Confirmed users
110
edits
m (→Threats) |
|||
| Line 76: | Line 76: | ||
| | | | ||
|- | |- | ||
| IFrame origin handling | | IFrame origin handling {{bug|664301}} | ||
| A parent page and child iframe may opt-in to cross-domain communication by setting their document.domain . In this event, what should the value of "Sec-WebSocket-Origin:" be? Should the page/frame be able to share the same websocket connection? | | A parent page and child iframe may opt-in to cross-domain communication by setting their document.domain . In this event, what should the value of "Sec-WebSocket-Origin:" be? Should the page/frame be able to share the same websocket connection? | ||
| Client browser | | Client browser | ||