Safe AJAX URLs
Safe AJAX URLs: free step-by-step lesson with examples, common mistakes, and interview tips — part of jQuery Tutorial on Toolliyo Academy.
On this page
jQuery Tutorial · Lesson 68 of 100
Safe AJAX URLs
Setup & DOM ✓ → Events Effects AJAX ✓ → Perf & Integrate → Ship & Projects
Perf & Integrate · 3 — Harden · ~10 min · Performance and Security
What is this?
Build URLs from allowlisted paths and encoded parameters. Never concatenate unsanitized user input into URLs in ways that change host or protocol (open redirects / SSRF-ish mistakes on server proxies).
Why should you care?
QueryVerse filters that put raw strings into URLs can break APIs or open abuse paths.
See it live — copy this example
Examples include the jQuery 3.7 CDN. Paste into an HTML file or use Run Example to preview.
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>QueryVerse</title>
<style>
body { font-family: system-ui, sans-serif; margin: 1.25rem; }
.box { padding: .75rem; border: 1px solid #ccc; border-radius: 8px; margin: .5rem 0; }
.muted { color: #666; }
button { margin-right: .35rem; margin-top: .35rem; }
input, select, textarea { margin: .25rem 0; }
table { border-collapse: collapse; width: 100%; }
th, td { border: 1px solid #ddd; padding: .4rem .55rem; text-align: left; }
.hidden { display: none; }
.row-odd { background: #f7f7f7; }
.active { font-weight: 700; }
.toast { background: #111; color: #fff; padding: .5rem .75rem; border-radius: 6px; }
</style>
</head>
<body>
<input id="id" value="1">
<button type="button" id="go">Fetch post by id</button>
<pre id="out" class="box muted"></pre>
<script src="https://code.jquery.com/jquery-3.7.1.min.js"></script>
<script>
$(function () {
function postUrl(id) {
var n = String(id).replace(/[^0-9]/g, '');
if (!n) throw new Error('invalid id');
return 'https://jsonplaceholder.typicode.com/posts/' + encodeURIComponent(n);
}
$('#go').on('click', function () {
try {
var url = postUrl($('#id').val());
$('#out').text('GET ' + url + '\n…');
$.getJSON(url)
.done(function (p) { $('#out').text(JSON.stringify(p, null, 2)); })
.fail(function () { $('#out').text('fail'); });
} catch (e) {
$('#out').text(String(e.message || e));
}
});
});
</script>
</body>
</html>
Run Example »
Edit the code below and click Run to see the result in Toolliyo’s live editor.
What happened?
- Allowlist hosts in client helpers when absolute URLs are required.
- encodeURIComponent for query/path segments.
- Reject ../ and http: injections in user-controlled segments.
Practice next
- Fetch id 1.
- Try id="1;alert(1)" and see sanitizing.
- Pass empty and hit the throw.
- Centralize url builders.
- Log the final URL in dev only.
Remember
Allowlist + encode. Validate ids. No user-controlled hosts.
Filtered GET builder
A Cleartrip ops QueryVerse tool loads booking ids typed by agents.
Outcome: Only digits reach the path; encoding stays strict.
Interview prep for this lesson
Practice these questions aloud after reading—each links to a full structured answer.
Sign in to ask a question or upvote helpful answers.
No questions yet — be the first to ask!