Adds a json prefix setting. #1604

wants to merge 1 commit into


None yet

2 participants

gjohnson commented May 5, 2013

Adds a new optional setting called json prefix for prefixing a value to the body of json responses in order to prevent json hijacking.

Could technically be external middleware, but seems simple enough to live inside .json() like the rest of the json settings.

tj commented May 24, 2013

tempted to leave this one as middleware, for us at least it's nice to do apply conditionally so api consumers that aren't browsers don't have to worry about stripping the prefix


that makes sense.

@gjohnson gjohnson closed this Jul 15, 2013
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment