
Amon2::Plugin::Web::JSON - JSON plugin

use Amon2::Lite;
__PACKAGE__->load_plugins(qw/Web::JSON/);
get '/' => sub {
my $c = shift;
return $c->render_json(+{foo => 'bar'});
};
__PACKAGE__->to_app();

This is a JSON plugin.

Generate JSON data from \%dat and returns instance of Plack::Response.

You can use JSONP by using Plack::Middleware::JSONP.

This module escapes '<', '>', and '+' characters by "\uXXXX" form. Browser don't detects the JSON as HTML.
And also this module outputs "X-Content-Type-Options: nosniff" header for IEs.
It's good enough, I hope.
Latest browsers doesn't have a JSON hijacking issue(I hope). __defineSetter__ or UTF-7 attack was resolved by browsers.
But Firefox<=3.0.x and Android phones have issue on Array constructor, see http://d.hatena.ne.jp/ockeghem/20110907/p1.
Firefox<=3.0.x was outdated. Web application developers doesn't need to add workaround for it, see http://en.wikipedia.org/wiki/Firefox#Version_release_table.
Amon2::Plugin::Web::JSON have a JSON hijacking detection feature. Amon2::Plugin::Web::JSON returns "403 Forbidden" response if following pattern request.
See also the hasegawayosuke's article(Japanese).

render_json method returns instance of Plack::Response. You can modify the response object.
Here is a example code:
get '/' => sub {
my $c = shift;
if (-f '/tmp/maintenance') {
my $res = $c->render_json({err => 'Under maintenance'});
$res->status(503);
return $res;
}
return $c->render_json({err => undef});
};

hasegawayosuke