For some reason, the performance doesn't seem that clear cut.
For instance, I get the following on Chrome, running it a few times:
(Doing 100,000 parses of a small JSON string)
JSON: (1653ms) vs eval: (206ms)
Firefox the two are about even (650ms). Safari is also pretty much identical (250ms).
Surprising that the Chrome JSON parse is so much slower than eval.
Do you have any performance figures for JSON parsing?
So you have JSON.parse which is the same, if not slower (Chrome) than using eval. Having to include extra unnecessary characters costs you bandwidth, but you do get the slightly better security from JSON, although that can be done with a quick regexp beforehand.
{foo:1} should be valid dammit. It tells us exactly all we need to know, with 0 ambiguity.
So yeah, a bit faster in Firefox and Safari, much much faster in IE 8 (the one that matters), and oddly slower in Chrome. I'll go out on a limb and blame their lax parsing (they support malformed strings).
In the end though the parsing is a distant second to the improved security: Guaranteeing that eval will never get touched in modern browsers is a huge win from a framework perspective.
Comments
For some reason, the performance doesn't seem that clear cut.
For instance, I get the following on Chrome, running it a few times: (Doing 100,000 parses of a small JSON string)
JSON: (1653ms) vs eval: (206ms)
Firefox the two are about even (650ms). Safari is also pretty much identical (250ms).
Surprising that the Chrome JSON parse is so much slower than eval.
Do you have any performance figures for JSON parsing?
So you have JSON.parse which is the same, if not slower (Chrome) than using eval. Having to include extra unnecessary characters costs you bandwidth, but you do get the slightly better security from JSON, although that can be done with a quick regexp beforehand.
{foo:1} should be valid dammit. It tells us exactly all we need to know, with 0 ambiguity.
just my 2c.
Test case: http://ejohn.org/files/json-parse/
So yeah, a bit faster in Firefox and Safari, much much faster in IE 8 (the one that matters), and oddly slower in Chrome. I'll go out on a limb and blame their lax parsing (they support malformed strings).In the end though the parsing is a distant second to the improved security: Guaranteeing that eval will never get touched in modern browsers is a huge win from a framework perspective.