te')); return $arr; } /* 遍历用户所有主题 * @param $uid 用户ID * @param int $page 页数 * @param int $pagesize 每页记录条数 * @param bool $desc 排序方式 TRUE降序 FALSE升序 * @param string $key 返回的数组用那一列的值作为 key * @param array $col 查询哪些列 */ function thread_tid_find_by_uid($uid, $page = 1, $pagesize = 1000, $desc = TRUE, $key = 'tid', $col = array()) { if (empty($uid)) return array(); $orderby = TRUE == $desc ? -1 : 1; $arr = thread_tid__find($cond = array('uid' => $uid), array('tid' => $orderby), $page, $pagesize, $key, $col); return $arr; } // 遍历栏目下tid 支持数组 $fid = array(1,2,3) function thread_tid_find_by_fid($fid, $page = 1, $pagesize = 1000, $desc = TRUE) { if (empty($fid)) return array(); $orderby = TRUE == $desc ? -1 : 1; $arr = thread_tid__find($cond = array('fid' => $fid), array('tid' => $orderby), $page, $pagesize, 'tid', array('tid', 'verify_date')); return $arr; } function thread_tid_delete($tid) { if (empty($tid)) return FALSE; $r = thread_tid__delete(array('tid' => $tid)); return $r; } function thread_tid_count() { $n = thread_tid__count(); return $n; } // 统计用户主题数 大数量下严谨使用非主键统计 function thread_uid_count($uid) { $n = thread_tid__count(array('uid' => $uid)); return $n; } // 统计栏目主题数 大数量下严谨使用非主键统计 function thread_fid_count($fid) { $n = thread_tid__count(array('fid' => $fid)); return $n; } ?>javascript - Cross-domain communication using a Firefox addon - Stack Overflow
最新消息:雨落星辰是一个专注网站SEO优化、网站SEO诊断、搜索引擎研究、网络营销推广、网站策划运营及站长类的自媒体原创博客

javascript - Cross-domain communication using a Firefox addon - Stack Overflow

programmeradmin3浏览0评论

Firefox addons allow you to do cross-domain munication.

Is there any way to expose this function so I can initiate cross-domain ajax from any page (given I have installed this addon)?

Edit: I know what is CORS, and CORS only make sense when you have control the server, but I don't. The point here is I control the browser, I bear the risk so I am asking if anyway to export the cross-domain function from addon stage to the userland.

Firefox addons allow you to do cross-domain munication.

Is there any way to expose this function so I can initiate cross-domain ajax from any page (given I have installed this addon)?

Edit: I know what is CORS, and CORS only make sense when you have control the server, but I don't. The point here is I control the browser, I bear the risk so I am asking if anyway to export the cross-domain function from addon stage to the userland.

Share Improve this question edited Jun 24, 2012 at 11:10 Howard asked Jun 23, 2012 at 7:58 HowardHoward 19.8k36 gold badges115 silver badges187 bronze badges 3
  • You should rather look at CORS (see bart's answer) - allowing any web page to do cross-origin requests without any checks whatsoever would be a huge security hole. – Wladimir Palant Commented Jun 23, 2012 at 9:11
  • CORS only make sense when you have control the server, but I don't. The point here is I control the browser, I bear the risk so I am asking if anyway to export the cross-domain function from addon platform to the userland. – Howard Commented Jun 24, 2012 at 11:09
  • Do you mean like how greasemonkey does it? – Yansky Commented Jul 3, 2012 at 4:53
Add a ment  | 

5 Answers 5

Reset to default 5 +150

As you have said, the same origin policy only serves to protect the client (yourself), usually from XSS attacks.

I'm not sure what you're trying to achieve with the addon, but you can certainly try doing the following on your own machine. By changing the settings on firefox, you can ignore the same origin policy.

If you're trying to develop a plugin that allows cross domain access (and thus potentially open up vulnerabilities in your client-base), you may need to employ some unorthodox tricks. I can think of a couple ways, but like CORS, you will need access to SOME server at least. You can essentially create a proxy that fetches the resources on your server instead. Ie, the users of your plugin hits http://yourwebsite./?url=http://someotherwebsite./resource.

I can think of no way to do a client-side only solution.

Cross domain munication aka CORS (Cross Origin Resource Share) is only possible if the server allows it, and the browser supports it.

Easy reading in this Wikipedia article

Heavy reading in this W3C document which is still a working draft.

I have used CORS now for a year in the C# Webserver. I noticed whenever I do not add the CORS headers on the server side, I run into the same origin policy. Even when requesting to the same IP address but a different port.

If the server does not support CORS, you may find your cross domain requests to fail

EDIT:

I recently learned that the same domain policy can be worked around using Yahoo! Query Language (YQL). See the link for more information.

See this SO item for an example Cross Domain Post method ajax call using jquery with xml response

You might be able to make use of this gem: https://github./progrium/localtunnel

Userscripts have cross-domain XMLHttpRequest, and they will even run on all browsers.

Do you have access to the other server?? JSONP it's generally a good idea if you have access.

http://en.wikipedia/wiki/JSONP

发布评论

评论列表(0)

  1. 暂无评论