A policy of the same origin says that scripts running on some source cannot read resources from another source. (Origin is a domain, plus a schema and port, for example http://foo.example.com:80.)
, . , -. <img>: example.com other.com, script on example.com . ; .
API - . , . -, script . - script (, ), . , , , .
, Chrome cross-origin , .
, - HTTP CORS Access-Control-Allow-Origin: *. Firefox, . Firefox , .