You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AS3本地运行SWF遭遇SecurityError #2121安全沙箱违规求助

解决Flash本地加载远程SWF的SecurityError #2121问题

问题概述

本地运行SWF(file://协议)加载远程HTTPS的SWF时触发以下安全沙箱错误:

SecurityError: Error #2121: Security sandbox violation: LoaderInfo.content: file:///C|/Users/Admin/Desktop/whatever.swf cannot access https://content.mspcdns.com/swf/headwear/story_2022_girlhat_tk.swf. This may be worked around by calling Security.allowDomain.
    at flash.display::LoaderInfo/get content()
    at Function/com.mspicker.utils:SWFLoader/loadSWF/com.x.utils:onComplete()[C:\Users\x\Adobe Flash Builder 4.6\whatever\src\com\x\utils\SWFLoader.as:77]

目标域content.mspcdns.com的crossdomain.xml已配置为完全开放:

<?xml version="1.0"?>
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*" secure="false"/>
<allow-http-request-headers-from domain="*" headers="*" secure="false"/>
</cross-domain-policy> 

核心原因

本地file://沙箱的SWF受严格安全限制,直接调用Security.allowDomain无法突破该限制,必须通过LoaderContext明确配置安全策略,让加载的远程SWF获得访问许可。

修复方案

修改loadSWF函数,重点调整LoaderContext配置并修正安全策略加载逻辑:

修正后的代码

public function loadSWF(param1: String):void {
    var fullUrl:String = param1;
    var loader:Loader = new Loader();
            
    // 提前加载目标域的跨域策略文件,确保加载SWF前获取许可
    Security.loadPolicyFile("https://content.mspcdns.com/crossdomain.xml");
    
    // 配置LoaderContext,核心是设置安全域关联
    var context:LoaderContext = new LoaderContext();
    context.allowCodeImport = true;
    // 关键:将远程SWF纳入本地SWF的安全域,消除沙箱隔离
    context.securityDomain = SecurityDomain.currentDomain;
    context.allowLoadBytesCode = true;
            
    loader.contentLoaderInfo.addEventListener(Event.COMPLETE, onComplete);
            
    try {
        loader.load(new URLRequest(fullUrl), context);
    } catch(error:Error) {
        ErrorHandler.triggerError("error", "Could not load SWF file!");
        return;
    }
            
    function onComplete(e:Event):void {
        var movie:MovieClip = new MovieClip();
        try {
            movie = e.currentTarget.content as MovieClip;
            // 类型转换失败则触发后续Bitmap转换逻辑
            if(!movie) throw new Error("Content is not a MovieClip");
        } catch(error:Error) {
            var content:DisplayObject = e.currentTarget.content as DisplayObject;
            if(content) {
                var bitmapData:BitmapData = new BitmapData(content.width, content.height, true, 0x00000000);
                bitmapData.draw(content);
                var bitmap:Bitmap = new Bitmap(bitmapData);
                movie.addChild(bitmap); 
            }
        }
                
        movie.x = 25;
        movie.y = 30;
        stage.addChild(movie);
    }
}

关键修改说明

  • 提前加载策略文件:将Security.loadPolicyFile放在loader.load之前,确保Flash优先获取跨域许可。
  • 关联安全域:context.securityDomain = SecurityDomain.currentDomain 让远程SWF使用本地SWF的安全域,避免沙箱隔离导致的content访问限制。
  • 移除无效调用:原代码中Security.allowDomain(loader.contentLoaderInfo.url)在加载前调用无效(此时URL未赋值),直接移除即可。
  • 类型安全判断:增加类型转换校验,避免不必要的错误抛出。

额外注意事项

  • 本地运行时,需在Flash Player设置管理器中开启「允许本地文件访问网络」(路径:高级→开发人员设置)。
  • 若问题仍存在,可将本地SWF部署到HTTP服务器(如XAMPP)上运行,规避file://协议的沙箱限制。

内容的提问来源于stack exchange,提问作者allesmoegliche

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 06:10:32