spacer

Webref WebRef   Sitemap · Experts · Tools · Services · Newsletters · About i.com

home / experts / javascript / column39


IE 5.0 Review, Part V: HTML Applications (HTAs) (5)

Developer News
Mandrake Linux Founder Back, Virtually
Amazon: We're a Technology Company
Sun Expands MySQL With Closed Source

Trusting HTAs

One of the main advantages of HTAs over regular Web pages, is that they are fully trusted. As such, HTAs are allowed actions that Internet Explorer would never approve of for Web pages. The bottom line is that HTAs do not bother the user with questions and interruptions. They are fully trusted.

There are several implications for being a trusted application. HTAs have read/write access to the system registry on the client machine. HTAs run embedded ActiveX controls and Java applets without any warning. Zone security is off for HTAs, so all operations subject to security zone options are nevertheless permitted for HTAs.

The immediate question one may ask is what happens to content in other domains that the HTA window communicates with. Luckily, HTAs extend their trusted privileges to content in other domains. For example, HTAs allow script access between window objects and cookies. Things get stickier when you use FRAMEs and IFRAMEs. The new APPLICATION attribute should be used to signal if the FRAME or IFRAME is trusted or not. Unless the APPLICATION attribute is set to yes, the FRAMEs or IFRAMEs have no script access to the HTA containing them. In addition, several rules are imposed on the untrusted FRAMEs and IFRAMEs. The top level frames of the window behave like the top window. You cannot go from a top-level FRAME to the window containing it. For such a FRAME, window.top and window.self are identical. Also, FRAMEs an IFRAMEs permit neither a referrer nor an opener URL from the parent HTA. This is the way to to keep unsecure data away from a trusted window.

If all content is safe, the APPLICATON attribute can be set to "on" for all FRAMEs and IFRAMEs of the application:

<IFRAME SRC="filename.htm" APPLICATON="yes">

The above IFRAME is permitted to pass information back to its parent window, while the following one doesn't:

<IFRAME SRC="filename.htm" APPLICATON="no">

This IFRAME should be implemented as regular HTML. It is also subject to the security setting for its zone.

When you run your HTAs, be sure to take the same precuations as with any executable. Only Install HTAs produced by reliable sources such as your intranet at work, established software vendor, and, of course, Doc JavaScript.

http://www.internet.com

Produced by Yehuda Shiran and Tomer Shiran

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Whitepapers and eBooks

Intel Whitepaper: Comparing Two- and Four-Socket Platforms for Server Virtualization
IBM Solutions Brief: Go Green With IBM System xTM And Intel
HP eBook: Simplifying SQL Server Management
IBM Contest: Are You the Next Superstar? Join the "Search for the XML Superstar" Contest to Find Out
Microsoft PDF: Top 10 Reasons to Move to Server Virtualization with Hyper-V
Microsoft PDF: Six Reasons Why Microsoft's Hyper-V Will Overtake Vmware
Microsoft Step-by-Step Guide: Hyper-V and Failover Clustering
Intel PDF: Quad-Core Impacts More Than the Data Center
Intel PDF: Virtualization Delivers Data Center Efficiency
Go Parallel Article: PDC 2008 in Review
Microsoft PDF: Top 11 Reasons to Upgrade to Windows Server 2008
Avaya Article: Communication-Enabled Mashups: Empowering Both Business Owners and IT
Intel Whitepaper: Building a Real-World Model to Assess Virtualization Platforms
  PDF: Intel Centrino Duo Processor Technology with Intel Core2 Duo Processor
Microsoft Article: Build and Run Virtual Machines with Hyper-V Server 2008
Go Parallel Article: Q&A with a TBB Junkie
IBM Whitepaper: Innovative Collaboration to Advance Your Business
Internet.com eBook: Real Life Rails
IBM eBook: The Pros and Cons of Outsourcing
Internet.com eBook: Best Practices for Developing a Web Site
IBM CXO Whitepaper: The 2008 Global CEO Study "The Enterprise of the Future"
Avaya Article: Call Control XML in Action - A CCXML Auto Attendant
IBM CXO Whitepaper: Unlocking the DNA of the Adaptable Workforce--The Global Human Capital Study 2008
Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
HP eBook: Guide to Storage Networking
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
webref The latest from WebReference.com Browse >
Popular JavaScript Framework Libraries: An Overview - Part 3 · Accessing Your MySQL Database from the Web with PHP · Working with the DOM Stylesheets Collection
Sitemap · Experts · Tools · Services · Email a Colleague · Contact FREE Newsletters 
 The latest from internet.com
Crucial Triples Up With New Three-Channel DDR3 Kits · Meet the Finalists: Excellence in Technology Awards · Tealeaf Offers Insight to Mobile Customer Behavior


Created: May 10, 1999
Revised: May 10, 1999

URL: http://www.webreference.com/js/column39/trust.html