The following are the different ways in which an XSSI attack can be prevented:
- All JSON responses are prefixed with string such as )]}',\n. This makes the JSON response non-executable.
- Angular recognizes the previously mentioned string and strips it prior to parsing the response.
- The server should avoid embedding user related information in dynamically generated JavaScript files.