There is mention in the spec: https://tools.ietf.org/html/rfc6455#section-10.2
Is this not enough?
Is this not enough?
However, the lack of the same-origin policy in WebSockets makes the presence of the same-origin policy in XMLHttpRequests questionable. I am just talking about this part where the browser does not have to restrict a connection to any origin from a given website without even a need for a CORS like whitelist.