You are writing a Web 2.0 widget. You want it to be hosted on your site but embedded in third-party sites. You also want it to exchange data with your site. You would naturally consider XmlHttpRequest. Since you use have been using it extensively to write all your AJAX code. But that is not going to work from the third party site where your widget will be embedded. Any attempt to load data from your site is going to be a security issue. It's formally known as XSS (Cross-Site scripting). And is quite rightly blocked by the browsers.
A wise developer would say, "let's use an iFrame and point it to any URL we want. Then we can get its contents by accessing innerHTML or innerText from DOM". This then would be kicking a** of the smartest programmers hired by the "smartest" companies of the first world. Unfortunately, however this is a kind of statement only a tyro can make.
Having said that, luckily, the developers of (allegedly) bullet-proof browsers are not that smart. As Web in it's early days looked forward to a rosy future (though beset on all sides by a desultory present). Visionaries convinced commons that everybody was going to use a web browser. Everything was going to happen in the browser. They also told people that browser would render a new markup code HTML. Then they wrote the specifications. Which were shambolic. And if they were any good, neither did anybody have time to respect the specs nor did anyone care! Amidst this progress, a new language tailored for the web, christened "Javascript", was born. Zealots then also promised that e-commerce was the way to go. They pushed the browser makers to come up with ways to support it. And this another instance of chaos theory ended in an unholy mating of Javascript and the WWW Browser.
As I said due to web's haphazard growth there are numerous loopholes in the entire ecosystem. I recently came across a hack to get out of the boundaries circumscribed by a browser: Loading Javascript from a third-party site. Now, it is really surprising why this is not considered a security issue because allowing Javascripts to load from third-party sites totally defeats the purpose of having XSS security in place. You can do pretty much everything with it that you would otherwise do with standard AJAX. I learned in detail about XSS when my progress was impeded while writing a Web2.0 gadget/widget that required cross-site data exchange. I was able to work out a solution within a few minutes. It is fairly straightforward. Whenever you want to load data from remote site, all you have to do is create a new Javascript element and append it to DOM. Now on the server side make your dynamic scripting enging spit out a Javascript that calls another already defined function. This newly received function however contains the data that you were set out to ferry. I'm sure this is a commonly known/used solution. That leaves me with a final question, why is this still possible if an average Joe like me could figure it out in minutes? Pondering over the question for a while I got the answer myself. The answer is "Google" or any I advertising company/aggregator for that matter. Finally it boils down to another unanswerable question, "Otherwise, how would they push adverts on third-party sites? or How would Google Analytics collect data about your users (oops!)"
Sphere: Related Content