1// jsr_class.js 2// 3// JSONscriptRequest -- a simple class for making HTTP requests 4// using dynamically generated script tags and JSON 5// 6// Author: Jason Levitt 7// Date: December 7th, 2005 8// 9// A SECURITY WARNING FROM DOUGLAS CROCKFORD: 10// "The dynamic <script> tag hack suffers from a problem. It allows a page 11// to access data from any server in the web, which is really useful. 12// Unfortunately, the data is returned in the form of a script. That script 13// can deliver the data, but it runs with the same authority as scripts on 14// the base page, so it is able to steal cookies or misuse the authorization 15// of the user with the server. A rogue script can do destructive things to 16// the relationship between the user and the base server." 17// 18// So, be extremely cautious in your use of this script. 19// 20// 21// Sample Usage: 22// 23// <script type="text/javascript" src="jsr_class.js"></script> 24// 25// function callbackfunc(jsonData) { 26// alert('Latitude = ' + jsonData.ResultSet.Result[0].Latitude + 27// ' Longitude = ' + jsonData.ResultSet.Result[0].Longitude); 28// aObj.removeScriptTag(); 29// } 30// 31// request = 'http://api.local.yahoo.com/MapsService/V1/geocode?appid=YahooDemo& 32// output=json&callback=callbackfunc&location=78704'; 33// aObj = new JSONscriptRequest(request); 34// aObj.buildScriptTag(); 35// aObj.addScriptTag(); 36// 37// 38 39 40// Constructor -- pass a REST request URL to the constructor 41// 42function JSONscriptRequest(fullUrl) { 43 // REST request path 44 this.fullUrl = fullUrl; 45 // Keep IE from caching requests 46 this.noCacheIE = '&noCacheIE=' + (new Date()).getTime(); 47 // Get the DOM location to put the script tag 48 this.headLoc = document.getElementsByTagName("head").item(0); 49 // Generate a unique script tag id 50 this.scriptId = 'JscriptId' + JSONscriptRequest.scriptCounter++; 51} 52 53// Static script ID counter 54JSONscriptRequest.scriptCounter = 1; 55 56// buildScriptTag method 57// 58JSONscriptRequest.prototype.buildScriptTag = function() { 59 60 // Create the script tag 61 this.scriptObj = document.createElement("script"); 62 63 // Add script object attributes 64 this.scriptObj.setAttribute("type", "text/javascript"); 65 this.scriptObj.setAttribute("charset", "utf-8"); 66 this.scriptObj.setAttribute("src", this.fullUrl + this.noCacheIE); 67 this.scriptObj.setAttribute("id", this.scriptId); 68}; 69 70// removeScriptTag method 71// 72JSONscriptRequest.prototype.removeScriptTag = function() { 73 // Destroy the script tag 74 this.headLoc.removeChild(this.scriptObj); 75}; 76 77// addScriptTag method 78// 79JSONscriptRequest.prototype.addScriptTag = function() { 80 // Create the script tag 81 this.headLoc.appendChild(this.scriptObj); 82};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.