A method for an HTML document to access local system resources, which
receives an HTTP request and judges whether the HTTP request includes a
predetermined keyword. A system-resource-accessing portion of the HTTP
request is processed when the HTTP request includes the predetermined
keyword. Then, the HTTP request is checked whether it contains a Referer
field. If the header of the HTTP request includes the Referer field, the
HTTP request will be treated as an external request, and the local system
resource accessing will be denied even when the HTTP request includes the
predetermined keyword.