Why not eval() JSON?

前端 未结 6 805
再見小時候
再見小時候 2020-12-10 06:14

As far as I know it is considered bad practice to eval() JSON objects in JavaScript, because of security. I can understand this concern if the JSON comes from a

6条回答
  •  情书的邮戳
    2020-12-10 06:40

    Seriously? Some of the guys here are paranoid. If you're delivering the JSON and you know it's safe, it's ok to fallback(*) to eval(); instead of a js lib for IE. After all, IE users have much more to worry about.

    And the man-in-the-middle argument is bullsh*t.

    (*) the words fallback and safe are in bold because some people here didn't see them.

提交回复
热议问题