Make sure that null params aren't traversed. Fixes #5794.
[jquery.git] / src / ajax.js
index 35d83e4..3c199af 100644 (file)
@@ -390,14 +390,17 @@ jQuery.extend({
 
                // Wait for a response to come back
                var onreadystatechange = xhr.onreadystatechange = function( isTimeout ) {
-                       // The request was aborted, clear the interval and decrement jQuery.active
+                       // The request was aborted
                        if ( !xhr || xhr.readyState === 0 ) {
-                               requestDone = true;
-                               xhr.onreadystatechange = jQuery.noop;
+                               // Opera doesn't call onreadystatechange before this point
+                               // so we simulate the call
+                               if ( !requestDone ) {
+                                       complete();
+                               }
 
-                               // Handle the global AJAX counter
-                               if ( s.global && ! --jQuery.active ) {
-                                       jQuery.event.trigger( "ajaxStop" );
+                               requestDone = true;
+                               if ( xhr ) {
+                                       xhr.onreadystatechange = jQuery.noop;
                                }
 
                        // The transfer is complete and the data is available, or the request timed out
@@ -447,6 +450,22 @@ jQuery.extend({
                        }
                };
 
+               // Override the abort handler, if we can (IE doesn't allow it, but that's OK)
+               // Opera doesn't fire onreadystatechange at all on abort
+               try {
+                       var oldAbort = xhr.abort;
+                       xhr.abort = function() {
+                               if ( xhr ) {
+                                       oldAbort.call( xhr );
+                                       if ( xhr ) {
+                                               xhr.readyState = 0;
+                                       }
+                               }
+
+                               onreadystatechange();
+                       };
+               } catch(e) { }
+
                // Timeout checker
                if ( s.async && s.timeout > 0 ) {
                        setTimeout(function() {
@@ -459,7 +478,7 @@ jQuery.extend({
 
                // Send the data
                try {
-                       xhr.send( type === "POST" || type === "PUT" ? s.data : null );
+                       xhr.send( type === "POST" || type === "PUT" || type === "DELETE" ? s.data : null );
                } catch(e) {
                        jQuery.handleError(s, xhr, null, e);
                        // Fire the complete handlers
@@ -570,20 +589,29 @@ jQuery.extend({
 
                // The filter can actually parse the response
                if ( typeof data === "string" ) {
-                       // If the type is "script", eval it in global context
-                       if ( type === "script" || !type && ct.indexOf("javascript") >= 0 ) {
-                               jQuery.globalEval( data );
-                       }
-
                        // Get the JavaScript object, if JSON is used.
                        if ( type === "json" || !type && ct.indexOf("json") >= 0 ) {
-                               // Try to use the native JSON parser first
-                               try {
-                                       data = JSON.parse( data );
+                               // Make sure the incoming data is actual JSON
+                               // Logic borrowed from http://json.org/json2.js
+                               if (/^[\],:{}\s]*$/.test(data.replace(/\\(?:["\\\/bfnrt]|u[0-9a-fA-F]{4})/g, "@")
+                                       .replace(/"[^"\\\n\r]*"|true|false|null|-?\d+(?:\.\d*)?(?:[eE][+\-]?\d+)?/g, "]")
+                                       .replace(/(?:^|:|,)(?:\s*\[)+/g, ""))) {
+
+                                       // Try to use the native JSON parser first
+                                       if ( window.JSON && window.JSON.parse ) {
+                                               data = window.JSON.parse( data );
+
+                                       } else {
+                                               data = (new Function("return " + data))();
+                                       }
 
-                               } catch(e) {
-                                       data = (new Function("return " + data))();
+                               } else {
+                                       throw "Invalid JSON: " + data;
                                }
+
+                       // If the type is "script", eval it in global context
+                       } else if ( type === "script" || !type && ct.indexOf("javascript") >= 0 ) {
+                               jQuery.globalEval( data );
                        }
                }
 
@@ -637,7 +665,7 @@ jQuery.extend({
                                                }
                                        });
                                        
-                               } else if ( !traditional && typeof obj === "object" ) {
+                               } else if ( !traditional && obj != null && typeof obj === "object" ) {
                                        // Serialize object item.
                                        jQuery.each( obj, function( k, v ) {
                                                buildParams( prefix + "[" + k + "]", v );