This page is loaded on a different origin (in a real attack, attacker.tld). Here it just demonstrates the same-origin case, but origin is never checked.
Click Steal Config to send {action:"getConfig"} to the widget
without any origin check:
Result will appear here...