Newsletter sign-up
View all newsletters

Enterprise Java Newsletter
Stay up to date on the latest tutorials and Java community news posted on JavaWorld

JavaWorld Daily Brew

Be careful with crossdomain.xml



Back to:
www.javaworld.com/javaworld/jw-02-2009/jw-02-javaee-flex-2.html
.

Great article! One comment... For testing it's ok to have a "*" crossdomain.xml policy. But you have to be very careful with those in production. My two general rules of thumb for crossdomain files:
1) NEVER put a "*" policy on a server that uses cookies (especially for authentication)
2) NEVER put a "*" policy on an intranet server

-James

Your rating: None Average: 4 (4 votes)