Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Cool stuff!

This concept is pretty much how I started with SockJS. I realized that by using the iframe/postmessage it is possible to get decent "realtime" in all the browsers. For example Opera had EventSource but it didn't support cross domain. But it did support iframe/postmessage....

To make things even more exciting the iframe was loaded with proper (third party) cookies, so it is theoretically possible to use cookie-based authorization (at least to some extent).

Cookies are also required in long-polling scenarios to get sticky sessions, think: JSESSIONID.

But the problem is browsers nowadays block third party cookies and CORS just works, so there is _no_ need for the postmessage hack. Sadly...



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: