Created
January 19, 2013 06:26
-
-
Save rakeshpai/4571053 to your computer and use it in GitHub Desktop.
Code to replicate a potential bug with Firefox when using the crossorigin attribute on script tags. When using crossorigin="anonymous", if the server doesn't set access-control headers, Firefox doesn't evaluate the external script, even though it's downloaded. Thus, alert(foo) breaks with a ReferenceError if the server doesn't send the access-co…
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
window.foo = 3; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
<!doctype html> | |
<script src="http://localhost:4000/foo.js" crossorigin="anonymous"></script> | |
<script> | |
alert(foo); | |
</script> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
var http = require("http"), | |
fs = require("fs"); | |
http.createServer(function(req, res) { | |
// Only serves foo.js | |
res.setHeader("Access-Control-Allow-Origin", "*"); // Commenting this line out makes the loading of scripts asynchronous | |
res.setHeader("Content-Type", "application/javascript"); | |
fs.createReadStream(__dirname + "/foo.js").pipe(res); | |
}).listen(4000); |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment