Enable this for websites within the same domain only. Also, fixes CheckSameOriginPrincipal to just check the principals, and not care whether we have anything on the JS stack. r=mstoltz, sr=jst git-svn-id: svn://10.0.0.236/trunk@143900 18797224-902f-48f8-a5cc-f745e15eee43