On 06/11/11 12:46, tor@xxxxxxxxxxxxxxxxxx wrote:

> The content-type should be application/json or at the very least text/plain.

I was clearly talking rubbish here; the content type should be a
javascript one. Still, I was completely correct about the danger of
using text/html and allowing arbitrary content for the callback parameter.

