-
If you design an #api returning #json always return with an object on the outside: owasp.org/index.php/AJAX_Security_Cheat_Sheet#Always_return_JSON_with_an_Object_on_the_outside haacked.com/archive/2008/11/20/anatomy-of-a-subtle-json-vulnerability.aspx/ #security