How to implement cross-origin through JSONP

Source: Internet
Author: User

JSONP is JSON with Padding. Due to the same-origin policy restrictions, XmlHttpRequest only allows requests to resources of the Current Source (domain name, protocol, port. For cross-origin requests, we can use the html script tag to perform cross-origin requests, and return the script code to be executed in the response, where javascript objects can be directly transmitted using JSON. This cross-origin communication method is called JSONP.

For the above explanation, we can simply understand it as follows: JSONP is a cross-domain communication method that can be implemented through JavaScript files. For example, the search tips that are currently popular on various websites. Note: The JSONP server code must take full security measures.

Below is a simple JSONP:

Var JSONP = document. createElement ("script"); // FF: onload IE: onreadystatechangeJSONP. onload = JSONP. onreadystatechange = function () {// onreadystatechange, only IEif (! This. readyState | this. readyState = "loaded" | this. readyState = "complete") {alert ($ ("# demo" ).html (); JSONP. onload = JSONP. onreadystatechange = null // memory usage to prevent IE memory leaks} JSONP. type = "text/javascript"; JSONP. src = ""; // Add the js file document. getElementsByTagName ("head") [0]. appendChild (JSONP );

Simple Explanation: we create a script, specify its src and other attributes, and insert it to the head for execution.

Suggestion: onload and onreadystatechange should be written before the src value assignment to prevent loading js files from being too fast and not assigning values to onload and onreadystatechange (this is the case for Image objects in IE ).

We can first define a function to execute the data returned by JSONP, and then pass this function to the background through src of JSONP for processing and return executable functions. For example, the following code:

Function jsonpHandle (a) {alert (a);} var JSONP = document. createElement ("script"); JSONP. type = "text/javascript"; JSONP. src = " Callback = jsonpHandle "; // Add the js file document. getElementsByTagName (" head ") [0]. appendChild (JSONP) after the head );

Jsonp. php code in the background:

echo $_GET["callback"]."('hello,world')";

Common ajax requests can only interact with data in the same domain, but they do not work once cross-domain requests exist. However, different jsonp methods can use browser tags for cross-origin purposes. In fact, jsonp is a very simple thing. The <script> tag is used to dynamically parse javascript documents.

The Script tag function is to load js asynchronously and parse and execute it in js mode. Once the src attribute is added to the script tag, the browser will go back to the specified address when executing the tag. If the server returns JavaScript code or even JavaScript Functions, as long as it can be parsed by js, it can be executed, which is the principle of jsonp.

Demo of using jsonp:


This is the most basic principle of jsonp.

Use as an example to upload callback=ajaxlistloader.reload

<! Doctype html>  

Use yui's get. script () to trigger the url, replacing the original script tag. Fill in the returned data to the page for display.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.