Closed Bug 129551 Opened 24 years ago Closed 9 years ago

document.load(url) fails if url has diferent host from current page location

Categories

(Core :: DOM: Core & HTML, defect, P4)

defect

Tracking

()

RESOLVED INVALID

People

(Reporter: nick, Unassigned)

References

()

Details

If you load "m.xml", as the default says, the script will load it, apply the "debug.xsl" stylesheet and show the output. If you type "http://slashdot.org/slashdot.xml" it won't work. It can be a "you can only connect to the same host" kind of thing, but is silly. To demonstrate the sillyness I've created an alternative version which uses an iframe to load the requested XML document. Just check "Use iframe hack" and everything will work.
Mitch, this is as designed, right?
Assignee: jst → mstoltz
Component: DOM Core → DOM Mozilla Extensions
i see exactly as described by the reporter.
document.load() works as designed, but this does feel kind of strange though: why can you do it with iframe then?
Well, you can load an XML document from another domain into an iframe, but you can't access the document in the iframe after it's loaded if the document is from a different domain.
But we are accessing it since we can do an XSLT transformation on it...
Uhm.. probably someone could use this hack to guess an internal DNS name and get its content, that way getting content from inside a corporate firewall. The other problem are cookies, because a site could use an iframe to access another site using the client's cookies, thus accessing private information. The latter can be avoided by not sending any cookies when a request is initiated this way, but the former case I think is unavoidable. Ugh... it would be nice to find a secure way fo this to work....
You can do an XSLT transformation on it - but can a script read the XML data before or after the transformation?
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Priority: -- → P4
...what would be the difference among passing it to the XSLT processor and being able to use any other function on it? BTW, I'd like to add yet another way to access another site's xml, using the document() function of xslt. Check http://mazinger.technisys.com.ar/pruebas-nick/kt.xml . This page will download Kernel Traffic in xml format from its original site, transform it and display it. The result would be able to do whatever it wishes with the generated content through embeded scripts.
Assignee: security-bugs → general
Status: ASSIGNED → NEW
QA Contact: stummala → ian
Assignee: general → nobody
QA Contact: ian → general
Component: DOM: Mozilla Extensions → DOM
Cannot violate the same-origin policy.
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → INVALID
Component: DOM → DOM: Core & HTML
You need to log in before you can comment on or make changes to this bug.