{"title":"Security of CORS on LocalStorage","authors":"Ningxian Zhu","doi":"10.1109/IEIT53597.2021.00038","DOIUrl":null,"url":null,"abstract":"HTML5 is the next generation of web application. Its LocalStorage solves some problems that can use cookies alone, but also brings new potential safety vulnerabilities because of using CORS. This paper discuss basic principle for using CORS in LocalStorage, compare several different cross-domain schemes, focus on existing security risks in CORS. A test case is designed for further analysis how to protect user privacy information, and put forward a practical scheme and some strategy on using CORS. Finally, a solution of using CORS is summed up, and also give some suggestions to security of CORS.","PeriodicalId":321853,"journal":{"name":"2021 International Conference on Internet, Education and Information Technology (IEIT)","volume":"198 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-04-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 International Conference on Internet, Education and Information Technology (IEIT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IEIT53597.2021.00038","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
HTML5 is the next generation of web application. Its LocalStorage solves some problems that can use cookies alone, but also brings new potential safety vulnerabilities because of using CORS. This paper discuss basic principle for using CORS in LocalStorage, compare several different cross-domain schemes, focus on existing security risks in CORS. A test case is designed for further analysis how to protect user privacy information, and put forward a practical scheme and some strategy on using CORS. Finally, a solution of using CORS is summed up, and also give some suggestions to security of CORS.