Suppose the Javascript on my site has data in the localStorage like this:
<script>
localStorage['my_website'] = "https://my_website.com";
</script>
<script type="text/javascript" src="https://bad_website.com/bad.js"></script>
The bad.js from another site can read and write the localStorage['my_website']. That is quite surprising to me because I thought the same-origin policy is enforced by every browser automatically. Am I missing something totally?
If the bad.js can change the business logic of your Javascript, does that mean the ads run by your website can change many parts of your website?
Anyway, could you please comment on the issue? Do I have to do something to prevent cross domain access?
Thanks.