The invention provides a new mechanism which is used to protect all
internal resources against requests from sandboxed scripts. In the
preferred embodiment, the mechanism is implemented for SOAP calls by
untrusted scripts. When an attempt is made to access a resource at a
previously-unknown URI, the sandbox reads a file at that domain with
declarations to determine whether access is permitted to the script. If
the file is not found, the access is denied.