search
HomeWeb Front-endJS TutorialJavaScript cross-domain summary and solutions

What is cross-domain?
For security reasons, JavaScript does not allow cross-domain calls to objects on other pages. However, in addition to security restrictions, it also brings a lot of trouble to injecting iframe or ajax applications. Here is a brief summary of some issues related to cross-domain:

First of all, what is cross-domain? A simple understanding is that because of the restrictions of the JavaScript same-origin policy, js under the domain name a.com cannot operate b.com or c.a.com Objects under the domain name. For more detailed instructions, please see the table below:

URL Description Whether communication is allowed
http://www.a.com/a.js
http://www.a.com/b.js Under the same domain name, allowed
http ://www.a.com/lab/a.js
http://www.a.com/script/b.js Different folders under the same domain name are allowed
http://www.a.com:8000/ a.js
http://www.a.com/b.js Same domain name, different ports are not allowed
http://www.a.com/a.js
https://www.a.com/b .js Same domain name, different protocols are not allowed
http://www.a.com/a.js
http://70.32.92.74/b.js Domain name and domain name corresponding IP are not allowed
http://www.a .com/a.js
http://script.a.com/b.js The main domain is the same, but the subdomain is different. Not allowed
http://www.a.com/a.js
http://a. com/b.js The same domain name, different second-level domain names (same as above) are not allowed (cookies are not allowed to be accessed in this case)
http://www.cnblogs.com/a.js
http://www.a .com/b.js Different domain names are not allowed
Pay special attention to two points:
First, if the cross-domain problem is caused by protocols and ports, the "front desk" is powerless,
Second: When it comes to cross-domain issues, the domain is just It is identified by the "URL header" without trying to determine whether the same IP address corresponds to two domains or whether the two domains are on the same IP.
"URL header" refers to window.location.protocol +window.location.host, which can also be understood as "Domains, protocols and ports must match".
The following is a brief summary of the general method of handling cross-domain in the "front-end". The back-end proxy solution involves back-end configuration, which will not be explained here. If you are interested, you can read this article from Yahoo: "JavaScript: Use a Web Proxy for Cross-Domain XMLHttpRequest Calls》

1. Setting of document.domain+iframe
For examples where the main domain is the same but the subdomains are different, it can be solved by setting document.domain. The specific method is to add document.domain = 'a.com' to the two files http://www.a.com/a.html and http://script.a.com/b.html respectively; Then create an iframe in the a.html file to control the contentDocument of the iframe, so that the two js files can "interact". Of course, this method can only solve the situation where the primary domain is the same but the secondary domain name is different. If you set the domian of script.a.com to alibaba.com out of the blue, an error will obviously be reported! The code is as follows:

a.html on www.a.com

document.domain = 'a.com';
var ifr = document.createElement('iframe');
ifr.src = 'http:// script.a.com/b.html';
ifr.style.display = 'none';
document.body.appendChild(ifr);
ifr.onload = function(){
var doc = ifr.contentDocument || ifr.contentWindow.document;
// Manipulate b.html here
alert(doc.getElementsByTagName("h1")[0].childNodes[0].nodeValue);
};
b on script.a.com .html

document.domain = 'a.com';
This method is suitable for any page in {www.kuqin.com, kuqin.com, script.kuqin.com, css.kuqin.com} to communicate with each other.

Note: The domain of a certain page is equal to window.location.hostname by default. The main domain name is a domain name without www, such as a.com. The main domain name with a prefix in front of it is usually a second-level domain name or a multi-level domain name. For example, www.a.com is actually a second-level domain name. Domain can only be set as the primary domain name, and domain cannot be set to c.a.com in b.a.com.

