Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.javascript > #17116
| Message-ID | <28208070.qZZrvzLHK0@PointedEars.de> (permalink) |
|---|---|
| From | Thomas 'PointedEars' Lahn <PointedEars@web.de> |
| Organization | PointedEars Software (PES) |
| Date | 2012-11-10 11:36 +0100 |
| Subject | Re: eval - how to |
| Newsgroups | comp.lang.javascript |
| References | <k7iqg9$n49$1@speranza.aioe.org> <2261899.gBobAo4G4S@PointedEars.de> <k7jtpr$jqo$1@speranza.aioe.org> <4265d7df-81e2-4c58-a16d-cafc435a1e88@j19g2000vba.googlegroups.com> |
| Followup-To | comp.lang.javascript |
Followups directed to: comp.lang.javascript
Asen Bozhilov wrote:
> Cezary Tomczyk wrote:
>> As for parsing JSON string and according to what wrote Asen. Quick
>> review of David Mark code bring me [1]:
>>
>> [...]
>> return function(s) { return (new Function('return (' + s + ')'))(); };
>> [...]
>
> Obviously the JSON string comes from your server, otherwise the AJAX
> call would fail to fetch the string duo to cross domain policy.
First of all, it is the Same Origin Policy (SOP; *origin*, i. e. protocol,
host, and port number must match). That aside, this argument is no longer
sound. XHR can be made cross-domain if the target domain allows it.
<http://en.wikipedia.org/wiki/Same_origin_policy>
> So the used approach according that is pretty safe. If you maintain
> safe JSON strings, you should not care about the security at all. If
> the strings come from the third parties, you could use the Crockford
> approach.
Even if it was not a cross-origin request, there is no guarantee that the
data are coming from the requested site. You can work around the SOP
yourself by setting up a transparent proxy for certain requests to your
server, and there can still be a man-in-the-middle (MITM)-attack when you
did not.
>> On the other hand, looked into the
>> codehttps://github.com/douglascrockford/JSON-js/blob/master/json2.js[2]
>> and I see much, much more complicated regexps and rest of code to check
>> JSON string before its evaluated.
>>
>> Now I am more confused than before. Why code [1] is so simple and code
>> [2] is so complicated?
>
> He uses regexps to filter invalid tokens in the JSON string. If there
> any invalid tokens the code throws a SyntaxError.
Which is, of course, no longer necessary to do manually in many cases as
that is what the built-in JSON.parse() does now.
> We have discussed it before in the group.
ACK.
PointedEars
--
Danny Goodman's books are out of date and teach practices that are
positively harmful for cross-browser scripting.
-- Richard Cornford, cljs, <cife6q$253$1$8300dec7@news.demon.co.uk> (2004)
Back to comp.lang.javascript | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-09 12:47 +0100
Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-09 05:53 -0800
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-09 22:28 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 10:23 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 11:15 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-11 00:35 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 20:34 +0100
Re: eval - how to Dr J R Stockton <reply1245@merlyn.demon.co.uk.invalid> - 2012-11-10 22:42 +0000
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-09 17:46 +0100
Re: eval - how to Tim Streater <timstreater@greenbee.net> - 2012-11-09 17:00 +0000
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-09 18:19 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-09 22:49 +0100
Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-09 16:40 -0800
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 11:36 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-10 13:29 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 13:55 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-10 14:17 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 20:50 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-10 22:54 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 15:22 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-11 16:24 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 19:23 +0100
Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-11 10:40 -0800
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 20:41 +0100
Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-11 13:34 -0800
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 23:03 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 10:21 +0100
Re: eval - how to SAM <stephanemoriaux.NoAdmin@wanadoo.fr.invalid> - 2012-11-10 04:16 +0100
csiph-web