Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6737893
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 26, 20262026-05-26T11:18:07+00:00 2026-05-26T11:18:07+00:00

First off, I’m embarassed that I don’t know this. I know these things work,

  • 0

First off, I’m embarassed that I don’t know this. I know these things work, but just not sure why. There is something I still don’t get about CDNs and stuff like Google Analytics or Adsense.

If these scripts are coming from a domain other than your site’s domain how does this all tie in with same origin policy (SOP) and cross-site scripting (XSS)? From what I understand about XSS and SOP, these scripts just shouldn’t be able to run or interact with the DOM in your site. How come they are given special privileges? And how are these special privileges differentiated from other external scripts that cause errors in browsers due to XSS and SOP?

In a nutshell, I want to know why scripts from another domain are allowed to run, interact with and manipulate my site?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-26T11:18:08+00:00Added an answer on May 26, 2026 at 11:18 am

    You’re misunderstanding these policies.

    SOP prevents a page (such as in a frame) from interacting with a page from a different domain, or from reading a resource (AJAX request) in a different domain.

    There is nothing wrong with a script from a different domain executing in your page, as long as you explicitly load it. (that’s how JSONP works) However, you can’t read the script’s source, since that’s a resource from a different domain.

    Browser security restrictions are based on the source of the page executing the code, not the site that a particular <script> came from.


    Note that including Javascript from a different domain grants that script full access to your page; it can send AJAX requests (to your domain) and steal information by sending non-AJAX requests to other domains.

    Only include a script from a different domain if you trust that domain.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

First off, I'm not all that familiar with cookies but I know how they
first off this is a class assignment so i would appreciate help but just
First off, I know this is a base JS issue, not jQuery. I am
First off, please forgive the stupidness of this question but Im not from a
First off, I'm not entirely sure that my question title is very descriptive, so
First off, I know this may be a very stupid question, so don't shoot
First off, let me start off that I am not a .net developer. The
First off, I'm not terribly experienced in XML. I know the very basics of
First off, I know there are ways to make it so that text can
First off, I am cross-posting this from Server Fault because I did not receive

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.