RESOLVED INVALID7731
Cross site XMLHttpRequest doesn't even initialize
https://bugs.webkit.org/show_bug.cgi?id=7731
Summary Cross site XMLHttpRequest doesn't even initialize
Neil Roberts
Reported 2006-03-11 21:54:56 PST
If this file is downloaded and run, it works (pops up alerts on state changes) or if the URL is set to something within the domain ( http://10is2.com/foo2.html ) then the alerts pop up fine.
Attachments
Neil Roberts
Comment 2 2006-03-11 22:00:31 PST
Seemed to happen during Security Update / 10.4.5 update
David Kilzer (:ddkilzer)
Comment 3 2006-03-11 22:08:42 PST
Confirming bug (tested on my PB G4 already). Reporter mentioned this happens on Safari 2.0.3 (417.8) on 10.4.5 so changing Version to 417.x. Reporter noted that this behavior started with either the Mac OS X 10.4.5 update or Security Update 2006-001 that followed shortly thereafter. About the Mac OS X 10.4.5 Update (delta) http://docs.info.apple.com/article.html?artnum=303179 About Security Update 2006-001 http://docs.info.apple.com/article.html?artnum=303382
David Kilzer (:ddkilzer)
Comment 4 2006-03-11 22:12:10 PST
Neil, the URL you provided in Comment #1 isn't going to work for anyone else. You need to list the "Radar" bug number assigned to the issue here. It probably starts with "4" and has 7 digits.
David Kilzer (:ddkilzer)
Comment 5 2006-03-11 22:16:28 PST
Adding Regression keyword since this apparently is a regression from earlier versions of Mac OS X. Also adding HasReduction since the reduction is available. The reporter said that this code works in Firefox 1.5.0.1, but I can't seem to get it to work now. Perhaps this isn't a bug after all? Firefox throws a permission denied error....
Alexey Proskuryakov
Comment 6 2006-03-12 00:41:53 PST
Cross-site XMLHttpRequests aren't allowed, the script should be from the same domain that the request URI has. WebKit specifically allows scripts running from local files to make any request; this is needed for Dashboard widgets. Firefox raises an exception on attempts to use cross-site requests, unless the script is signed and granted special privileges. WebKit simply ignores such attempts, which is a known bug (it should also raise an exception).
Neil Roberts
Comment 7 2006-03-12 06:38:29 PST
Radar bug is 4474958 This also works in Firefox for me with no security differences
Eric Seidel (no email)
Comment 8 2006-03-13 19:49:47 PST
This does not work in the latest FireFox either. As far as I can tell this is correct behavior. Resolving Radar as well.
Lucas Forschler
Comment 9 2019-02-06 09:02:43 PST
Mass moving XML DOM bugs to the "DOM" Component.
Note You need to log in before you can comment on or make changes to this bug.