> How does HTTP(S) Same Origin policy work with local file:/// URLs?
It doesn't since file:/// is just a uri and not part of the http protocol
It doesn't since file:/// is just a uri and not part of the http protocol
If so, Isn't it thus probably better to run an HTTP server over a permissioned socket than to serve static HTML [manpages] from file URLs [in a [DEB] package]?