Problems:
1. Security. When one site (b.a.com) is attacked, another site (c.a.com) will cause a security vulnerability.
2. If multiple iframes are introduced into a page, the same domain must be set in order to be able to operate all iframes.
2. Dynamically create script
Although the browser prohibits cross-domain access by default, it does not prohibit referencing JS files from other domains in the page, and you can freely execute the functions in the introduced JS files (including operating cookies, Dom, etc. ). Based on this, complete cross-domain communication can be easily achieved by creating script nodes. For specific methods, please refer to YUI's Get Utility

It is quite interesting to judge whether the script node is loaded: IE can only use the readystatechange attribute of the script, and other browsers use the load event of the script. The following are some methods to determine whether the script is loaded.

js.onload = js.onreadystatechange = function() {
if (!this.readyState || this.readyState === 'loaded' || this.readyState === 'complete') {
// callback here Execute everywhere
              js.onload = js.onreadystatechange = null;
    }
};
3. Use iframe and location.hash
This method is more convoluted, but it can solve the problem of footstep replacement in completely cross-domain situations. The principle is to use location.hash to transfer values. In the URL: http://a.com#helloword, ‘#helloworld’ is location.hash. Changing the hash will not cause the page to refresh, so the hash value can be used to transfer data. Of course, the data capacity is limited. Assume that the file cs1.html under the domain name a.com wants to transfer information to cs2.html under the domain name cnblogs.com. First, cs1.html is created to automatically create a hidden iframe. The src of the iframe points to cs2.html under the domain name cnblogs.com. page, the hash value at this time can be used for parameter passing. After cs2.html responds to the request, it will pass the data by modifying the hash value of cs1.html (since the two pages are not in the same domain, IE and Chrome do not allow modification of the value of parent.location.hash, so we need to use a.com A proxy iframe under the domain name; Firefox can modify it). At the same time, add a timer to cs1.html to determine whether the value of location.hash has changed after a period of time. If there is any change, obtain the hash value. The code is as follows:

First, the file cs1.html file under a.com:

function startRequest(){
var ifr = document.createElement('iframe');
ifr.style.display = 'none';
ifr .src = 'http://www.cnblogs.com/lab/cscript/cs2.html#paramdo';
document.body.appendChild(ifr);
}

function checkHash() {
try {
var data = location.hash ? location.hash.substring(1) : '';
              if (console.log) {
                 console.log('Now the data is '+data); 
                                                                                                                                                          ;
}
setInterval(checkHash, 2000);
cs2.html under the cnblogs.com domain name:

//Simulate a simple parameter processing operation

switch(location.hash){
case '#paramdo':
callBack ();
             break; e) {
                                                                                                                                                                                                                                                                                  .style.display = ‘none’; body.appendChild(ifrproxy);
}
}
a.com domain name cs3.html

//Because parent.parent and itself belong to the same domain, you can change the value of its location.hash

parent.parent. location.hash = self.location.hash.substring(1);
Of course, there are many disadvantages in doing this, such as the data is directly exposed in the URL, the data capacity and type are limited, etc...

4. Window.name implementation Cross-domain data transfer
The article is too long to be read here. For details, please see the cross-domain data transfer implemented by window.name.

5. Use HTML5 postMessage
One of the coolest new features in HTML5 is Cross Document Messaging. The next generation of browsers will support this feature: Chrome 2.0+, Internet Explorer 8.0+, Firefox 3.0+, Opera 9.6+, and Safari 4.0+. Facebook already uses this feature to support real-time web-based messaging with postMessage.

otherWindow.postMessage(message, targetOrigin);
otherWindow: A reference to the window that receives the message page. It can be the contentWindow attribute of the iframe in the page; the return value of window.open; the value obtained from window.frames through name or subscript.
message: The data to be sent, string type.
targetOrigin: used to limit otherWindow, "*" means no limit

The code in a.com/index.html:



b.com/index. Code in html:



Statement
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
The Origins of JavaScript: Exploring Its Implementation LanguageThe Origins of JavaScript: Exploring Its Implementation LanguageApr 29, 2025 am 12:51 AM

JavaScript originated in 1995 and was created by Brandon Ike, and realized the language into C. 1.C language provides high performance and system-level programming capabilities for JavaScript. 2. JavaScript's memory management and performance optimization rely on C language. 3. The cross-platform feature of C language helps JavaScript run efficiently on different operating systems.

