Version: 4.3.1 (KDE 4.3.1) "release 9" (using 4.3.1 (KDE 4.3.1) "release 9", KDE:KDE4:STABLE:Desktop / openSUSE_11.2) Compiler: gcc OS: Linux (x86_64) release 2.6.32.2-0.0.16.d8b32f9-desktop XMLHttpRequests need to be capable of retrieving documents from different domains. Just think about content aggregation. This is also a necessity for users of URL-Framing. It is not possible to directly retrieve a document on behalf of an URL-Framed URL because you will then only receive the frame instead of the document. To circumvent URL-Framing I have defined a domain redirect from a second domain mirror.elstel.com instead of using http://www.elstel.com: i.e. you have two domains that belong to the same page.
Making XMLHttpRequests across domains has the potential to break Same Origin Policy and could lead to easier cross-site request forgery attacks, cookie stealing etc. Please don't implement it.
At least issuing XMLHttpRequests on the same subdomain i.e. www.elstel.com and mirror.elstel.com needs to work since this is an absolutely unnecessary restriction.
Firefox does already implement it. It won`t make a difference if Konqueror does so, too.
Dear Bug Submitter, This bug has been stagnant for a long time. Could you help us out and re-test if the bug is valid in the latest version? I am setting the status to NEEDSINFO pending your response, please change the Status back to REPORTED when you respond. Thank you for helping us make KDE software even better for everyone!
Dear Bug Submitter, This is a reminder that this bug has been stagnant for a long time. Could you help us out and re-test if the bug is valid in the latest version? This bug will be moved back to REPORTED Status for manual review later, which may take a while. If you are able to, please lend us a hand. Thank you for helping us make KDE software even better for everyone!
Thank you for reporting this issue in KDE software. As it has been a while since this issue was reported, can we please ask you to see if you can reproduce the issue with a recent software version? If you can reproduce the issue, please change the status to "REPORTED" when replying. Thank you!
I am not sure if this would be intended behaviour or if other browsers forbid this for reasons of policy/security.
Dear user, KHTML (and KJS) was a long time more or less unmaintained and got removed in KF6. Please migrate to use a QWebEngine based HTML component. We will do no further fixes or improvements to the KF5 branches of these components beside important security fixes. For security issues, please see: https://kde.org/info/security/ Sorry that we did not fix this issue during the life-time of KHTML. Greetings Christoph Cullmann