Re: Content Security Policy feedback

2008-12-01 Thread Lucas Adamski
I think this is true, but it kind of depends on how you look at it. I think sometimes different types of cross-domain operations can get conflated together: * cross-domain scripting - when code in one domain has the ability to access another domain's code or DOM * cross-domain data importing - tr

Re: Content Security Policy feedback

2008-12-01 Thread Bil Corry
On Nov 22, 2:03 pm, Lucas Adamski <[EMAIL PROTECTED]> wrote: > Yes, my understanding is that Access Control is actually intended as a > generic cross-site server policy mechanism, and XHR is just its first > implementation. Anne confirmed that it's not intended to be XHR-only, however it's not int