Cross-Site HTTP Requests Now Supported in Firefox
developer.mozilla.org
developer.mozilla.org
- The Mozilla Developer site has a lot of good documentation and examples: https://developer.mozilla.org/en/Firefox_3.6_for_developers
Depends on your target audience. IE has vanishing small market share amongst several groups such as tech savy, non-MS developers, Apple fanboys, etc.
Also, if those capabilities lead to features that vastly surpass your competition it'll be easier to own majority of non-IE customers than it would be going after all customers with generic features.
You don't need every person with a web connection as a customer, you just need enough to be profitable/successful.
In some industries, IE6 is still the plurality.
Here in the present, IE6 is around 2-3% of visitors.
On the bright side, government & gov't contractors are only 10% IE6.
The financial services industry. I work on a large retail trading site - many of our customers and a majority of our clients still visit our site in IE6. They have no choice, and some of them do not even realize they have no choice.
I wish browsers would implement an 'application mode' which would require some kind of installation step and then open up more permissions to code from that domain.
Even if you get users to install Prism you can't make cross-domain requests, which seems crazy, as I could get you to install some other binary and have full control. (Air does allow cross domain requests.)
Opening up some additional permissions (using something like the Android permissions model) would be a touch more restrained.
Why are they using a new set of HTTP headers to describe scenarios that are already covered by HTTP response codes? Why does the client send an Origin header at all in the first place, when it can be inferred from the referer? Why does the server respond with a list of allowed origins, when it could simply send an HTTP response code to say allowed/not allowed/auth required/etc.
I'm probably missing something, but this just doesn't add up...
EDIT:
Oh - maybe because there isn't a good javascript interface to HTTP response codes? Well, it sounds like a client-side solution would be to build this interface, rather than making the server support some weird headers that will still rely on the client to faithfully perform access control.
I'm talking to YOU, Twitter...