<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>12182</bug_id>
          
          <creation_ts>2007-01-09 05:37:42 -0800</creation_ts>
          <short_desc>XMLHttpRequest should raise SECURITY_ERR for same-origin policy violations</short_desc>
          <delta_ts>2008-03-10 09:26:39 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>XML</component>
          <version>420+</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.4</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://www.w3.org/TR/XMLHttpRequest/#security-err</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Alexey Proskuryakov">ap</reporter>
          <assigned_to name="Julien Chaffraix">jchaffraix</assigned_to>
          
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>36088</commentid>
    <comment_count>0</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2007-01-09 05:37:42 -0800</bug_when>
    <thetext>Currently, we raise our own exception; the draft now specifies that SECURITY_ERR should be raised.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>65960</commentid>
    <comment_count>1</comment_count>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2008-01-01 16:29:40 -0800</bug_when>
    <thetext>http://www.w3.org/TR/XMLHttpRequest/#security-err</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72498</commentid>
    <comment_count>2</comment_count>
      <attachid>19484</attachid>
    <who name="Julien Chaffraix">jchaffraix</who>
    <bug_when>2008-03-02 10:12:26 -0800</bug_when>
    <thetext>Created attachment 19484
First version</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72528</commentid>
    <comment_count>3</comment_count>
      <attachid>19484</attachid>
    <who name="Darin Adler">darin</who>
    <bug_when>2008-03-02 18:31:54 -0800</bug_when>
    <thetext>Comment on attachment 19484
First version

r=me</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>73204</commentid>
    <comment_count>4</comment_count>
    <who name="Darin Adler">darin</who>
