Flash Player 9,0,124 的安全性更新
Flash Player 9,0,124 這個版本加強了一些安全性相關的限制.
http://www.adobe.com/devnet/flashplayer/articles/flash_player9_security_update.html#policy_file
http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security_03.html
主要這幾個. 如果不注意會對一些應用產生奇怪的現象.
1. 我遇到的一個是自己增加httpheader內容后引發的.
crossdomain.xml的DTD
<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- Adobe DTD for cross-domain policy files -->
<!-- Copyright (c) 2008, Adobe Systems Inc. -->
<!ELEMENT cross-domain-policy (site-control?,allow-access-from*,allow-http-request-headers-from*)>
<!ELEMENT site-control EMPTY>
<!ATTLIST site-control permitted-cross-domain-policies (all|by-content-type|by-ftp-filename|master-only|none) #REQUIRED>
<!ELEMENT allow-access-from EMPTY>
<!ATTLIST allow-access-from domain CDATA #REQUIRED>
<!ATTLIST allow-access-from to-ports CDATA #IMPLIED>
<!ATTLIST allow-access-from secure (true|false) "true">
<!ELEMENT allow-http-request-headers-from EMPTY>
<!ATTLIST allow-http-request-headers-from domain CDATA #REQUIRED>
<!ATTLIST allow-http-request-headers-from headers CDATA #REQUIRED>
<!ATTLIST allow-http-request-headers-from secure (true|false) "true">
<!-- End of file. -->
注意一下這個東西就可以了
http://www.adobe.com/devnet/flashplayer/articles/flash_player9_security_update.html#policy_file
http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security_03.html
主要這幾個. 如果不注意會對一些應用產生奇怪的現象.
1. 我遇到的一個是自己增加httpheader內容后引發的.
crossdomain.xml的DTD
<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- Adobe DTD for cross-domain policy files -->
<!-- Copyright (c) 2008, Adobe Systems Inc. -->
<!ELEMENT cross-domain-policy (site-control?,allow-access-from*,allow-http-request-headers-from*)>
<!ELEMENT site-control EMPTY>
<!ATTLIST site-control permitted-cross-domain-policies (all|by-content-type|by-ftp-filename|master-only|none) #REQUIRED>
<!ELEMENT allow-access-from EMPTY>
<!ATTLIST allow-access-from domain CDATA #REQUIRED>
<!ATTLIST allow-access-from to-ports CDATA #IMPLIED>
<!ATTLIST allow-access-from secure (true|false) "true">
<!ELEMENT allow-http-request-headers-from EMPTY>
<!ATTLIST allow-http-request-headers-from domain CDATA #REQUIRED>
<!ATTLIST allow-http-request-headers-from headers CDATA #REQUIRED>
<!ATTLIST allow-http-request-headers-from secure (true|false) "true">
<!-- End of file. -->
注意一下這個東西就可以了