Security/Reviews/Firefox6/ReviewNotes/WebSockets: Difference between revisions

Line 76: Line 76:
|
|
|-
|-
| IFrame origin handling
| IFrame origin handling {{bug|664301}}
| A parent page and child iframe may opt-in to cross-domain communication by setting their document.domain . In this event, what should the value of "Sec-WebSocket-Origin:" be? Should the page/frame be able to share the same websocket connection?
| A parent page and child iframe may opt-in to cross-domain communication by setting their document.domain . In this event, what should the value of "Sec-WebSocket-Origin:" be? Should the page/frame be able to share the same websocket connection?
| Client browser
| Client browser
Confirmed users
110

edits