Wayback Machinekoobas.hobune.stream
May JUN Jul
Previous capture 13 Next capture
2021 2022 2023
1 capture
13 Jun 22 - 13 Jun 22
sparklines
Close Help
  • Products
  • Solutions
  • Made with Unity
  • Learning
  • Support & Services
  • Community
  • Asset Store
  • Get Unity

UNITY ACCOUNT

You need a Unity Account to shop in the Online and Asset Stores, participate in the Unity Community and manage your license portfolio. Login Create account
  • Blog
  • Forums
  • Answers
  • Evangelists
  • User Groups
  • Beta Program
  • Advisory Panel

Navigation

  • Home
  • Products
  • Solutions
  • Made with Unity
  • Learning
  • Support & Services
  • Community
    • Blog
    • Forums
    • Answers
    • Evangelists
    • User Groups
    • Beta Program
    • Advisory Panel

Unity account

You need a Unity Account to shop in the Online and Asset Stores, participate in the Unity Community and manage your license portfolio. Login Create account

Language

  • Chinese
  • Spanish
  • Japanese
  • Korean
  • Portuguese
  • Ask a question
  • Spaces
    • Default
    • Help Room
    • META
    • Moderators
    • Topics
    • Questions
    • Users
    • Badges
  • Home /
avatar image
0
Question by greg_leanplum · Jun 14, 2013 at 09:37 PM · editorsecuritycrossdomainsecuritysandbox

Cross-domain policy for specific folder/URL

We're providing a service for app developers to be able to easily stream new content to their game, by providing an editor extension that bundles assets and uploads them to our service.

This is done by posting it to website.com/api via a binary element of WWWForm. Unity blocks this inside the editor saying "no cross-domain policy" (http://docs.unity3d.com/Documentation/Manual/SecuritySandbox.html)

We're able to get around that by adding the crossdomain policy file as suggested:

 <?xml version="1.0"?>
 <cross-domain-policy>
 <allow-access-from domain="*"/>
 </cross-domain-policy>

But that's a security risk since our login page is also on the same domain.

Adobe's standard actually lets you set policies by folders, as such:

domain.com/crossdomain.xml

 <?xml version="1.0"?>
 <cross-domain-policy>
 <site-control permitted-cross-domain-policies="all"/>
 </cross-domain-policy>

domain.com/api/crossdomain.xml

 <?xml version="1.0"?>
 <cross-domain-policy>
 <allow-access-from domain="*"/>
 </cross-domain-policy>

But Unity doesn't seem to even notice this. Here's the Editor.Log, after setting ENABLE_CROSSDOMAIN_LOGGING to 1

 Received policy
 Parsing: cross-domain-policy
 cross-domain-policy
 Parsing: site-control
 site-control
   permitted-cross-domain-policies: all
 done parsing policy
 crossdomain.xml was succesfully parsed
 About to parse url: http://localhost:8080/api/
 Rejected because there was no AllowedAcces entry in the crossdomain file allowing this request.
 Rejected because no crossdomain.xml policy file was found

Is there any way to set a policy for a specific folder/URL? It seems like our only option is to create a subdomain

Comment
Add comment
10 |3000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users

1 Reply

· Add your reply
  • Sort: 
avatar image
0

Answer by Graham-Dunnett · Jun 14, 2013 at 09:38 PM

Yes, your only option is to create a sub-domain.

Comment
Add comment · Share
10 |3000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users

Your answer

Hint: You can notify a user about this post by typing @username

Up to 2 attachments (including images) can be used with a maximum of 524.3 kB each and 1.0 MB total.

Follow this Question

Answers Answers and Comments

15 People are following this question.

avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image

Related Questions

Disabling Webplayer Security Sandbox in The Editor 0 Answers

The name 'Joystick' does not denote a valid type ('not found') 2 Answers

How to edit a enumerator in the editor? 2 Answers

How do I reference variables from one editor script in another 0 Answers

Need help with editor (script?) 1 Answer


Enterprise
Social Q&A

Social
Subscribe on YouTube social-youtube Follow on LinkedIn social-linkedin Follow on Twitter social-twitter Follow on Facebook social-facebook Follow on Instagram social-instagram

Footer

  • Purchase
    • Products
    • Subscription
    • Asset Store
    • Unity Gear
    • Resellers
  • Education
    • Students
    • Educators
    • Certification
    • Learn
    • Center of Excellence
  • Download
    • Unity
    • Beta Program
  • Unity Labs
    • Labs
    • Publications
  • Resources
    • Learn platform
    • Community
    • Documentation
    • Unity QA
    • FAQ
    • Services Status
    • Connect
  • About Unity
    • About Us
    • Blog
    • Events
    • Careers
    • Contact
    • Press
    • Partners
    • Affiliates
    • Security
Copyright © 2020 Unity Technologies
  • Legal
  • Privacy Policy
  • Cookies
  • Do Not Sell My Personal Information
  • Cookies Settings
"Unity", Unity logos, and other Unity trademarks are trademarks or registered trademarks of Unity Technologies or its affiliates in the U.S. and elsewhere (more info here). Other names or brands are trademarks of their respective owners.
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Spaces
  • Default
  • Help Room
  • META
  • Moderators
  • Explore
  • Topics
  • Questions
  • Users
  • Badges