|
A while back ago, i gave an overview of the very valid security concerns behind restricting xmlhttprequests to the same host, and offered an informal proposal for a new object with looser security settings, but with a few restrictions: ContextAgnosticXmlHttpRequuest (http://chrisholland.blogspot.com/2005/03/contextagnosticxmlhttprequest-informal.html) . The idea is to retain security while allowing for a more straightforward and appropriate way for sites to syndicate content from each-other. |