In flex help documentation it is mentioned that if swf file
is loaded from a website which is listed trusted in browser, then
it acts as if file in local trusted sandbox.
But it does not work. Has anyone tried it?
Here is the help quote:
"Trusted sites and directories
The browser security model includes levels of trust applied
to specific websites. Flash Player interacts with this model by
assigning a sandbox based on whether the browser declared the site
of the SWF file's origin trusted.
If Flash Player loads a SWF file from a trusted website, the
SWF file is put in the local-trusted sandbox. The SWF file can read
from local data sources and communicate with the Internet."
But the scenario is a sfollows. I have two web server running
on a host. one is apache and another is wsman(Windows remote mgmt
I place swf file under apache root. Now this swf has to
access data from same host but from wsman server.
swf url is
http://host:apacheport/my.swf wsman url is
Ws man server does not allow any kind of file to place at its
root and accept just the POST request.
So I could not use cross domain file under wsman.
Now as per flex documentation if I include host in the
trusted list of the browser, it does not need cros domain.
But it does not work. Did they changed the policy for new