Behind the Scenes: What Language Powers JavaScript?Behind the Scenes: What Language Powers JavaScript?Apr 28, 2025 am 12:01 AM

JavaScript runs in browsers and Node.js environments and relies on the JavaScript engine to parse and execute code. 1) Generate abstract syntax tree (AST) in the parsing stage; 2) convert AST into bytecode or machine code in the compilation stage; 3) execute the compiled code in the execution stage.

The Future of Python and JavaScript: Trends and PredictionsThe Future of Python and JavaScript: Trends and PredictionsApr 27, 2025 am 12:21 AM

The future trends of Python and JavaScript include: 1. Python will consolidate its position in the fields of scientific computing and AI, 2. JavaScript will promote the development of web technology, 3. Cross-platform development will become a hot topic, and 4. Performance optimization will be the focus. Both will continue to expand application scenarios in their respective fields and make more breakthroughs in performance.

Python vs. JavaScript: Development Environments and ToolsPython vs. JavaScript: Development Environments and ToolsApr 26, 2025 am 12:09 AM

Both Python and JavaScript's choices in development environments are important. 1) Python's development environment includes PyCharm, JupyterNotebook and Anaconda, which are suitable for data science and rapid prototyping. 2) The development environment of JavaScript includes Node.js, VSCode and Webpack, which are suitable for front-end and back-end development. Choosing the right tools according to project needs can improve development efficiency and project success rate.

Is JavaScript Written in C? Examining the EvidenceIs JavaScript Written in C? Examining the EvidenceApr 25, 2025 am 12:15 AM

Yes, the engine core of JavaScript is written in C. 1) The C language provides efficient performance and underlying control, which is suitable for the development of JavaScript engine. 2) Taking the V8 engine as an example, its core is written in C, combining the efficiency and object-oriented characteristics of C. 3) The working principle of the JavaScript engine includes parsing, compiling and execution, and the C language plays a key role in these processes.

JavaScript's Role: Making the Web Interactive and DynamicJavaScript's Role: Making the Web Interactive and DynamicApr 24, 2025 am 12:12 AM

JavaScript is at the heart of modern websites because it enhances the interactivity and dynamicity of web pages. 1) It allows to change content without refreshing the page, 2) manipulate web pages through DOMAPI, 3) support complex interactive effects such as animation and drag-and-drop, 4) optimize performance and best practices to improve user experience.

C   and JavaScript: The Connection ExplainedC and JavaScript: The Connection ExplainedApr 23, 2025 am 12:07 AM

C and JavaScript achieve interoperability through WebAssembly. 1) C code is compiled into WebAssembly module and introduced into JavaScript environment to enhance computing power. 2) In game development, C handles physics engines and graphics rendering, and JavaScript is responsible for game logic and user interface.

From Websites to Apps: The Diverse Applications of JavaScriptFrom Websites to Apps: The Diverse Applications of JavaScriptApr 22, 2025 am 12:02 AM

JavaScript is widely used in websites, mobile applications, desktop applications and server-side programming. 1) In website development, JavaScript operates DOM together with HTML and CSS to achieve dynamic effects and supports frameworks such as jQuery and React. 2) Through ReactNative and Ionic, JavaScript is used to develop cross-platform mobile applications. 3) The Electron framework enables JavaScript to build desktop applications. 4) Node.js allows JavaScript to run on the server side and supports high concurrent requests.

See all articles

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

MantisBT

MantisBT

Mantis is an easy-to-deploy web-based defect tracking tool designed to aid in product defect tracking. It requires PHP, MySQL and a web server. Check out our demo and hosting services.

EditPlus Chinese cracked version

EditPlus Chinese cracked version

Small size, syntax highlighting, does not support code prompt function

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

ZendStudio 13.5.1 Mac

ZendStudio 13.5.1 Mac

Powerful PHP integrated development environment

SecLists

SecLists

SecLists is the ultimate security tester's companion. It is a collection of various types of lists that are frequently used during security assessments, all in one place. SecLists helps make security testing more efficient and productive by conveniently providing all the lists a security tester might need. List types include usernames, passwords, URLs, fuzzing payloads, sensitive data patterns, web shells, and more. The tester can simply pull this repository onto a new test machine and he will have access to every type of list he needs.