Is this something restricted by cross-origin policy or not?
You can't. You could only sent requests to www.foo.com.
www.foo.com