Same-Origin Policy and Cross-Origin Access
· β 2 min read
1. Same-Origin Policy The same-origin policy is the cornerstone of browser security.
The definition of same-origin covers three aspects:
Same protocol Same domain Same port Scope of the restrictions:
Cookie, LocalStorage, and IndexDB cannot be read The DOM cannot be obtained AJAX requests cannot be sent Simply put, two URLs whose protocol, domain, and port differ in any way are not allowed to communicate with each other, and the scope covers reading each other’s cookies and DOM and sending AJAX requests.