WebKit Bugzilla
New
Browse
Search+
Log In
×
Sign in with GitHub
or
Remember my login
Create Account
·
Forgot Password
Forgotten password account recovery
RESOLVED INVALID
7731
Cross site XMLHttpRequest doesn't even initialize
https://bugs.webkit.org/show_bug.cgi?id=7731
Summary
Cross site XMLHttpRequest doesn't even initialize
Neil Roberts
Reported
2006-03-11 21:54:56 PST
If this file is downloaded and run, it works (pops up alerts on state changes) or if the URL is set to something within the domain (
http://10is2.com/foo2.html
) then the alerts pop up fine.
Attachments
Add attachment
proposed patch, testcase, etc.
Neil Roberts
Comment 1
2006-03-11 21:59:52 PST
Also shown on
https://bugreport.apple.com/cgi-bin/WebObjects/RadarWeb.woa/3/wo/vIeBNGYXJSOQXAzfd0WURM/4.27
Neil Roberts
Comment 2
2006-03-11 22:00:31 PST
Seemed to happen during Security Update / 10.4.5 update
David Kilzer (:ddkilzer)
Comment 3
2006-03-11 22:08:42 PST
Confirming bug (tested on my PB G4 already). Reporter mentioned this happens on Safari 2.0.3 (417.8) on 10.4.5 so changing Version to 417.x. Reporter noted that this behavior started with either the Mac OS X 10.4.5 update or Security Update 2006-001 that followed shortly thereafter. About the Mac OS X 10.4.5 Update (delta)
http://docs.info.apple.com/article.html?artnum=303179
About Security Update 2006-001
http://docs.info.apple.com/article.html?artnum=303382
David Kilzer (:ddkilzer)
Comment 4
2006-03-11 22:12:10 PST
Neil, the URL you provided in
Comment #1
isn't going to work for anyone else. You need to list the "Radar" bug number assigned to the issue here. It probably starts with "4" and has 7 digits.
David Kilzer (:ddkilzer)
Comment 5
2006-03-11 22:16:28 PST
Adding Regression keyword since this apparently is a regression from earlier versions of Mac OS X. Also adding HasReduction since the reduction is available. The reporter said that this code works in Firefox 1.5.0.1, but I can't seem to get it to work now. Perhaps this isn't a bug after all? Firefox throws a permission denied error....
Alexey Proskuryakov
Comment 6
2006-03-12 00:41:53 PST
Cross-site XMLHttpRequests aren't allowed, the script should be from the same domain that the request URI has. WebKit specifically allows scripts running from local files to make any request; this is needed for Dashboard widgets. Firefox raises an exception on attempts to use cross-site requests, unless the script is signed and granted special privileges. WebKit simply ignores such attempts, which is a known bug (it should also raise an exception).
Neil Roberts
Comment 7
2006-03-12 06:38:29 PST
Radar bug is 4474958 This also works in Firefox for me with no security differences
Eric Seidel (no email)
Comment 8
2006-03-13 19:49:47 PST
This does not work in the latest FireFox either. As far as I can tell this is correct behavior. Resolving Radar as well.
Lucas Forschler
Comment 9
2019-02-06 09:02:43 PST
Mass moving XML DOM bugs to the "DOM" Component.
Note
You need to
log in
before you can comment on or make changes to this bug.
Top of Page
Format For Printing
XML
Clone This Bug