Path: csiph.com!usenet.pasdenom.info!dedibox.gegeweb.org!gegeweb.eu!nntpfeed.proxad.net!proxad.net!feeder2-2.proxad.net!newsfeed.arcor.de!newsspool1.arcor-online.net!news.arcor.de.POSTED!not-for-mail Content-Type: text/plain; charset="ISO-8859-1" Message-ID: <3451959.NK5rUynJWR@PointedEars.de> From: Thomas 'PointedEars' Lahn Reply-To: Thomas 'PointedEars' Lahn Organization: PointedEars Software (PES) Date: Wed, 24 Oct 2012 01:45:44 +0100 User-Agent: KNode/4.4.11 Content-Transfer-Encoding: 7Bit X-Face: %i>XG-yXR'\"2P/C_aO%~;2o~?g0pPKmbOw^=NT`tprDEf++D.m7"}HW6.#=U:?2GGctkL,f89@H46O$ASoW&?s}.k+&. Followup-To: comp.lang.javascript MIME-Version: 1.0 Lines: 60 NNTP-Posting-Date: 24 Oct 2012 02:45:45 CEST NNTP-Posting-Host: c3bb1b53.newsspool3.arcor-online.net X-Trace: DXC=Vb3ZHjaXYZBC4i^e1BZ=_HMcF=Q^Z^V3H4Fo<]lROoRA8kFK@JjkNj3FBJ;IgB:n7X7Y0>F X-Complaints-To: usenet-abuse@arcor.de Xref: csiph.com comp.lang.javascript:16826 Andrew Poulos wrote: > AFAIK > > AJAX That is a misnomer which leads to misconceptions. Forget about it. > - not cross domain Not necessarily. You can allow that now with a header field. See the other answer. > - has error handling Not necessarily. There are errors that cannot be handled. > JSONP > - cross domain Not necessarily. You can forbid that based on the Referer (sic!), but it can be circumvented. > - no error handling Not necessarily. You can add error handling. > - insecure Not necessarily. HTTP over SSL/TLS can be used the same as it can with XHR. > - adds javascript elements to the page No, it adds `script' elements to an (X)HTML document. That is where that technique is inherently unreliable, because AFAIK there still is no (quasi-)standard specifying what is supposed to happen then. Proper tests are pending. > Both can return the same "data" No. A script inserted with JSONP can include code that is compiled and executed immediately. A script returned from XHR needs to be inserted/evaluated before it is executed. > and in my testing I couldn't find any real speed differences between the > two. Test more. > If I'm writing a mobile app in HTML5 which needs to talk with a > web-based database. Is JSONP the only option? No. PointedEars -- Danny Goodman's books are out of date and teach practices that are positively harmful for cross-browser scripting. -- Richard Cornford, cljs, (2004)