[Webkit-unassigned] [Bug 171666] New: CORS execution from file:// scheme not allowed by default in STP 29

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Thu May 4 09:25:53 PDT 2017


https://bugs.webkit.org/show_bug.cgi?id=171666

            Bug ID: 171666
           Summary: CORS execution from file:// scheme not allowed by
                    default in STP 29
           Product: WebKit
           Version: Safari Technology Preview
          Hardware: Macintosh
                OS: macOS 10.12
            Status: NEW
          Severity: Normal
          Priority: P2
         Component: JavaScriptCore
          Assignee: webkit-unassigned at lists.webkit.org
          Reporter: d.i.richardson at icloud.com

Created attachment 309055

  --> https://bugs.webkit.org/attachment.cgi?id=309055&action=review

A simple html file with XHR to fetch and display http://webkit.org

Beginning with Safari Technology Preview release 29, all CORS requests from file:// are blocked unless Disable Local File Restrictions or Disable Cross-Origin Restrictions selected from Develop menu.
This behaviour is new, and not present in release versions of Safari or Webkit Nightly r216177.

Load attached file in browser to test.

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20170504/fd274dc1/attachment.html>


More information about the webkit-unassigned mailing list