HTML 5ͨ¹ýsandboxÊôÐÔÌáÉýiFrameµÄ°²È«ÐÔ
ת×Ô£ºInfoQ
×÷Õß
Abel Avram
ÒëÕß
ÕÅÁú
·¢²¼ÓÚ
2010Äê1ÔÂ30ÈÕ ÉÏÎç12ʱ6·Ö
ĿǰWeb Hypertext Application
Technology Working Group
£¨WHATWG£©ÕýÓëW3C
ͨ
Á¦ºÏ×÷½¨Á¢HTML 5±ê×¼£¬ÔÚ¹ýÈ¥3¸öÔÂÖУ¬¸ÃÏ×÷ÒѾ½øÈëµ½ÁËWHATWGµÄ“Last Call
”½×
¶Î¡£ÔÚÕâÆÚ¼ä£¬±ä»¯×î´óµÄÒ»¸öÌØÐÔ¾ÍÊÇiframeÔªËØµÄsandboxÊôÐÔ¡£sandboxÊôÐÔ¿ÉÒÔ·ÀÖ¹²»ÐÅÈεÄWebÒ³ÃæÖ´ÐÐijЩ²Ù×÷¡£
HTML
5
¹æ·¶µÄ±à¼Ian Hickson̸µ½ÁË
sandboxµÄºÃ´¦
£¬Ëü¿ÉÒÔ·ÀÖ¹ÈçϲÙ×÷£º
·ÃÎʸ¸Ò³ÃæµÄDOM£¨´Ó¼¼Êõ½Ç¶ÈÀ´Ëµ£¬ÕâÊÇÒòΪÏà¶ÔÓÚ¸¸Ò³ÃæiframeÒѾ³ÉΪ²»Í¬µÄÔ´ÁË£©
Ö´Ðнű¾
ͨ¹ý½Å±¾Ç¶Èë×Ô¼ºµÄ±íµ¥»òÊDzÙ×Ý±íµ¥
¶Ôcookie¡¢±¾µØ´æ´¢»ò±¾µØSQLÊý¾Ý¿âµÄ¶Áд
HTML
5µÄÐÞ¶©ÀúÊ·Ò³Ãæ
»¹Ìáµ½ÁËsandboxµÄÆäËûÌØÐÔ£º
½ûÓòå¼þ
½ûÖ¹ÆäËûä¯ÀÀÉÏÏÂÎĵĵ¼º½
½ûÖ¹µ¯³ö´°¿ÚºÍģʽ¶Ô»°¿ò
iFramesÒò°²È«ÎÊÌâ¶ø³ôÃûÕÑÖø£¬ÕâÖ÷ÒªÊÇÒòΪiFrames³£³£±»ÓÃÓÚǶÈëµÚÈý·½ÄÚÈÝ£¬¶øºóÕßÔò¿ÉÄÜ»áÖ´ÐÐijЩ¶ñÒâ²Ù×÷¡£sandboxͨ¹ý
ÏÞÖÆ±»Ç¶ÈëÄÚÈÝËùÔÊÐíµÄ²Ù×÷¶øÌáÉýiFramesµÄ°²È«ÐÔ¡£ÕâÖÖ·½Ê½½«É³ÏäÄÚÈÝÓë¸¸Ò³Ãæ½øÐÐÁË·ÖÀ룬Òò´ËÏÞÖÆÁ˱»Ç¶ÈëÄÚÈݵÄȨÏÞ¡£
ÓësandboxÒ»Æð³öÀ´µÄ»¹ÓÐÆäMIMEÀàÐÍ£ºtext/html-sandboxed¡£Hickson˵µ½£º
text/html-sandboxed
MIMEÀàÐÍÈ·±£Óû§²»»á·ÃÎʵ½²»¿ÉÐŵÄÄÚÈÝ¡£Ëü°üº¬Á½²¿·ÖÄÚÈÝ£ºÊ×ÏÈ£¬Èç¹ûÓû§Ö±½Ó·ÃÎÊÒ³ÃæÊ±£¬ä¯ÀÀÆ÷²»¿ÉÒÔäÖȾÄÇЩ¾ßÓÐtext/html-
sandboxed
MIMEÀàÐ͵ÄÒ³Ãæ¡£Ä¿Ç°ËùÓÐä¯ÀÀÆ÷¶¼Ö§³ÖÕâÒ»µã£¬ÕâЩä¯ÀÀÆ÷»áÏÂÔØÒ³ÃæµÄ±ê¼Çµ«²»»áäÖÈ¾Ò³Ãæ£»Æä´Î£¬Ö§³ÖsandboxÊôÐÔµÄä¯ÀÀÆ÷ÐèÒªäÖȾ¾ßÓÐ
text/html-sandboxed
MIMEÀàÐ͵Äiframes£¨µ«»áÊܵ½sandboxÊôÐÔÖÐËùÉ趨µÄȨÏÞÏÞÖÆ£©Ä¿Ç°ÎªÖ¹£¬»¹Ã»ÓÐä¯ÀÀÆ÷ʵÏÖÕâÒ»µã£¬Google
ChromeÒ²ÊÇÈç´Ë£¨Ëü»áäÖȾ¸¸Ò³Ã棬µ«È´ÏÂÔØiframeÄÚÈݶø·ÇÔÚiframeÖÐ¶ÔÆä½øÐÐäÖȾ£©¡£Òò´ËĿǰ»¹Ã»·¨Ê¹ÓøÃÏî¼¼Êõ£¬³ý·ÇGoogle¸ü