    <bug_when>2008-03-10 09:26:39 -0700</bug_when>
    <thetext>Committed revision 30932.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>19484</attachid>
            <date>2008-03-02 10:12:26 -0800</date>
            <delta_ts>2008-03-02 18:31:54 -0800</delta_ts>
            <desc>First version</desc>
            <filename>bug12182-ready.patch</filename>
            <type>text/plain</type>
            <size>5431</size>
            <attacher name="Julien Chaffraix">jchaffraix</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL0NoYW5nZUxvZyBiL0xheW91dFRlc3RzL0NoYW5nZUxv
ZwppbmRleCBjZmRmNmQwLi42NTE3Njk4IDEwMDY0NAotLS0gYS9MYXlvdXRUZXN0cy9DaGFuZ2VM
b2cKKysrIGIvTGF5b3V0VGVzdHMvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTMgQEAKKzIwMDgtMDMt
MDIgIEp1bGllbiBDaGFmZnJhaXggIDxqdWxpZW4uY2hhZmZyYWl4QGdtYWlsLmNvbT4KKworICAg
ICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBidWcgMTIxODIgOiBY
TUxIdHRwUmVxdWVzdCBzaG91bGQgcmFpc2UgU0VDVVJJVFlfRVJSIGZvciBzYW1lLW9yaWdpbiBw
b2xpY3kgdmlvbGF0aW9ucworCisgICAgICAgICogaHR0cC90ZXN0cy94bWxodHRwcmVxdWVzdC9l
eGNlcHRpb25zLWV4cGVjdGVkLnR4dDogVXBkYXRlZCByZXN1bHRzCisKIDIwMDgtMDMtMDEgIE9s
aXZlciBIdW50ICA8b2xpdmVyQGFwcGxlLmNvbT4KIAogICAgICAgICBSZXZpZXdlZCBieSBTYW0g
V2VpbmlnLgpkaWZmIC0tZ2l0IGEvTGF5b3V0VGVzdHMvaHR0cC90ZXN0cy94bWxodHRwcmVxdWVz
dC9leGNlcHRpb25zLWV4cGVjdGVkLnR4dCBiL0xheW91dFRlc3RzL2h0dHAvdGVzdHMveG1saHR0
cHJlcXVlc3QvZXhjZXB0aW9ucy1leHBlY3RlZC50eHQKaW5kZXggNmIzNGY5Ny4uMmRiMjA4NyAx
MDA2NDQKLS0tIGEvTGF5b3V0VGVzdHMvaHR0cC90ZXN0cy94bWxodHRwcmVxdWVzdC9leGNlcHRp
b25zLWV4cGVjdGVkLnR4dAorKysgYi9MYXlvdXRUZXN0cy9odHRwL3Rlc3RzL3htbGh0dHByZXF1
ZXN0L2V4Y2VwdGlvbnMtZXhwZWN0ZWQudHh0CkBAIC0zLDcgKzMsNyBAQCBUZXN0IHRoYXQgWE1M
SHR0cFJlcXVlc3QgcmFpc2VzIGV4Y2VwdGlvbnMgd2hlbiBpdCBzaG91bGQuCiBuZXcgWE1MSHR0
cFJlcXVlc3QoKQogUEFTUzogcmVxLnNldFJlcXVlc3RIZWFkZXIoIkZvbyIsICJiYXIiKSB0aHJl
dyBleGNlcHRpb24gRXJyb3I6IElOVkFMSURfU1RBVEVfRVJSOiBET00gRXhjZXB0aW9uIDExLgog
UEFTUzogcmVxLnNlbmQobnVsbCkgdGhyZXcgZXhjZXB0aW9uIEVycm9yOiBJTlZBTElEX1NUQVRF
