How to prevent ads from accessing and changing data on my own website

Viewed 35

Suppose the Javascript on my site has data in the localStorage like this:

<script>
    localStorage['my_website'] = "https://my_website.com";
</script>
<script type="text/javascript" src="https://bad_website.com/bad.js"></script>

The bad.js from another site can read and write the localStorage['my_website']. That is quite surprising to me because I thought the same-origin policy is enforced by every browser automatically. Am I missing something totally?

If the bad.js can change the business logic of your Javascript, does that mean the ads run by your website can change many parts of your website?

Anyway, could you please comment on the issue? Do I have to do something to prevent cross domain access?

Thanks.

0 Answers
Related