Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"You can only use JSOP and CROS with sites you have control over or are designed to behave and support external requests."

That's kind of the point.



It limits the thing you can do. This library allows you to easily get and display content from any external source.


Those limits are a security measure to protect against XSS and CSRF. Intentionally weakening your site security isn't a good idea for most people. Your mash up site evidently uses this to get around same origin policy without the cooperation of targeted sites. It would be interesting to know how you plan to mitigate those risks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: