Preview ?!?

What you may have noticed is that the security-level is (default) higher
on javascript running from a file your local machine, which may seem strange
but makes sense when you think about it, since it's "closer" to your "ressources".
So a cross-frame script could "upload" files on your disk to a site somewhere.
- But this new security feature can be bypassed by selecting
[ ] Allow active content to run on "this computer"