This concept is pretty much how I started with SockJS. I realized that by using the iframe/postmessage it is possible to get decent "realtime" in all the browsers. For example Opera had EventSource but it didn't support cross domain. But it did support iframe/postmessage....
To make things even more exciting the iframe was loaded with proper (third party) cookies, so it is theoretically possible to use cookie-based authorization (at least to some extent).
Cookies are also required in long-polling scenarios to get sticky sessions, think: JSESSIONID.
But the problem is browsers nowadays block third party cookies and CORS just works, so there is _no_ need for the postmessage hack. Sadly...
This concept is pretty much how I started with SockJS. I realized that by using the iframe/postmessage it is possible to get decent "realtime" in all the browsers. For example Opera had EventSource but it didn't support cross domain. But it did support iframe/postmessage....
To make things even more exciting the iframe was loaded with proper (third party) cookies, so it is theoretically possible to use cookie-based authorization (at least to some extent).
Cookies are also required in long-polling scenarios to get sticky sessions, think: JSESSIONID.
But the problem is browsers nowadays block third party cookies and CORS just works, so there is _no_ need for the postmessage hack. Sadly...