Wednesday, September 4, 2013

IE10 Cross domain issue - Access Denied error while making xhr call

The IE10 supports CORS fully. 
In some cases user may face "Access denied" while making a xhr call. 
Let me try to explain the scenario where the user will get "Access denied" error-

Before that we should be aware of the two terminology -

Origin : domain hosting the script content
Host : the domain requested by xhr call

Let the Origin in our case be * & Host be *

Now either both domains should be in the IE10 trusted site domain list or both should not be present in the list. To go to the IE trusted site settings, Go to Internet options -> Security -> Select trusted sites option & click on Sites(button). It will show all the trusted websites (domain)

If one of the Origin/ Host is present in the trusted site domain list, then the user will get Access denied error while making xhr call in the native open method of javascript. for example user will get Access denied error while making xhr call to * from the script hosted/running on *

Cross domain reference link from MS blog -CORS for XHR in IE10

Working cross domain example - Cross-Site Upload
In the cross site upload example -

Origin -
Host -

If we put either the Origin or Host in the Trusted Sites domain then while making the xhr call, Access Denied error will prevent file upload operation.


    After 2 days of searching and seeing dozens of questions about this problem without answers... the answer is here, and so simple!

    1. Good to hear that it helped you.

    2. The effectiveness of IEEE Project Domains depends very much on the situation in which they are applied. In order to further improve IEEE Final Year Project Domains practices we need to explicitly describe and utilise our knowledge about software domains of software engineering Final Year Project Domains for CSE technologies. This paper suggests a modelling formalism for supporting systematic reuse of software engineering technologies during planning of software projects and improvement programmes in Final Year Projects for CSE.

      Software management seeks for decision support to identify technologies like JavaScript that meet best the goals and characteristics of a software project or improvement programme. JavaScript Training in Chennai Accessible experiences and repositories that effectively guide that technology selection are still lacking.

      Aim of technology domain analysis is to describe the class of context situations (e.g., kinds of JavaScript software projects) in which a software engineering technology JavaScript Training in Chennai can be applied successfully

      The Angular Training covers a wide range of topics including Components, Angular Directives, Angular Services, Pipes, security fundamentals, Routing, and Angular programmability. The new Angular TRaining will lay the foundation you need to specialise in Single Page Application developer. Angular Training

  2. Thank you! Helped us while performing a critical deployment test at our customer.

    1. Glad that it helped you during your deployment !!!

  3. Hey, great blog, but I don’t understand how to add your site in my rss reader. Can you Help me please? video streaming

    1. Thanks Calvin.
      You can add the following URL is your RSS feed to get the update from the blog -

  4. This comment has been removed by the author.

  5. Awesome bro... this is the single place where a real solution to this issue is discussed.

  6. Yes, but how to get around this?
    How is it that adding a domain to TRUSTED SITES, dammit, produces "access denied" error?
    This is as counter-intuitive as it gets!

  7. Bluehost is ultimately one of the best hosting company with plans for any hosting needs.

  8. No matter if you admit it or not, the world of technology is changing at a rapid pace. One of the problems of this change is not knowing who is calling you and why. This could happen because you misplaced your address book, may be you have a lot of free phonecalls that you may receive or you might want to know where your kids are calling from.