Expand Minimize
0 out of 2 rated this helpful - Rate this topic

JsonRequestBehavior Enumeration

Specifies whether HTTP GET requests from the client are allowed.

Namespace:  System.Web.Mvc
Assembly:  System.Web.Mvc (in System.Web.Mvc.dll)
type JsonRequestBehavior
Member nameDescription
AllowGetHTTP GET requests from the client are allowed.
DenyGetHTTP GET requests from the client are not allowed.

The default value is DenyGet. Allowing GET requests can result in a user visiting one Web site while still logged into another Web site. This can create an information-disclosure security vulnerability. For information about this vulnerability, see the entry JSON Hijacking on Phil Haack's blog.

Did you find this helpful?
(1500 characters remaining)
© 2013 Microsoft. All rights reserved.