Is json_encode Sufficient XSS Protection?

前端 未结 5 514
挽巷
挽巷 2020-12-25 13:49

I have a stdClass object in PHP, something like

$o = new stdClass;
$o->foo = $bar

The variable $bar contains a

5条回答
  •  情书的邮戳
    2020-12-25 14:21

    What I do is to evaluate the json object before assuming its safe. I think the method is evalJSON(true) in prototype and jquery has a similar implementation. I don't know much about xss standards with JSON but this helps me

提交回复
热议问题