Showing posts with label json. Show all posts
Showing posts with label json. Show all posts

Tuesday, December 15, 2009

JSON Hijacking

If you request JSON


DO NOT use GET
 or if you must, DO NOT return a JSON array.
return a JSON object.

The problem is that an array on its own is a valid javascript statement while an object is not (it needs to be assigned to something or passed to something). By returning valid javascript the request can accessed via a script tag instead of an XHR and executed. Excecuted arrays can be manipulated by malicious code.

 I think this article should be renamed "JSON arrays considered harmful". Vulnerability currently only in "modern" e.g. Firefox, Chrome and Safari.

IE8 is too old fashioned.


Tuesday, September 08, 2009

SitePen Blog � JSON Namespacing

SitePen Blog � JSON Namespacing

JSON Hyper Schemas can be referenced from instances by Link headers or media type parameters. A simple example illustrates how JSON properties have universally locatable definitions:

Content-Type: application/json; schema=http://www.book-warehouse.com/book-schema
[
{"title": "Oliver Twist", "price": 16.99},
{"title": "Robinson Crusoe", "price": 15.99}
]

This message gives the authoritative URI for the schema. With a look at the schema, we can see how each property has a corresponding definition with an authoritative URI as well:

Content-Type: application/schema+json; schema=http://json-schema.org/hyper-schema
{ "properties": {
"title": {"type": "string", "description": "The title of the book"},
"price": {"type": "number", "description": "The price of the book in US"},
}
}