ÐÂChromeÒÔÖ§³ÖÕâÒ»µã£¨´ÓÀíÂÛÉÏÀ´Ëµ£¬ÆäËûµÄä¯ÀÀÆ÷³§ÉÌÔÚʵÏÖÁ˶ÔsandboxÊôÐÔµÄÖ§³Öºó¾Í»áʵÏָü¼Êõ£¬ÈÃÎÒÃÇÊÃÄ¿ÒÔ´ý°É£©¡£
Ŀǰ£¬Ö»ÓÐGoogle Chrome
4.0ʹÓÃÁËsandbox£¬Firefox¡¢IE8ºÍSafari¶¼»¹Ã»ÓÐʵÏÖÕâÒ»µã£¬µ«ÏàÐŲ»¾ÃÖ®ºóÕâЩä¯ÀÀÆ÷¶¼»áʵÏֵġ£Î§ÈÆ×ÅHTML 5
<video>ÔªËØ·¢ÉúÁ˺ܶàÊÂÇé
£¬Googleͨ¹ýH.264
±ê×¼¶ÔÆä½øÐÐʵÏÖ£¬¶ø
Ïà¹ØÎĵµ£º
<html:link> ±êÇ©ÓÃÓÚÉú³ÉHTML <a> ÔªËØ¡£<html:link> ÔÚ´´½¨³¬Á´½Óʱ£¬ÓÐÁ½¸öÓŵ㣺
(1) ÔÊÐíÔÚURL ÖÐÒÔ¶àÖÖ·½Ê½°üº¬ÇëÇó²ÎÊý¡£
(2) µ±Óû§ä¯ÀÀÆ÷¹Ø±ÕCookie ʱ£¬»á×Ô¶¯ÖØÐ´URL£¬°ÑSessionID ×÷ΪÇëÇó²ÎÊý°üº¬ÔÚURL ÖУ¬ÓÃÓÚ¸ú×ÙÓû§µÄSession ״̬¡£
<ht ......
·ÃÎʿؼþµÄÖ÷Òª¶ÔÏóÊÇ:document¶ÔÏó¡£·Ö±ð¶ÔÓ¦µ±Ç°ÎĵµËùÓеģ¨×Ó¶ÔÏ󣩸öÈ˹۵㡣²¢ÇÒÒѾÌṩµÄ¼¸¸öÖ÷Òª·½·¨À´·ÃÎʶÔÏó¡£
1. document.getElementById
2. document.getElementsByName
3 &n ......
Êó±êµÄ¶àÖÖÑùʽ...
<P><a href="help.htm" style="cursor:hand">ÊÖ</a>
<a href="help.htm" style="cursor:text">Îı¾</a>
<a href="help.htm" style="cursor:MOVE">Ëĸö·½ÏòµÄ¼ýÍ·</a>
<a href="help.htm" st ......
µ±HTML¿Ø¼þµÄid="ctl00_contentPlaceHolder_ddl_academy",name="ctl00$contentPlaceHolder$ddl_academy"ʱ
Request.Form["ctl00$contentPlaceHolder$ddl_academy"]¶ø²»ÊÇ
Request.Form["ctl00_contentPlaceHolder_ddl_academy"] ......
<%@LANGUAGE="VBSCRIPT" CODEPAGE="936"%>
<%
Option Explicit
Response.Buffer = True '»º´æÍ¼Æ¬
Dim objXMLHTTP, XML
Set XML = Server.CreateObject("Microsoft.XMLHTTP") '½¨Á¢ÏÂÔØ¶ÔÏó
XML.Open "GET","http://www.google.cn/images/nav_logo7.png",False '¿ªÊ¼»ñȡͼƬ,http://xxx/pngÕâ½Ú¿ÉÒԸijÉ× ......