Gon's JSON generation fails when multi_json uses the json gem as its backend with json 3.0.0.
The failure was observed in the test-multi-json-compatibility (1.20.1) CI job:
ArgumentError:
unknown keywords: mode, escape_mode, time_format
# ./lib/gon/json_dumper.rb:20:in `dump'
# ./spec/gon/json_dumper_spec.rb:14
Cause
Gon::JsonDumper.dump passes these Oj-specific options to multi_json regardless of the selected backend:
{ mode: :compat, escape_mode: :xss_safe, time_format: :ruby }
When the json backend is selected, multi_json forwards them to JSON.generate. json 2.x ignored unknown options, but json 3.0.0 raises ArgumentError.
Running the existing json_dumper_spec.rb locally on Ruby 4.0.6 reproduced the failure:
| multi_json |
json 2.21.2 |
json 3.0.0 |
| 1.20.1 |
Pass |
Fail |
| 1.21.1 |
Pass |
Fail |
Upstream status
multi_json PR #67, released in v1.21.2, adds json 3.x compatibility. However, it primarily addresses parsing options and does not filter the Oj-specific generation options passed by gon.
Possible fix
Remove the explicit options from Gon::JsonDumper.dump, while preserving its final escape call:
mode: :compat and time_format: :ruby are already defaults in multi_json's Oj adapter in modern versions.
- Gon's own
escape method escapes <, >, &, U+2028, and U+2029 after JSON generation, providing the escaping needed for embedding JSON in a script tag.
Removing the options experimentally made the existing spec pass with json 3.0.0 for both tested multi_json versions.
Gon's JSON generation fails when multi_json uses the json gem as its backend with json 3.0.0.
The failure was observed in the
test-multi-json-compatibility (1.20.1)CI job:Cause
Gon::JsonDumper.dumppasses these Oj-specific options to multi_json regardless of the selected backend:When the json backend is selected, multi_json forwards them to
JSON.generate. json 2.x ignored unknown options, but json 3.0.0 raisesArgumentError.Running the existing
json_dumper_spec.rblocally on Ruby 4.0.6 reproduced the failure:Upstream status
multi_json PR #67, released in v1.21.2, adds json 3.x compatibility. However, it primarily addresses parsing options and does not filter the Oj-specific generation options passed by gon.
Possible fix
Remove the explicit options from
Gon::JsonDumper.dump, while preserving its finalescapecall:mode: :compatandtime_format: :rubyare already defaults in multi_json's Oj adapter in modern versions.escapemethod escapes<,>,&, U+2028, and U+2029 after JSON generation, providing the escaping needed for embedding JSON in a script tag.Removing the options experimentally made the existing spec pass with json 3.0.0 for both tested multi_json versions.