5 ms·
>`JSON.load` should never be given input from unknown sources. If you are processing JSON from an unknown source, always use `JSON.parse`. This seems like poo
by mapgrep 14y ago
>`JSON.load` should never be given input from unknown sources. If you are processing JSON from an unknown source, always use `JSON.parse`.
This seems like poor method naming; I would not intuitively understand that "load" is far more dangerous than "parse."
Why not deprecate these and do names like
JSON.load_trusted
JSON.load_untrusted
- jdleesmiller 14y agoA few further notes on this, following some reading... The docs aren't very clear about it, either (http://flori.github.com/json/doc/index.html http://flori.github.com/json/doc/index.html). There is a JSON.parse! method that they explicitly say is to be used only for trusted input, and it looks like JSON.load has some of the same default options. To further confuse things, JSON.load has the very useful property that you can pass it a String or an IO (e.g. from Rack::Request#body), whereas JSON.parse only accepts a String. edit: the docs will soon contain a warning about JSON.load; see https://github.com/flori/json/blob/master/lib/json/common.rb https://github.com/flori/json/blob/master/lib/json/common.rb
- dbaupp 14y agoBetter would be load and load_trusted so that the safer function has the short (and expected) name.
- MatthewPhillips 14y agoWhy have the unsafe function at all?
- mikeash 14y agoBetter yet would be to remove the trusted functionality entirely and give a good talking-to to whoever wrote it. A generic JSON parser shouldn't have an unsafe parsing method on it period. If you want to implement clever nonsense like this, do it at the next layer up and call it something else.