Description
BOSH can be used in setups where the BOSH webapp is not on the same domain as the BOSH server. Browsers have restrictions to not allow AJAX-POST calls across origins, which is exactly what BOSH needs in those cases.
So, today, our BoshServlet supports flxhr (AJAX over Flash) by returning a crossdomain.xml file with information about allowed CORS domains.
Another, more modern and future prove way is to return CORS HTTP Headers, as described here:
http://en.wikipedia.org/wiki/Cross-origin_resource_sharing