From: Andreas Schwarz Date: 2004-06-22T15:23:16+09:00 Subject: Re: Full-featured untaint() method for Ruby? Randy Lawrence wrote: > What we'd like to find out is if there is a ruby class or method that > will fully parse+modify+untaint (rather than simply removing the taint > flag) of: > > 1. strings potentially utilized as part of a shell command > (prevent shell command injection) > > 2. strings potentially utilized as part of sql statements > (prevent sql injection) > > 3. strings potentially utilized as part of html documents ^^^^^^^^^^^ Do you want to escape all the characters that are dangerous for Shell, SQL _and_ HTML "just in case"? That's pretty useless IMO; the template engine is responsible for HTML, the database lib for SQL, and Shell is used so rarely that you can do it by hand.