In the same origin policy , the host must exactly match (so it should have a protocol and port, but that's aloof). If a sufficient suffix can be sufficient, foo.com will be considered "the same origin" as bar.com , or fie.co.uk in the same way as flap.co.uk , etc., completely destroying the purpose of the policy.
I understand what you think of www.blah.com as being βcloserβ to whatever.blah.com than the examples I gave, but itβs just not so - think of all the countless something.appspot.com domains on which launched Google App Engine applications from myriads, for example, from different authors who have absolutely no connection.
source share