X0VSUjogRE9NIEV4Y2VwdGlvbiAxMS4KLVBBU1M6IHJlcS5vcGVuKCJHRVQiLCAiaHR0cDovL3d3
dy5hcHBsZS5jb20vIiwgdHJ1ZSkgdGhyZXcgZXhjZXB0aW9uIEVycm9yOiBQZXJtaXNzaW9uIGRl
bmllZC4KK1BBU1M6IHJlcS5vcGVuKCJHRVQiLCAiaHR0cDovL3d3dy5hcHBsZS5jb20vIiwgdHJ1
ZSkgdGhyZXcgZXhjZXB0aW9uIEVycm9yOiBTRUNVUklUWV9FUlI6IERPTSBFeGNlcHRpb24gMTgu
CiBvcGVuKCkKIFBBU1M6IHJlcS5zZXRSZXF1ZXN0SGVhZGVyKCkgdGhyZXcgZXhjZXB0aW9uIFN5
bnRheEVycm9yOiBOb3QgZW5vdWdoIGFyZ3VtZW50cy4KIFBBU1M6IHJlcS5zZXRSZXF1ZXN0SGVh
ZGVyKCJGb28iKSB0aHJldyBleGNlcHRpb24gU3ludGF4RXJyb3I6IE5vdCBlbm91Z2ggYXJndW1l
bnRzLgpkaWZmIC0tZ2l0IGEvV2ViQ29yZS9DaGFuZ2VMb2cgYi9XZWJDb3JlL0NoYW5nZUxvZwpp
bmRleCBlOTE5NTVkLi5lNzFkOThlIDEwMDY0NAotLS0gYS9XZWJDb3JlL0NoYW5nZUxvZworKysg
Yi9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDI1IEBACisyMDA4LTAzLTAyICBKdWxpZW4g
Q2hhZmZyYWl4ICA8anVsaWVuLmNoYWZmcmFpeEBnbWFpbC5jb20+CisKKyAgICAgICAgUmV2aWV3
ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAgICAgICAgYnVnIDEyMTgyIDogWE1MSHR0cFJlcXVl
c3Qgc2hvdWxkIHJhaXNlIFNFQ1VSSVRZX0VSUiBmb3Igc2FtZS1vcmlnaW4gcG9saWN5IHZpb2xh
dGlvbnMKKworICAgICAgICBSZW1vdmVkIHJlZmVyZW5jZSB0byBQRVJNSVNTSU9OX0RFTklFRCAo
cHJldmlvdXMgbm9uIHN0YW5kYXJkIGV4Y2VwdGlvbikgYW5kIHJlcGxhY2VkIGl0CisgICAgICAg
IGJ5IERPTSBleGNlcHRpb24gU0VDVVJJVFlfRVJSLiBVcGRhdGVkIFhNTEh0dHBSZXF1ZXN0Ojpv
cGVuIHRvIHJhaXNlIFNFQ1VSSVRZX0VSUi4KKworICAgICAgICAqIGJpbmRpbmdzL2pzL2tqc19i
aW5kaW5nLmNwcDogUmVtb3ZlZCBQRVJNSVNTSU9OX0VSUiBjb2RlCisgICAgICAgIChXZWJDb3Jl
OjpzZXRET01FeGNlcHRpb24pOgorICAgICAgICAqIGRvbS9FeGNlcHRpb25Db2RlLmNwcDoKKyAg
ICAgICAgKFdlYkNvcmU6Oik6IEFkZGVkIFNFQ1VSSVRZX0VSUiBleGNlcHRpb24uCisgICAgICAg
ICogZG9tL0V4Y2VwdGlvbkNvZGUuaDoKKyAgICAgICAgKFdlYkNvcmU6Oik6IERpdHRvLgorICAg
ICAgICAqIHhtbC9YTUxIdHRwUmVxdWVzdC5jcHA6CisgICAgICAgIChXZWJDb3JlOjpYTUxIdHRw
UmVxdWVzdDo6b3Blbik6IFJldHVybnMgU0VDVVJJVFlfRVJSIG5vdworICAgICAgICAqIHhtbC9Y
TUxIdHRwUmVxdWVzdEV4Y2VwdGlvbi5oOgorCiAyMDA4LTAzLTAxICBNYXJrIFJvd2UgIDxtcm93
ZUBhcHBsZS5jb20+CiAKICAgICAgICAgUmV2aWV3ZWQgYnkgVGltIEhhdGNoZXIuCmRpZmYgLS1n
aXQgYS9XZWJDb3JlL2JpbmRpbmdzL2pzL2tqc19iaW5kaW5nLmNwcCBiL1dlYkNvcmUvYmluZGlu
