Research any topic before you write.

Find related topics. | Discover entities. | See connections. | Build a topical map.

Same-origin policy

In computing, the same-origin policy (SOP) is a concept in the web application security model. Under the policy, a web browser permits scripts contained in a first web page to access data in a second web page, but only if both web pages have the same origin. An origin is defined as a combination of URI scheme, host name, and port number. This policy…

History & Products

Use the mouse wheel or two fingers (on touchscreens) to zoom in and out of the map.

Research this topic

Explore the main themes, entities and connections around Same-origin policy. Start with the topic map, then use the sections below for research and deeper semantic analysis.

Explore this topic

Start with a few of the strongest sections from the source topic. These are research directions, not a list of keywords you must use.

Topics to explore

Browse the full topic structure. Each item opens a new analysis centered on that subject.

Overview

History

Implementation

Origin determination rules

  • URL Uniform Resource Locator

Read access to sensitive cross-origin responses via reusable authentication

  • CSRF Cross-site request forgery

Relaxing the same-origin policy

Attacks

Advanced semantic analysis

Deeper signals for content research, entity SEO and topical coverage. The plain-language headings explain what each technical view is useful for.

Map overview Semantic statistics

Same-origin policy

Nodes31
Edges30
Triples101
Avg. degree1.94
Density0.064516
Components1

How this topic connects Entity context

See the strongest relationship patterns around the current topic before diving into the raw triples.

Same-origin policy

Top relations

related to Read access to sensitive cross-origin responses via reusable authentication · 13
Same-origin policy → Assume, Authorization, Because, Counteracting, CSRF, For, JavaScript, Same Origin Policy, The, Then, This, While, World Wide Web
related to Reading information · 12
Same-origin policy → CORP, Cross-Origin Resource Policy, Cross-Origin Resource Sharing, Even, Further, If, IP, JavaScript, JavaScript-initiatedfetchrequests, These, This, WebRTC
related to Cross-origin resource sharing · 11
Same-origin policy → Browsers, Control-Allow-Originresponse, CORS, Firefox, HTTP, Internet Explorer, It, Safari, The, This, XMLHttpRequest
related to External links · 7
Same-origin policy → February, HTML5, OriginW3C Article, Same Origin PolicyRFC, Sample, The Web Origin Concept, Wayback Machine
related to Implementation · 7
Same-origin policy → Adobe Acrobat, Adobe Flash, All, DOM, Microsoft Silverlight, The, XMLHttpRequest
related to document.domain property · 6
Same-origin policy → For, If, Netscape Navigator, Setting, Thedocument, To
related to WebSockets · 6
Same-origin policy → However, Modern, Origin, To, WebSocket, WebSocket URI
related to Writing information (CSRF) · 6
Same-origin policy → GET, OPTIONS, POST, The, Therefore, TRACE
related to history · 5
Same-origin policy → DOM, JavaScript, Netscape, Netscape Navigator, The
related to Leaking or writing information via cookies · 5
Same-origin policy → If, Note, SOP, Therefore, This

Important terminology Word statistics

Use these terms to understand the vocabulary surrounding the topic, not as a checklist for keyword stuffing.

Important terminology

policy same-origin origin access web cross-origin data javascript security resource cookies browsers port site browser script user page scripts information

Entity relationships Subject–Predicate–Object triples

SubjectPredicateObjectConfidenceSrc
imagesinstance ofThis means that resources0.80text
CSSinstance ofThis means that resources0.80text
and dynamically loaded scripts can be accessed across origins via the corresponding HTML tagsinstance ofThis means that resources0.80text
session cookiesinstance ofbrowsers are required to tag along authentication details0.80text
platform-level kinds of the Authorization request header to the banking site based on the domain of the banking site.The bank site owners would expect that regular browsers of users visiting the malicious site do not allow the code loaded from the malicious site access the banking session cookie or platform-level authorizationinstance ofbrowsers are required to tag along authentication details0.80text
using the fragment identifier or thewindow.nameproperty were used to pass data between documents residing in different domainsinstance ofa number of workarounds0.80text
Firefox 3.5instance ofBrowsers0.80text
Safari 4instance ofBrowsers0.80text
Internet Explorer 10 use this header to allow the cross-origin HTTP requests with XMLHttpRequest that would otherwise have been forbidden by the same-origin policy.Cross-document messagingAnother techniqueinstance ofBrowsers0.80text
cross-document messaginginstance ofBrowsers0.80text
allows a script from one page to pass textual messages to a script on another page regardless of the script originsinstance ofBrowsers0.80text
Internet Explorer 10 use this header to allow the cross-origin HTTP requests with XMLHttpRequest that would otherwise have been forbidden by the same-origin policyinstance ofBrowsers0.80text

Related concept clusters Concept neighborhoods

These clusters group vocabulary that occurs around closely connected concepts in the source material.

    Connections between topic areas Semantic bridges

    Bridges can reveal useful research angles that are easy to miss in a flat list of related terms.

    Min side: 3
    For writers, content strategists, SEOs, marketers and creators — from quick topic research to advanced semantic analysis.