Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.javascript > #17116

Re: eval - how to

Message-ID <28208070.qZZrvzLHK0@PointedEars.de> (permalink)
From Thomas 'PointedEars' Lahn <PointedEars@web.de>
Organization PointedEars Software (PES)
Date 2012-11-10 11:36 +0100
Subject Re: eval - how to
Newsgroups comp.lang.javascript
References <k7iqg9$n49$1@speranza.aioe.org> <2261899.gBobAo4G4S@PointedEars.de> <k7jtpr$jqo$1@speranza.aioe.org> <4265d7df-81e2-4c58-a16d-cafc435a1e88@j19g2000vba.googlegroups.com>
Followup-To comp.lang.javascript

Followups directed to: comp.lang.javascript

Show all headers | View raw


Asen Bozhilov wrote:

> Cezary Tomczyk wrote:
>> As for parsing JSON string and according to what wrote Asen. Quick
>> review of David Mark code bring me [1]:
>>
>> [...]
>> return function(s) { return (new Function('return (' + s + ')'))(); };
>> [...]
> 
> Obviously the JSON string comes from your server, otherwise the AJAX
> call would fail to fetch the string duo to cross domain policy.

First of all, it is the Same Origin Policy (SOP; *origin*, i. e. protocol, 
host, and port number must match).  That aside, this argument is no longer 
sound.  XHR can be made cross-domain if the target domain allows it.

<http://en.wikipedia.org/wiki/Same_origin_policy>

> So the used approach according that is pretty safe. If you maintain
> safe JSON strings, you should not care about the security at all. If
> the strings come from the third parties, you could use the Crockford
> approach.

Even if it was not a cross-origin request, there is no guarantee that the 
data are coming from the requested site.  You can work around the SOP 
yourself by setting up a transparent proxy for certain requests to your 
server, and there can still be a man-in-the-middle (MITM)-attack when you 
did not.
 
>> On the other hand, looked into the
>> codehttps://github.com/douglascrockford/JSON-js/blob/master/json2.js[2]
>> and I see much, much more complicated regexps and rest of code to check
>> JSON string before its evaluated.
>>
>> Now I am more confused than before. Why code [1] is so simple and code
>> [2] is so complicated?
> 
> He uses regexps to filter invalid tokens in the JSON string. If there
> any invalid tokens the code throws a SyntaxError.

Which is, of course, no longer necessary to do manually in many cases as 
that is what the built-in JSON.parse() does now.

> We have discussed it before in the group.

ACK.


PointedEars
-- 
Danny Goodman's books are out of date and teach practices that are
positively harmful for cross-browser scripting.
  -- Richard Cornford, cljs, <cife6q$253$1$8300dec7@news.demon.co.uk> (2004)

Back to comp.lang.javascript | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-09 12:47 +0100
  Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-09 05:53 -0800
    Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-09 22:28 +0100
      Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 10:23 +0100
      Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 11:15 +0100
        Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-11 00:35 +0100
          Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 20:34 +0100
    Re: eval - how to Dr J R Stockton <reply1245@merlyn.demon.co.uk.invalid> - 2012-11-10 22:42 +0000
  Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-09 17:46 +0100
    Re: eval - how to Tim Streater <timstreater@greenbee.net> - 2012-11-09 17:00 +0000
      Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-09 18:19 +0100
    Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-09 22:49 +0100
      Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-09 16:40 -0800
        Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 11:36 +0100
          Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-10 13:29 +0100
            Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 13:55 +0100
              Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-10 14:17 +0100
                Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 20:50 +0100
                Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-10 22:54 +0100
                Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 15:22 +0100
                Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-11 16:24 +0100
                Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 19:23 +0100
          Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-11 10:40 -0800
            Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 20:41 +0100
              Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-11 13:34 -0800
                Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 23:03 +0100
      Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 10:21 +0100
  Re: eval - how to SAM <stephanemoriaux.NoAdmin@wanadoo.fr.invalid> - 2012-11-10 04:16 +0100

csiph-web