CSSHttpRequest is cross-domain AJAX using CSS
nb.io
nb.io
"Unlike JSONP, untrusted third-party JavaScript cannot execute in the context of the calling page."
Edit: It looks like they create an iframe, load the css, and parse the data using javascript, so it seems to be fairly safe.
Cool hack, but I don't see where this is useful.
I want them to call back my supplied function with the data. That I have to allow them to execute arbitrary code they supply to do that is a flaw.
Having said that, using CSS as the delivery mechanism seems pretty exotic, so I'm not advocating this as the solution, but there is a problem out there.