Learning path

Full curriculum

Full curriculum

Unit content

Web origins and the same-origin policy

Browsers group web content into origins. An origin is determined by the combination of

$$\text{scheme} + \text{host} + \text{port}.$$

For example, https://example.com and https://example.com:8443 are different origins because their ports differ.

The same-origin policy limits how script from one origin can read or manipulate resources belonging to another origin. A page may still be able to send some cross-origin requests or embed cross-origin resources, but reading the resulting data is more restricted.

This boundary lets mutually untrusted sites coexist in one browser without giving every page direct access to every other site's DOM and response data.

Web security mechanisms selectively relax or supplement this policy. CORS can authorize specified cross-origin reads, while cookies have their own domain, path and SameSite rules.

The origin boundary is central to XSS and CSRF: XSS runs attacker-controlled code inside a trusted origin, while CSRF abuses requests sent to another origin without gaining normal same-origin read access.