4 ms·
Note that this is not an implementation problem but a problem in the general specification of websockets. So there is not going to be a solution to this issue u
by subudeepak 12y ago
Note that this is not an implementation problem but a problem in the general specification of websockets. So there is not going to be a solution to this issue until the specification itself is updated.
- jkarneges 12y agoThere is mention in the spec: https://tools.ietf.org/html/rfc6455#section-10.2 https://tools.ietf.org/html/rfc6455#section-10.2 Is this not enough?
- subudeepak 12y agoThe Origin header is used to protect the server. This is to prevent the WebSocket Hijacking attack (http://www.christian-schneider.net/CrossSiteWebSocketHijacking.html http://www.christian-schneider.net/CrossSiteWebSocketHijacki...) . i.e. it does not help a lot in the browser end especially in the mashup scenario. However, the lack of the same-origin policy in WebSockets makes the presence of the same-origin policy in XMLHttpRequests questionable. I am just talking about this part where the browser does not have to restrict a connection to any origin from a given website without even a need for a CORS like whitelist.