Confused on safety of allowing Fetch in Custom settings
Posted: Sun Apr 13, 2025 8:46 pm
I understand that enabling Fetch allows "other" sites to fetch from "this" site, at keast I think that is what it means. But that seems like something I would not want to do, so maybe I am confused. Hypothetically (not real site names) - and assume my default settings are nothing allowed.
I go www.mybroker.com, open up noscript settings, and see these sites:
...mybroker.com
private.mybroker.com
news.mybroker.com
somerandomsite.com
wallstdata.com
For each of these, I choose custom and allow scripts, media, and frames - but only when the top page matches ...mybroker.com
After the page refreshes, fetch is highlighted red for the some/all of the 3 mybroker.com rules, indicating fetch is needed.
So here is where I am confused. Let's say I want the scripts for subdomains of mybroker.com to be able to fetch from other mybroker.com subdomains, but I do NOT want somerandomsite.com or wallstdata.com to be able to fetch from mybroker.com (or subdomains) while I am on mybroker.com
If I enable fetch for private.mybroker.com does that allow scripts from somerandomsite.com or wallstdata.com make requests to fetch data from private.mybroker.com?
And worse (to me) if I enable fetch on ...mybroker.com, does that allow any other allowed scripts from somerandomsite.com and wallstdata.com to fetch data from mybroker.com and any of it's subdomains?
Again, keep in mind for all of these rules I will restrict them to only apply if the top site matches ...mybroker.com
I hope that all makes sense, and yes... feel free to call me paranoid as heck! Or Mr. Confused User. Or both.
Obviously, I would prefer replies from someone who really knows how this works, not from someone just guessing how it works.
Thanks!
I go www.mybroker.com, open up noscript settings, and see these sites:
...mybroker.com
private.mybroker.com
news.mybroker.com
somerandomsite.com
wallstdata.com
For each of these, I choose custom and allow scripts, media, and frames - but only when the top page matches ...mybroker.com
After the page refreshes, fetch is highlighted red for the some/all of the 3 mybroker.com rules, indicating fetch is needed.
So here is where I am confused. Let's say I want the scripts for subdomains of mybroker.com to be able to fetch from other mybroker.com subdomains, but I do NOT want somerandomsite.com or wallstdata.com to be able to fetch from mybroker.com (or subdomains) while I am on mybroker.com
If I enable fetch for private.mybroker.com does that allow scripts from somerandomsite.com or wallstdata.com make requests to fetch data from private.mybroker.com?
And worse (to me) if I enable fetch on ...mybroker.com, does that allow any other allowed scripts from somerandomsite.com and wallstdata.com to fetch data from mybroker.com and any of it's subdomains?
Again, keep in mind for all of these rules I will restrict them to only apply if the top site matches ...mybroker.com
I hope that all makes sense, and yes... feel free to call me paranoid as heck! Or Mr. Confused User. Or both.
Obviously, I would prefer replies from someone who really knows how this works, not from someone just guessing how it works.
Thanks!