Application security / An illustrated guide
The Same Origin Policy.
An illustrated journey through the browser boundary: origins, tabs, storage, embedded resources, cookies, and postMessage.
Start reading ↗For security practitioners and curious web developers
An archive of the guide accompanying the OWASP Bay Area talk. This is a historical edition; verify technical details against current documentation.
Reading path
Contents
- 01Introduction
- 02What should be Allowed?
- 03Same Origin Policy
- 04Access Different Orgins
- 05Same Origin Policy in Tabs
- 06Same Origin Policy to Anchors
- 07Same Origin Policy to Forms
- 08Same Origin Policy to Images and CSS
- 09Same Origin Policy to JavaScript
- 10Same Origin Policy to Web Storage
- 11Same Origin Policy to Cookies
- 12Getting Around Same Origin Policy
- 13postMessage API Implementation and limitations
- 14References