templates/project/files/crossdomain.xml in html5-boilerplate-0.2.4 vs templates/project/files/crossdomain.xml in html5-boilerplate-0.2.5
- old
+ new
@@ -1,16 +1,25 @@
<?xml version="1.0"?>
-<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
+<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
- <!--
- If you host a crossdomain.xml file with allow-access-from domain=“*”
- and don’t understand all of the points described here, you probably
- have a nasty security vulnerability. ~ simon willison
-
- Please read: www.adobe.com/devnet/flashplayer/articles/cross_domain_policy.html
-
- <allow-access-from domain="*" to-ports="*" />
-
- -->
-</cross-domain-policy>
+
+
+<!-- Read this: www.adobe.com/devnet/articles/crossdomain_policy_file_spec.html -->
+<!-- Most restrictive policy: -->
+ <site-control permitted-cross-domain-policies="none"/>
+
+
+
+<!-- Least restrictive policy: -->
+<!--
+ <site-control permitted-cross-domain-policies="all"/>
+ <allow-access-from domain="*" to-ports="*" secure="false"/>
+ <allow-http-request-headers-from domain="*" headers="*" secure="false"/>
+-->
+<!--
+ If you host a crossdomain.xml file with allow-access-from domain=“*”
+ and don’t understand all of the points described here, you probably
+ have a nasty security vulnerability. ~ simon willison
+-->
+</cross-domain-policy>
\ No newline at end of file