The Same Origin Policy / Chapter 10 of 14

Same Origin Policy to Web Storage

Same Origin Policy to Web Storage in Pankaj Mouriya's Same Origin Policy guide.

All chapters ↘
  1. 01 / Introduction
  2. 02 / What should be Allowed?
  3. 03 / Same Origin Policy
  4. 04 / Access Different Orgins
  5. 05 / Same Origin Policy in Tabs
  6. 06 / Same Origin Policy to Anchors
  7. 07 / Same Origin Policy to Forms
  8. 08 / Same Origin Policy to Images and CSS
  9. 09 / Same Origin Policy to JavaScript
  10. 10 / Same Origin Policy to Web Storage
  11. 11 / Same Origin Policy to Cookies
  12. 12 / Getting Around Same Origin Policy
  13. 13 / postMessage API Implementation and limitations
  14. 14 / References

Local Storage: (Persistent)

  • Can be shared between windows with Same Origin
  • Remains even after browser window is closed

Session Storage: (Non-Persistent)

  • Applies to Active window
  • Destroyed after windows is closed

Web Storage follows the same rule of Same Origin Policy. Lets see it in action

Steps:

  1. Open Developer Tools
  2. Storage
  3. Under Local Storage, add Key and Value as shown below. You can also do it via console
Same Origin Policy to Web Storage, figure 1
Code
window.localStorage["Token-key-Name"] = "Token-Value"
  1. Navigate to Browser Console
Code
window.localStorage
Same Origin Policy to Web Storage, figure 2
  1. Same way it works for sessionStorage
Same Origin Policy to Web Storage, figure 3