Evil.js: A JavaScript library for thwarting hot-linkers
github.com
github.com
window.location = "http://someone-elses-site.com/Falun_Dafa_exercise_video.mpg";https://github.com/kitcambridge/evil.js/blob/gh-pages/evil.j...
null = None
Infinity = float('Infinity')
NaN = float('nan')
(But no, it's not quite Python)See http://www.json.org/ - it is very cleary defined. *It's a string notation for a number. Don't get hung up on the implementations of floats or integers - it's irrelevant!
This is totally wrong. Javascript has nothing whatsoever to do with Java. It only has a few very superficial syntactical similarities (curly brackets, semi-colon at the end of each line, and that awful 'new' keyword). JSON, on the other hand, stands for "Javascript Object Notation", and can be interpreted as Javascript (with 'eval'). It's explicitly meant for storing and transmitting javascript data, so when there's a javascript data value that is not supported by JSON, that is absolutely relevant.
Of the four letters in the acryonym, the "J" is the least significant. Yes, it's javascript-y, but that's it. So many misunderstandings come from focusing on the "J". So, as JavaScript has basically nothing to do with Java (aside from superficial syntax similarities) so does JSON to JavaScript, for the same reasons. This "JSON is a subset of JavaScript" is just not true - at best it's "inspired by and interoperable with".
Java, on the other hand, is a totally different language. Any similarities are superficial and exist primarily for PR reasons. You can't pretend javascript is legal Java or vice versa. But JSON is totally legal javascript. That is exactly how you can declare objects in javascript. The name JSON fits the bill perfectly: it is the javascript object notation.
Except it's not, which is part of the reason this sub thread started. JSON encoded numbers are not IEEE754 floats either. And JSONP is purely a convenient hack around browser security issues only, again it has noting to do with JSON as a format.
You can argue the specifics,, but you miss the point that the claim that "JSON is JavaScript" is false and leads to tricky edge cases when the assumption breaks down.
It gets around those browser security issues by having the JSON wrapped in a function call and interpreted as javascript. I've never heard of a server converting all the values for JSONP.
There are absolutely edge cases, and those are important to note, exactly because outside those edge cases JSON is valid javascript. Claiming that they are totally completely unrelated (like javascript and Java) is false.
Now that we've all had a laugh, wouldn't it make more sense to have the server respond with a redirect to a shared copy of the script hosted somewhere that provides bandwidth for free? (Perhaps this is a sign that the script should be open-sourced as well.)
I think the idea is more that if someone is eating your bandwidth by hotlinking your jQuery.js, then you can serve them this instead.
if(!window.location.host.match(/(www\.)?myapp.com/)) window.location = 'http://www.myapp.com';
I bet they won't hotlink after that.I'd be surprised if they actually have a leg to stand on legally if they are hotlinking off someone's site, especially if there's have no prior agreement to allow them to do so.
(function(){
if(document.domain != 'mydomain.com') return;
// my script
})(); (function () { if (document.domain !== "mydomain.com") { while (1); }})();