The Same Origin Policy / Chapter 06 of 14

Same Origin Policy to Anchors

Same Origin Policy to Anchors in Pankaj Mouriya's Same Origin Policy guide.

All chapters ↘
  1. 01 / Introduction
  2. 02 / What should be Allowed?
  3. 03 / Same Origin Policy
  4. 04 / Access Different Orgins
  5. 05 / Same Origin Policy in Tabs
  6. 06 / Same Origin Policy to Anchors
  7. 07 / Same Origin Policy to Forms
  8. 08 / Same Origin Policy to Images and CSS
  9. 09 / Same Origin Policy to JavaScript
  10. 10 / Same Origin Policy to Web Storage
  11. 11 / Same Origin Policy to Cookies
  12. 12 / Getting Around Same Origin Policy
  13. 13 / postMessage API Implementation and limitations
  14. 14 / References

How does SOP apply to anchors ?

When we link one website to another website. For example, sitea.com is linked siteb.com.

Code
<a href="http://siteb.com"></a>
Same Origin Policy to Anchors, figure 1

Whenever such hyperlink is visited. The browser always loads the response in new context(tab/window). Via this the browser makes sure that there is no data leakage between sitea.com and siteb.com.

In simple terms, The response loads in a new window/context. The originating site is replaced by the accessed site.

Hence, any site can link any other site, but can't read the response

Same Origin Policy to Anchors, figure 2