From: Hal Brodigan Date: 2008-12-17T09:10:49+09:00 Subject: [ruby-core:20603] [Bug #893] XMLRPC::Server "system.listMethods" handler returns hidden methods Bug #893: XMLRPC::Server "system.listMethods" handler returns hidden methods http://redmine.ruby-lang.org/issues/show/893 Author: Hal Brodigan Status: Open, Priority: Normal In the XMLRPC::Server, I noticed that the default handler for system.listMethods returns every method for objects that were registered with the server. This behavior is unexpected, since XMLRPC::Server will only allow public instance methods that were directly defined in the class (not inherited) to be called. Attached is a patch correcting this unexpected behavior in the "system.listMethods" handler. # # Server # require 'xmlrpc/server' class TestObject def test "this is a test" end end server = XMLRPC::Server.new server.add_introspection server.add_handler('obj', TestObject.new) server.serve # # Client # require 'xmlrpc/client' client = XMLRPC::Client.new2('http://localhost:8080') client.call('obj.test') # => "this is a test" client.call('system.listMethods') # => ["system.listMethods", "system.methodSignature", "system.methodHelp", "obj.inspect", "obj.clone", "obj.method", "obj.public_methods", "obj.instance_variable_defined?", "obj.to_yaml_style", "obj.equal?", "obj.freeze", "obj.methods", "obj.respond_to?", "obj.dup", "obj.instance_variables", "obj.__id__", "obj.eql?", "obj.object_id", "obj.test", "obj.id", "obj.singleton_methods", "obj.send", "obj.taint", "obj.frozen?", "obj.instance_variable_get", "obj.__send__", "obj.instance_of?", "obj.to_a", "obj.type", "obj.protected_methods", "obj.instance_eval", "obj.==", "obj.display", "obj.===", "obj.instance_variable_set", "obj.kind_of?", "obj.extend", "obj.to_s", "obj.to_yaml_properties", "obj.hash", "obj.class", "obj.dclone", "obj.tainted?", "obj.=~", "obj.private_methods", "obj.to_yaml", "obj.taguri", "obj.untaint", "obj.nil?", "obj.is_a?", "obj.taguri="] ---------------------------------------- http://redmine.ruby-lang.org