https://en.wikipedia.org/w/api.php?action=parse&page=Project:Sandbox&prop=headhtml&format=json&callback=foo includes data like wgUserName and private user settings (mw.user.options.set) when you are logged in. Instead it should (like https://en.wikipedia.org/w/api.php?action=parse&text=~~~~&pst&format=json&callback=foo does) treat the user as anon, when in JSONP mode (i.e. when the callback parameter is present).
Patches
1.27:
1.26:
1.23: