草案中给出了一点点说明,试想在"web"早期,如果"script"不能跨域,那这样对构建"web"来说就太困难了,要知道那时候依赖很多第三方"js"库是家常便饭。
简单来说,算是一种妥协,
"why-is-the-html-script-tag-not-subject-to-the-same-origin-policy" (https://link.segmentfault.com/?enc=xsKdQ8zPTx7hnmwtkKCvZg%3D%3D.ABOKGPjFMOyqzMpTBOvXWgV9GXXYHyLsOvrW8WgHaKECSWeLpZnO64TL7hDg%2Bf7VfnzsQLHp2NLF9%2B2wT6koznW3%2BVjijf0WbevqForaW7pgCKa2yZmijalTAldn4cCIw5aoJUyXTAJ0RajAkqyZOg%3D%3D)