Search code examples
cross-browsercorssame-origin-policy

Same Origin Policy and subdomains


Whether http://acme.help.com and http://acme.com can be considered as same origin? Will it fall under SO restrictions?


Solution

  • Yup, it will fail. In order for origins to be considered same-origin, their scheme, host and port must match. Here are some examples: http://en.wikipedia.org/wiki/Same-origin_policy#Origin_determination_rules