Re: [Json] The names within an object SHOULD be unique.

Nico Williams <nico@cryptonector.com> Mon, 10 June 2013 18:04 UTC

Return-Path: <nico@cryptonector.com>
X-Original-To: json@ietfa.amsl.com
Delivered-To: json@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6DE7321F9990 for <json@ietfa.amsl.com>; Mon, 10 Jun 2013 11:04:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.958
X-Spam-Level:
X-Spam-Status: No, score=-1.958 tagged_above=-999 required=5 tests=[AWL=0.019, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WhmMUK7+rt3Z for <json@ietfa.amsl.com>; Mon, 10 Jun 2013 11:04:28 -0700 (PDT)
Received: from homiemail-a66.g.dreamhost.com (caiajhbdcaid.dreamhost.com [208.97.132.83]) by ietfa.amsl.com (Postfix) with ESMTP id BA00F21F9995 for <json@ietf.org>; Mon, 10 Jun 2013 11:04:28 -0700 (PDT)
Received: from homiemail-a66.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a66.g.dreamhost.com (Postfix) with ESMTP id 8C40F350079 for <json@ietf.org>; Mon, 10 Jun 2013 11:04:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=cryptonector.com; h= mime-version:in-reply-to:references:date:message-id:subject:from :to:cc:content-type; s=cryptonector.com; bh=K7MJVs3Ea/uGP5AZT1RR 6N25rMc=; b=QJIGWvkGZ7ZA8rVEwmsXzi1aKXihZBy4bifd57s+W/+3MVb1UwN+ 5O+hSTu/s1OP5wtTs/jMglRiLQHx7azk4RtPwopeEMhd8OhDy5APkwXKo/PMNL1l Ez/8TorWMR1IyaN/N7QeP6T01gn6s8IYMYDgd7sIfFblPzWshyoz/Ng=
Received: from mail-wg0-f50.google.com (mail-wg0-f50.google.com [74.125.82.50]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by homiemail-a66.g.dreamhost.com (Postfix) with ESMTPSA id 3FA48350078 for <json@ietf.org>; Mon, 10 Jun 2013 11:04:28 -0700 (PDT)
Received: by mail-wg0-f50.google.com with SMTP id k13so5204089wgh.29 for <json@ietf.org>; Mon, 10 Jun 2013 11:04:27 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=30gigOWwINjZYo7xcr2ufggJqjpyITXT761fh7I2ogY=; b=l3IhaoN0/Gj+/d9O68M5CNrv5IahrefZwDEml4SeCrkBHnZcwxr1p47FPMWmwe+gYl 41vypJA/wNFEj0/C3vI5tCEwyxQ5uQ20fJctKDt6lUmNvwMbXvXuW7u3/3GkdB2SS6li iJouOSZEE24TWo18+8eNnMss+//WdEvq25p+izA8GZIIqYIaZFURiLZvETc9BTtCCPYJ 23Av2suAuMnc5nQa/yfZYQtfJ5emhvSPhNhi25Cq+MGu5eKIYRRxjchsX7NulMjuP1Vj X0IcdC5+U2HDFLsZj7tLZ1DqXTlAbrSEI19tWjnbYTJXw3RA47YjwCtbtas4e6AhJVvC kQsA==
MIME-Version: 1.0
X-Received: by 10.180.90.164 with SMTP id bx4mr5334704wib.13.1370887466978; Mon, 10 Jun 2013 11:04:26 -0700 (PDT)
Received: by 10.216.63.136 with HTTP; Mon, 10 Jun 2013 11:04:26 -0700 (PDT)
In-Reply-To: <20130610175036.GB31359@mercury.ccil.org>
References: <C86A9758-5BEF-415C-BD17-DC5E757FAA7E@yahoo.com> <51B1E909.2010402@drees.name> <CA+mHimN9=VZu4RRWcnk2F_uMi-+E-LDN2stb1MFNDP+o1R0WSg@mail.gmail.com> <51B1FE6A.80409@drees.name> <CA+mHimNuDwTF96v0PnEvFusCw-KEFT6QF4R9UeZ+8nbETB7oBw@mail.gmail.com> <51B45FAA.4070900@drees.name> <CA+mHimOBfb1RZhp6rYpL83rnHhrjNTeTeomi4hAv9avsYROE5A@mail.gmail.com> <62F282B7-11AA-44F8-A03B-201F2DAE51B5@vpnc.org> <CA+mHimNh26EUy4OxV1oSLNKvuz3VAsJjdte5ZFriTMc5HU9dRA@mail.gmail.com> <CAK3OfOi3tnRKHTFyESpks6zdHu106vDNpjptGxZds3cmE2JD3w@mail.gmail.com> <20130610175036.GB31359@mercury.ccil.org>
Date: Mon, 10 Jun 2013 13:04:26 -0500
Message-ID: <CAK3OfOhGfREDjwYpWEEw21FqYUhdghdt2pzbmhRhAK6qWBAYng@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: John Cowan <cowan@mercury.ccil.org>
Content-Type: text/plain; charset="UTF-8"
Cc: Stephen Dolan <stephen.dolan@cl.cam.ac.uk>, Paul Hoffman <paul.hoffman@vpnc.org>, "json@ietf.org" <json@ietf.org>
Subject: Re: [Json] The names within an object SHOULD be unique.
X-BeenThere: json@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "JavaScript Object Notation \(JSON\) WG mailing list" <json.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/json>, <mailto:json-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/json>
List-Post: <mailto:json@ietf.org>
List-Help: <mailto:json-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/json>, <mailto:json-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Jun 2013 18:04:35 -0000

On Mon, Jun 10, 2013 at 12:50 PM, John Cowan <cowan@mercury.ccil.org> wrote:
> Nico Williams scripsit:
>
>> But not one like this, which I doubt anyone will argue should be
>> allowed:
>>
>> while ((name, value) = parser.nextPair()) {
>>     if (hash[name])
>>         continue;
>>     hash[name] = value;
>>     doCommand(name, value);
>> }
>
> I do argue that it should be allowed.  Both "assume last" and "assume
> first", and for that matter "assume middle", are valid interpretations
> of RFC 4627, and ought to continue to be allowed.

I'm OK with disallowing the above, but if we can't get consensus even
on that then what we should do is leave the original text as it was
and move this discussion to the Security Considerations section (to
point out the risks) and the best practices document (to say "best
practice is not to do this").