The Same Origin Policy / Chapter 12 of 14

Getting Around Same Origin Policy

Getting Around Same Origin Policy in Pankaj Mouriya's Same Origin Policy guide.

All chapters ↘
  1. 01 / Introduction
  2. 02 / What should be Allowed?
  3. 03 / Same Origin Policy
  4. 04 / Access Different Orgins
  5. 05 / Same Origin Policy in Tabs
  6. 06 / Same Origin Policy to Anchors
  7. 07 / Same Origin Policy to Forms
  8. 08 / Same Origin Policy to Images and CSS
  9. 09 / Same Origin Policy to JavaScript
  10. 10 / Same Origin Policy to Web Storage
  11. 11 / Same Origin Policy to Cookies
  12. 12 / Getting Around Same Origin Policy
  13. 13 / postMessage API Implementation and limitations
  14. 14 / References

Various other ways via which you can bypass Same Origin Policy are -

  • JSONP
    • JSONP abuses JavaScript to load data cross-origin, just like a JavaScript include
  • XHR with CORS
    • XMLHTTPRequest by default can't do cross origin communication but it is possible to send data cross origin request with CORS header
  • URL Fragment
    • It is possible to use URL Fragments to communicate Cross Origin
  • postMessage API
    • It enabled cross origin communication between two different origins
  • many more