Chrome supports TCP & UDP sockets
blog.alexmaccaw.com
blog.alexmaccaw.com
This is for Chrome extensions only, not for web content. Mozilla has had an API available to extensions for this for a long time. That is how Chatzilla works, for example.
The Web API team has created a raw socket API for web content that will be used for the Boot to Gecko email client and other non-HTTP applications. For security reasons, this requires an extra permission to be granted by the app store and/or by the user.
Firefox has had sockets for a while and has also chosen to make them available to extensions only. Even Java Applets back in the day supported sockets only if you jumped through a bunch of hoops (if I recall correctly. it's possible you could only do socket communication with JNLP or something).
As far as I know, NACL is extension/app only as a way of controlling risk to the client.
about:flags and two clicks will enable NaCl TCP/UDP sockets and a third click will enable NaCl on any webpage with a prudent and applicable warning about the potential security risk.
There's a group of people beginning work on porting some of the traditional p2p constructs like DHTs into the browser, for those interested: http://joincollage.com/webp2p
And most importantly, the WebRTC APIs will be standardized and available on the web, not just for browser extensions.
Note that this was a research project. It works, but there's no security, so once installed, any malicious web-page could use your browser to connect to TCP/UDP end-points.
http://www.theregister.co.uk/2002/10/23/were_being_spanked_b...
The codename for the Microsoft phone was "Stinger" until everyone called it "Stinker". Choice quote:
(Microsoft hates the "Stinker" moniker so much, that it's
rebranded Stinker as "Canary" - perhaps unaware of the bird's
history as a sacrificial and disposable early warning system for
miners. When the Canary dies - you clear out fast).Or maybe is because chrome extensions already have a weak security model and you have to put trust in the author not to sniff all your data and upload it to a server.
In the case of sockets, the manifest needs the "experimental" permission. And I would assume (but have no idea if this is true) that once it's not experimental, there'll be a separate permissions flag for web sockets.
https://code.google.com/chrome/extensions/manifest.html#perm... https://code.google.com/chrome/extensions/permission_warning...
Edit: ajaxterm
http://src.chromium.org/viewvc/chrome/trunk/src/chrome/brows... --8<-- int TCPSocket::Bind(const std::string& address, int port) { // TODO(penghuang): Supports bind for tcp? return net::ERR_FAILED; } --8<--
Now that could be very useful...
These are raw, unadulterated sockets -- but only available to Chrome extensions, not normal web pages. I'm pretty certain Mozilla extensions have been able to create sockets for a while, and the sky hasn't fallen yet.
Edit: https://developer.mozilla.org/en/XPCOM_Interface_Reference/n...