3 ms·
Good questions: > Who's javascript/cookies run in a real URL amp page, if any? The document operates as the signed origin, so cookies, CORS etc all operate as
by gregable 7y ago
Good questions:
> Who's javascript/cookies run in a real URL amp page, if any?
The document operates as the signed origin, so cookies, CORS etc all operate as the signed origin (the one in the URL bar). The HTTP request is made using the request URL's origin however, so the server delivering the signed exchange has no cookie access to the signed origin's cookies.
> What happens if I hit refresh, does it reload the AMP page or the real page?
A refresh will cause the browser to make a normal HTTPS request to the origin in the URL bar. A refresh works identically to what it has in the past, essentially.
> Can a webpage that isn't Google use real domain AMP pages?
Yes. It is a spec that browsers can support, and any site can use. There is nothing Google specific, or even AMP specific, about the specification.
> In that case, can their javascript influence the page at all? (ie change the look, put elements over it, make http requests)
No. Conceptually, you can think of a signed exchange as a 301 redirect to a new URL which has already been cached by the browser (so there is no 2nd network event). The cache was populated by the contents of the signed exchange, assuming the signature validates.