Comment #11 on issue 20450 by aba...@chromium.org: Chromium shouldn't allow  
XHR to local directories
http://code.google.com/p/chromium/issues/detail?id=20450

The decision is made in SecurityOrigin::canRequest.  Safari might be doing  
magic here
to block these requests, but that's the right place to make the fix.  If  
you fix
this, you should also fix SecurityOrigin::canAccess, which would prevent  
reading the
content via an iframe.

--
You received this message because you are listed in the owner
or CC fields of this issue, or because you starred this issue.
You may adjust your issue notification preferences at:
http://code.google.com/hosting/settings

--~--~---------~--~----~------------~-------~--~----~
Automated mail from issue updates at http://crbug.com/
Subscription options: http://groups.google.com/group/chromium-bugs
-~----------~----~----~----~------~----~------~--~---

Reply via email to