城县| 托里县| 靖安县| 佛坪县| 台州市| 江达县| 肥西县| 若尔盖县| 井研县| 黑河市| 枣阳市| 子长县| 永州市| 临潭县| 保定市| 瓦房店市| 广丰县| 汕尾市| 通城县| 新化县| 罗田县| 灵璧县| 天长市| 满城县| 察隅县| 张掖市| 米脂县| 寿阳县|