none
Access data sources across domains RRS feed

  • Question

  • I recently had to work with some JavaScript code which sent a SOAP request to an external web service, so I had to enable "Access data sources across domains" under the Miscellaneous IE security settings.

    Are there any security issues with enabling this setting? Would it be safe to propagate this setting to a large number of users via Group Policy?

    Monday, August 24, 2015 12:52 PM

All replies

  • Hi,

    to debug your development and production environments.

    Tools>Internet Options>Advanced tab, check "Always record developer console messages".

    ... now normally suppressed console messages will be written to the Dev tool console. XSS blocks will be recorded. Click on an item in the console to navigate to the relevant MSDN documentation. 

    To invoke the Dev tool debugger, F12>Debug tab, select "Break on all exceptions" or "Break on unhandled exceptions". Return to the browser window without closing the dev tool and do your testing.

    Typically your dev and production environments won't map to the same IE Security zone... File>Properties menu to find out which IE security zone a domain maps to.

    For public web sites assume that users are using the default IE security zone settings and that they have no sites listed in the Trusted sites list... your public site should just work without the user having to tweak their IE security zone settings (MS Edge does not use the same security zone model).

    For Intranet sites you may have to place the services domain in your Trusted sites list.... use GPO to propagate the setting. GPO tweaks to the Advanced tab settings also propagates to domains in the Internet zone.

    Post questions about html, css and scripting for web site development to http://stackoverflow.com (IE forums). If possible include with your question a link to your website or a mashup (jsfiddle.com).

    Regards.

    Questions regarding Internet Explorer 8, 9 and 10 and Internet Explorer 11 for the IT Pro Audience. Topics covered are: Installation, Deployment, Configuration, Security, Group Policy, Management questions. If you are a consumer looking for answers or to raise a question, it's highly recommended you head on over to http://answers.microsoft.com/en-us


    Rob^_^

    Tuesday, August 25, 2015 1:04 AM
  • I'm not asking about how to debug my code, the code works fine.

    It's an Internet Explorer related question and I'm pretty sure this is the right forum. Let me rephrase my question:

    Does enabling "Access data sources across domains" in Internet Explorer 11 pose any security risks for a user's machine?

    Tuesday, August 25, 2015 5:00 AM