GMailã®ã³ã³ã¿ã¯ããªã¹ããå¤é¨ããå¼ã³åºãå¯è½ã«ãªã£ã¦ãã¾ã£ã¦ã件ã«ã¤ãã¦ã Googleå ãã©ã¤ãã¼ããªã¯ãã®ãã¼ã¿ããé¢ä¿ã®ãªãå¤é¨ã®ãµã¤ããããã¹ã¯ãªããçµç±ã§èªã¿è¾¼ã¾ãã¦ãã¾ãã¨ãããã®ã http://ajaxian.com/archives/gmail-csrf-security-flaw ã§ãããã£ã¦CSRFã£ã¦ããã®ããªï¼ãªããåé¡ãã¡ãã£ã¨éã£ã¦ããããªæ°ããããã©ãCSRFã¯æ å ±ãæãåãããã©ããã£ã¦ã¨ãã¯å¥ã«é¢ä¿ãªãã¯ãã ããå¤é¨ãµã¤ãã«ãã©ã¤ãã¼ããã¼ã¿ãçã¾ããã¨ããè å¨ã¨ãã¦ã¯CSSXSSã«è¿ããããªãï¼è¿½è¨ï¼ã©ããCSRFã®å®ç¾©ã£ã¦ã®ã¯ããã¡ãã£ã¨åºãã¿ããï¼ ãã®é¨ãã«å¼å¿ãã¦ãã¯ãã¹ãµã¤ãã®ã»ãã¥ãªãã£ã¢ãã«ã«ã¤ãã¦ã¾ã¨ãã¦ãã£ãã http://labs.cybozu.co.jp/blog/kazuho/archives/2007/01/cross
SEã®é²å°ã§ãã 2007å¹´1æã«æ稿ãããWeb 2.0çã¢ããªã®ã»ãã¥ãªãã£ï¼æ©å¯æ å ±ã«JSONPã§ã¢ã¯ã»ã¹ãããªãã¯å¤ãã®æ¹ã«ãèªã¿ããã ãã¾ããã誤ããææãããå ã¨ã³ããªã¼ã«æ¹ä¿®ãå ãã¾ããããããªãèªã¿ã¥ããç¶æ ã«ãªã£ã¦ãã¾ã£ã¦ãã¾ããã¾ããJSONãJSONPã®ã»ãã¥ãªãã£ã«é¢ããæ°ããªè©±é¡ãSea Surfers MLã§è°è«ããã¦ããã®ãèªã¿ãèªåèªèº«ã®èªèãç解ãå¤åãã¦ããã®ã§ããã®ã¨ã³ããªã¼ã§ããä¸åº¦JSONãJSONPï¼+JavaScriptï¼ã«æ©å¯æ å ±ãå«ãããã¨ã®æ¯éã¨æ¹çãæ´çãæ¤è¨ãããã¨æãã¾ãã âJSONãJSONPãJavaScriptã«ãããã¼ã¿æä¾æã«ã»ãã¥ãªãã£å¯¾çä¸çæãã¹ãç¹å¾´ JSONãJSONPãJavaScriptã«ãããã¼ã¿æä¾æã«çæãã¹ãç¹å¾´ã¨ãã¦ããã®ãããã¯ãã¹ãã¡ã¤ã³ã¢ã¯ã»ã¹å¯è½ãã¨ãããã®ã§ããJSONPã ãã§ãªããJS
« è ¹æ¸ã£ãï¼ | ã¡ã¤ã³ | JavaScript - dojoã®ScriptSrcIOã§åçã¯ãã¹ãã¡ã¤ã³JSONèªã¿è¾¼ã¿ » 2006å¹´07æ07æ¥ â JavaScript - JSONã§ãã¼ã¿ãåä¿¡ããæ¹æ³2ç¨®é¡ [Programming&Electronics][Technology] JSONãåä¿¡ãããµã³ãã«ãä½ã£ãã ã»del.icio.usã®JSON-APIããshokaiã®ããã¯ãã¼ã¯ä¸è¦§ãèªã¿è¾¼ã¿ ã»ãµã¼ãã«ç½®ããdel.icio.usã®JSONãã¡ã¤ã«ããããã¯ãã¼ã¯ä¸è¦§ãèªã¿è¾¼ã¿ ã»ãµã¼ãã«ç½®ããGPSãã¼ã¿ããä½ç½®æ å ±ã®ãªã¹ããèªã¿è¾¼ã¿ ãã£ã¨ç解ã§ããã JSONã¯ãJavaScriptObjectNotationã®ç¥ã§ãJavaScriptã®ãªãã¸ã§ã¯ããããã¹ããã¼ã¿ã§è¡¨è¨ããããã®ãã©ã¼ããããJSONããã¹ããJavaScriptã§eval()ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}