Closed
Bug 129551
Opened 24 years ago
Closed 9 years ago
document.load(url) fails if url has diferent host from current page location
Categories
(Core :: DOM: Core & HTML, defect, P4)
Core
DOM: Core & HTML
Tracking
()
RESOLVED
INVALID
People
(Reporter: nick, Unassigned)
References
()
Details
If you load "m.xml", as the default says, the script will load it, apply the
"debug.xsl" stylesheet and show the output. If you type
"http://slashdot.org/slashdot.xml" it won't work. It can be a "you can only
connect to the same host" kind of thing, but is silly.
To demonstrate the sillyness I've created an alternative version which uses an
iframe to load the requested XML document. Just check "Use iframe hack" and
everything will work.
Comment 1•24 years ago
|
||
Mitch, this is as designed, right?
Assignee: jst → mstoltz
Component: DOM Core → DOM Mozilla Extensions
Comment 2•24 years ago
|
||
i see exactly as described by the reporter.
document.load() works as designed, but this does feel kind of strange though:
why can you do it with iframe then?
Comment 4•24 years ago
|
||
Well, you can load an XML document from another domain into an iframe, but you
can't access the document in the iframe after it's loaded if the document is
from a different domain.
But we are accessing it since we can do an XSLT transformation on it...
| Reporter | ||
Comment 6•24 years ago
|
||
Uhm.. probably someone could use this hack to guess an internal DNS name and get
its content, that way getting content from inside a corporate firewall. The
other problem are cookies, because a site could use an iframe to access another
site using the client's cookies, thus accessing private information. The latter
can be avoided by not sending any cookies when a request is initiated this way,
but the former case I think is unavoidable. Ugh... it would be nice to find a
secure way fo this to work....
Comment 7•24 years ago
|
||
You can do an XSLT transformation on it - but can a script read the XML data
before or after the transformation?
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Updated•24 years ago
|
Priority: -- → P4
| Reporter | ||
Comment 8•24 years ago
|
||
...what would be the difference among passing it to the XSLT processor and being
able to use any other function on it?
BTW, I'd like to add yet another way to access another site's xml, using the
document() function of xslt. Check
http://mazinger.technisys.com.ar/pruebas-nick/kt.xml . This page will download
Kernel Traffic in xml format from its original site, transform it and display
it. The result would be able to do whatever it wishes with the generated content
through embeded scripts.
Updated•19 years ago
|
Assignee: security-bugs → general
Status: ASSIGNED → NEW
QA Contact: stummala → ian
Updated•17 years ago
|
Assignee: general → nobody
QA Contact: ian → general
| Assignee | ||
Updated•13 years ago
|
Component: DOM: Mozilla Extensions → DOM
Comment 9•9 years ago
|
||
Cannot violate the same-origin policy.
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → INVALID
| Assignee | ||
Updated•7 years ago
|
Component: DOM → DOM: Core & HTML
You need to log in
before you can comment on or make changes to this bug.
Description
•