Z3MvanMva2pzX2JpbmRpbmcuY3BwCmluZGV4IDU4NTVjYTAuLmRlNWI0NTUgMTAwNjQ0Ci0tLSBh
L1dlYkNvcmUvYmluZGluZ3MvanMva2pzX2JpbmRpbmcuY3BwCisrKyBiL1dlYkNvcmUvYmluZGlu
Z3MvanMva2pzX2JpbmRpbmcuY3BwCkBAIC0zMDEsMTIgKzMwMSw2IEBAIHZvaWQgc2V0RE9NRXhj
ZXB0aW9uKEV4ZWNTdGF0ZSogZXhlYywgRXhjZXB0aW9uQ29kZSBlYykKICAgICBpZiAoIWVjIHx8
IGV4ZWMtPmhhZEV4Y2VwdGlvbigpKQogICAgICAgICByZXR1cm47CiAKLSAgICAvLyBUbyBiZSBy
ZW1vdmVkOiBTZWUgWE1MSHR0cFJlcXVlc3QuaC4KLSAgICBpZiAoZWMgPT0gWE1MSHR0cFJlcXVl
c3RFeGNlcHRpb246OlBFUk1JU1NJT05fREVOSUVEKSB7Ci0gICAgICAgIHRocm93RXJyb3IoZXhl
YywgR2VuZXJhbEVycm9yLCAiUGVybWlzc2lvbiBkZW5pZWQiKTsKLSAgICAgICAgcmV0dXJuOwot
ICAgIH0KLQogICAgIEV4Y2VwdGlvbkNvZGVEZXNjcmlwdGlvbiBkZXNjcmlwdGlvbjsKICAgICBn
ZXRFeGNlcHRpb25Db2RlRGVzY3JpcHRpb24oZWMsIGRlc2NyaXB0aW9uKTsKIApkaWZmIC0tZ2l0
IGEvV2ViQ29yZS9kb20vRXhjZXB0aW9uQ29kZS5jcHAgYi9XZWJDb3JlL2RvbS9FeGNlcHRpb25D
b2RlLmNwcAppbmRleCBlN2VlMjBkLi5mYTBhN2E3IDEwMDY0NAotLS0gYS9XZWJDb3JlL2RvbS9F
eGNlcHRpb25Db2RlLmNwcAorKysgYi9XZWJDb3JlL2RvbS9FeGNlcHRpb25Db2RlLmNwcApAQCAt
NTcsNyArNTcsOCBAQCBzdGF0aWMgY29uc3QgY2hhciogY29uc3QgZXhjZXB0aW9uTmFtZXNbXSA9
IHsKICAgICAiTkFNRVNQQUNFX0VSUiIsCiAgICAgIklOVkFMSURfQUNDRVNTX0VSUiIsCiAgICAg
IlZBTElEQVRJT05fRVJSIiwKLSAgICAiVFlQRV9NSVNNQVRDSF9FUlIiCisgICAgIlRZUEVfTUlT
TUFUQ0hfRVJSIiwKKyAgICAiU0VDVVJJVFlfRVJSIgogfTsKIAogc3RhdGljIGNvbnN0IGNoYXIq
IGNvbnN0IHJhbmdlRXhjZXB0aW9uTmFtZXNbXSA9IHsKZGlmZiAtLWdpdCBhL1dlYkNvcmUvZG9t
L0V4Y2VwdGlvbkNvZGUuaCBiL1dlYkNvcmUvZG9tL0V4Y2VwdGlvbkNvZGUuaAppbmRleCA3ZTc1
NTg3Li5iZGZhNGIzIDEwMDY0NAotLS0gYS9XZWJDb3JlL2RvbS9FeGNlcHRpb25Db2RlLmgKKysr
IGIvV2ViQ29yZS9kb20vRXhjZXB0aW9uQ29kZS5oCkBAIC00OCw3ICs0OCwxMCBAQCBuYW1lc3Bh
Y2UgV2ViQ29yZSB7CiAKICAgICAgICAgLy8gSW50cm9kdWNlZCBpbiBET00gTGV2ZWwgMzoKICAg
ICAgICAgVkFMSURBVElPTl9FUlIgPSAxNiwKLSAgICAgICAgVFlQRV9NSVNNQVRDSF9FUlIgPSAx
NworICAgICAgICBUWVBFX01JU01BVENIX0VSUiA9IDE3LAorCisgICAgICAgIC8vIFhNTEh0dHBS
ZXF1ZXN0IGV4dGVuc2lvbjoKKyAgICAgICAgU0VDVVJJVFlfRVJSID0gMTgKICAgICB9OwogCiAg
ICAgZW51bSBFeGNlcHRpb25UeXBlIHsKZGlmZiAtLWdpdCBhL1dlYkNvcmUveG1sL1hNTEh0dHBS
ZXF1ZXN0LmNwcCBiL1dlYkNvcmUveG1sL1hNTEh0dHBSZXF1ZXN0LmNwcAppbmRleCBmY2FhMzdk
