Application security / An illustrated guide

The Same Origin Policy.

An illustrated journey through the browser boundary: origins, tabs, storage, embedded resources, cookies, and postMessage.

Start reading ↗

For security practitioners and curious web developers

An archive of the guide accompanying the OWASP Bay Area talk. This is a historical edition; verify technical details against current documentation.

Reading path

Contents

  1. 01Introduction
  2. 02What should be Allowed?
  3. 03Same Origin Policy
  4. 04Access Different Orgins
  5. 05Same Origin Policy in Tabs
  6. 06Same Origin Policy to Anchors
  7. 07Same Origin Policy to Forms
  8. 08Same Origin Policy to Images and CSS
  9. 09Same Origin Policy to JavaScript
  10. 10Same Origin Policy to Web Storage
  11. 11Same Origin Policy to Cookies
  12. 12Getting Around Same Origin Policy
  13. 13postMessage API Implementation and limitations
  14. 14References