As far as I can see, it seems reasonable for a browser to allow sending requests to a different domain as long as there are no cookies being sent to that domain.
Cros