Given the simplicity of writing a server side proxy that fetches data across domains, I’m at a loss as to what the initial intention was in preventing client side AJAX from making calls across domains. I’m not asking for speculation, I’m looking for documentation from the language designers (or people close to them) for what they thought they were doing, other than simply creating a mild inconvenience for developers.
TIA
It’s to prevent that a browser acts as a reverse proxy. Suppose you are browsing http://www.evil.com from a PC at your office, and suppose that in that office exists an intranet with sensitive information at http://intranet.company.com which is only accessible from the local network.
If the cross domain policy wouldn’t exists, http://www.evil.com could made ajax requests to http://intranet.company.com, using your browser as a reverse proxy, and send that information to http://www.evil.com with another Ajax request.
This one of the reasons of the restriction I guess.