Show HN: JSON Pizza – Beautify your JSON quickly
json.pizza
json.pizza
pbpaste | json_pp | pbcopy
For just viewing, I like Node's console.dir() formatting better since it's more compact and colored (but it's unquoted JS objects, not JSON), so I aliased this command in my shell: json='node -e '\''console.dir(JSON.parse(fs.readFileSync("/dev/stdin", "utf-8")), { depth: null })'\'
Then I can do pbpaste | json pbpaste | jqBut I've also written about how to do it with various stacks for various things at https://www.jvt.me/tags/pretty-print/
cat foo.json | python3 -m json.tool
Prettifying is also built in to python3 on any system. jq . foo.jsonpython3 -m json.tool foo.json
:) cat foo.json
[oh crap]
:) cat foo.json | python -m foo.tool
For the 2nd command I'd hit "[up] | pyth[tab] -m json.tool"Over the years I've seen a lot of developers take none open-source code, or private JSON data strings and paste them into random sites they find searching "json format" on google.
Does that make anyone else cringe? Is there anything we can do about this? Or is this just not a big deal and I shouldn't worry.
I too wonder if I'm out of touch, if I'm tilting at windmills.
At least ngrok supports end-to-end TLS tunnels[0], where you use your own TLS key/certs and the ngrok server never sees plaintext (the ngrok client is also open source, so for the truly paranoid you can examine it to ensure it isn't doing anything nefarious).
But I agree... I've seen people at a company where I used to work pasting sensitive data into a public pastebin. It still hurts my brain to think about it.
Sure, don't put arbitrary shit on the internet and know where your data is going. But every example you gave is incredibly useful to many people on a daily basis.
Or maybe I'm a crank and need to lighten up. That's why I'm asking.
> I don't trust new developers to make that determination.
Ignoring this issue is a sign of professional immaturity. Recommend you view it as an opportunity to educate the younger members of your team. Show them the power of a solid CLI toolbox that respects your privacy while delivering solid performance.
Still, you shouldn't be dogmatic about it. Webapp tools can be useful for understanding a new programming language or API. Just be judicious.
Security-related scanners are a tough one though. Free XSS scanners, free TLS cert checkers: The best intentions can result in unintended disclosure. Developers have it constantly beaten into their head "Security! Security! Security!" and are often given nothing more than an OWASP cheat-sheet, so I can totally understand and empathize with the thought process that leads someone to plug a company URL into a free web-hosted XSS scanner.
Google runs this (or an internal version) of this service to make sure people serving third party ads aren't sending sensitive data. At one of my past companies our customers would send out email marketing campaigns that contained URLs with tracking parameters with PII. We wound up having to just strip off any query parameters we didn't explicitly need because Google kept flagging us for PII leaks caused by our customers.
So yeah, there's a lot of noise. But, people are listening out there!
copy(JSON.stringify(obj, null, 2))
obj can be parsed with JSON.parse if it is in text.That’s rather condescending, and probably not true. Surely you must be able to think of reasons why someone would use a website instead of writing a one-line program.
And the JS console was only an example. Other languages can also pretty print JSON trivially. E.g. python.
The biggest struggle for me is diffing random bits of text. Pulling two JSON docs from the DB and wanting to compare them. Recently found a VSCode plugin that makes it a bit better, but still a pain in the ass.
There are some things you just shouldn't paste into the internet.
Aside from that, this is one area where web-based applications excel: You can inspect and limit what data an application is sending away about you via your browsers built-in dev tools and extensions like uMatrix (or your own request-filtering extensions).
For example you can detect changes in window sizes or look for plugins that are in the global namespace (e.g. Redux Dev Tools). Better play it safe and don't copy and paste private data to random sites.
Another attack vector would be to avoid sending down any data unless it contains something that looks like a hash or a token, or has a keyword like "password."
Second time through, I read the instructions, and realised that the keyboard shortcuts are Control-based – this is less common for macOS, "Cmd+Enter" feels like a more consistent shortcut to use.
I think this should probably just auto-format all the time. It's only for formatting, so that wouldn't get in the way.
There's also apparently some other things going on; CTRL-u uppercases the word you're on. A link to more docs or something may be helpful.
json_source_on_stdout | jq . pbpaste | jq . | pbcopy
Pretty sure this is one of my most frequent commands.1. Start Automator.
2. In the "Choose a type..." sheet, choose "Quick Action".
3. Set these:
Workflow recieves "current text" in "any application".
Input is "entire selection". [X] Output replaces text.
4. Add "Run shell script" and select your preferred shell. jq .
(Note that Automator is handling your stdin / stdout.)5. File / Save.
You can now find your workflow by command-clicking the document name in the window's titlebar. It should be in /Users/You/Library/Services
Now, fire up TextEdit, enter some JSON. Right-click, select Services and your service should be present. It's also in the TextEdit menu under Services.
cat input.json | python3 -m json.tool
For example, I wanted to write a simple expression to delete outputs from an ipython notebook.
{
"cells": [{
"stuff": "blah blah",
"outputs": ["crap", "to", "delete"]
}], "other stuff": "blah blah"
}
The simplest expression I could come up with was: merge(@, {
"cells": map(
&merge(@, {"outputs": `[]`}),
cells[]
)
})
And that's verbose because you're reconstructing the structure.In fairness, it's impressive that the language can express it at all, given it's a query language.
Maybe the real answer is to denote a subset of JMESPath that is guaranteed to return assignable nodes, that is only selects, slices, filters, etc. Then you run the query and perform assignments against those.
json_source_on_stdout | jq
If you give `jq` no arguments it acts like `jq .` const formattedText = JSON.stringify(JSON.parse(text), null, 2)`There are a few features that can cut out a ton of unnecessary whitespace, like keeping short lists and maps on a single line, and keeping singleton list brackets tight.
You can also just open chrome / firefox dev tools console and assign it to a variable...
Sadly, all of these tools fall over for very large json objects
I think a strong example would really help your case, the landing page now has already formatted json, and I can't figure out where to get a messy example from quickly.
Ctrl-B works.
Also for fun