From: Martin DeMello Date: 2004-06-22T18:23:20+09:00 Subject: Re: Full-featured untaint() method for Ruby? Andreas Schwarz wrote: > > Do you want to escape all the characters that are dangerous for Shell, > SQL _and_ HTML "just in case"? That's pretty useless IMO; the template > engine is responsible for HTML, the database lib for SQL, and Shell is > used so rarely that you can do it by hand. You could use pluggable modules, just to prevent people writing the same code by hand over and over. require 'untaint' string.untaint(:shell) That way, anyone who writes an untainter for a particular domain can contribute it back to the central untaint project. Someone writing a new database lib could simply call untaint(:sql), for instance. martin