[whatwg] postMessage: event.source allows navigation of sender
Thomas Broyer
t.broyer at gmail.com
Thu Feb 7 05:42:45 PST 2008
On Feb 7, 2008 10:59 AM, Hallvord R M Steen wrote:
>
> Have a look at section 4.7.4.1. Security which reads:
>
> User agents must raise a security exception whenever any of the
> members of a Location object are accessed by scripts whose origin is
> not the same as the Location object's associated Document's origin,
> with the following exceptions:
> * The href setter
Oops! My bad, missed the exceptions...
--
Thomas Broyer
More information about the whatwg
mailing list