Li40YWY2ZjRkIDEwMDY0NAotLS0gYS9XZWJDb3JlL3htbC9YTUxIdHRwUmVxdWVzdC5jcHAKKysr
IGIvV2ViQ29yZS94bWwvWE1MSHR0cFJlcXVlc3QuY3BwCkBAIC0zMzIsNyArMzMyLDcgQEAgdm9p
ZCBYTUxIdHRwUmVxdWVzdDo6b3Blbihjb25zdCBTdHJpbmcmIG1ldGhvZCwgY29uc3QgS1VSTCYg
dXJsLCBib29sIGFzeW5jLCBFeGMKICAgICBBU1NFUlQobV9zdGF0ZSA9PSBVbmluaXRpYWxpemVk
KTsKIAogICAgIGlmICghdXJsTWF0Y2hlc0RvY3VtZW50RG9tYWluKHVybCkpIHsKLSAgICAgICAg
ZWMgPSBYTUxIdHRwUmVxdWVzdEV4Y2VwdGlvbjo6UEVSTUlTU0lPTl9ERU5JRUQ7CisgICAgICAg
IGVjID0gU0VDVVJJVFlfRVJSOwogICAgICAgICByZXR1cm47CiAgICAgfQogCkBAIC0zNDUsNyAr
MzQ1LDcgQEAgdm9pZCBYTUxIdHRwUmVxdWVzdDo6b3Blbihjb25zdCBTdHJpbmcmIG1ldGhvZCwg
Y29uc3QgS1VSTCYgdXJsLCBib29sIGFzeW5jLCBFeGMKICAgICBTdHJpbmcgbWV0aG9kVXBwZXIo
bWV0aG9kLnVwcGVyKCkpOwogICAgIAogICAgIGlmIChtZXRob2RVcHBlciA9PSAiVFJBQ0UiIHx8
IG1ldGhvZFVwcGVyID09ICJUUkFDSyIgfHwgbWV0aG9kVXBwZXIgPT0gIkNPTk5FQ1QiKSB7Ci0g
ICAgICAgIGVjID0gWE1MSHR0cFJlcXVlc3RFeGNlcHRpb246OlBFUk1JU1NJT05fREVOSUVEOwor
ICAgICAgICBlYyA9IFNFQ1VSSVRZX0VSUjsKICAgICAgICAgcmV0dXJuOwogICAgIH0KIApkaWZm
IC0tZ2l0IGEvV2ViQ29yZS94bWwvWE1MSHR0cFJlcXVlc3RFeGNlcHRpb24uaCBiL1dlYkNvcmUv
eG1sL1hNTEh0dHBSZXF1ZXN0RXhjZXB0aW9uLmgKaW5kZXggMTU0MGQ0Yi4uMDcwMmNiYiAxMDA2
NDQKLS0tIGEvV2ViQ29yZS94bWwvWE1MSHR0cFJlcXVlc3RFeGNlcHRpb24uaAorKysgYi9XZWJD
b3JlL3htbC9YTUxIdHRwUmVxdWVzdEV4Y2VwdGlvbi5oCkBAIC00NCw3ICs0NCw2IEBAIG5hbWVz
cGFjZSBXZWJDb3JlIHsKICAgICAgICAgc3RhdGljIGNvbnN0IGludCBYTUxIdHRwUmVxdWVzdEV4
Y2VwdGlvbk1heCA9IDY5OTsKIAogICAgICAgICBlbnVtIFhNTEh0dHBSZXF1ZXN0RXhjZXB0aW9u
Q29kZSB7Ci0gICAgICAgICAgICBQRVJNSVNTSU9OX0RFTklFRCA9IFhNTEh0dHBSZXF1ZXN0RXhj
ZXB0aW9uT2Zmc2V0LCAvLyBVc2UgU0VDVVJJVFlfRVJSIHdoZW4gdGhhdCdzIGluIERPTSBDb3Jl
LCBodHRwOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0xMjE4MgogICAgICAgICAg
ICAgTkVUV09SS19FUlIgPSBYTUxIdHRwUmVxdWVzdEV4Y2VwdGlvbk9mZnNldCArIDEwMQogICAg
ICAgICB9OwogICAgIH07Cg==
</data>
<flag name="review"
          id="8520"
          type_id="1"
          status="+"
          setter="darin"
    />
          </attachment>
      

    </bug>

</bugzilla>