single origin policy

Hi guys,
i am working on developing a sample application. it has problems when i trying to access loading page from iframe

according to SOP [Single Origin Policy] a java script executing in page A can manipuate the dom tree of page b if a is embeded in the iframe tag of B and A , b have the same domain

am i wrong

please can anyone have a right answer
hard2u2001Connect With a Mentor Commented:
yes you can always manipulate the dom tree of iframe or parent frame if and only if both A and B are from same domain.

Though there are some complicated solutions if you want to use different domains,
but for that also u should have control over both the domains.

see the solution :
hard2u2001Connect With a Mentor Commented:
As By Google Code

What is the Single Origin Policy?

Modern browsers implement a security model known as the "Single Origin Policy" (SOP). Conceptually, it is very simple, but the limitations it applies to JavaScript applications can be quite subtle.

Simply stated, the SOP states that JavaScript code running on a web page may not interact with any resource not originating from the same web site. The reason this security policy exists is to prevent malicious web coders from creating pages that steal web users' information or compromise their privacy. While very necessary, this policy also has the side effect of making web developers' lives difficult.
Michel PlungjanConnect With a Mentor IT ExpertCommented:
NOTE: a change of port or protocol is ALSO seen as a different server

To bypass, you need to set up a server proxy or pass info in the attribute
emeraldpiggyAuthor Commented:
yeah according to google, I thought we can manipulate the Dom tree  of page B if A is embeded in the iframe tag of B  and (A B have the same domain)
emeraldpiggyAuthor Commented:
thanks that helps
