From: Kaspar Schiess Date: 2004-06-22T18:30:53+09:00 Subject: Re: Full-featured untaint() method for Ruby? -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Martin DeMello wrote: | You could use pluggable modules, just to prevent people writing the same | code by hand over and over. | | require 'untaint' | | string.untaint(:shell) | | That way, anyone who writes an untainter for a particular domain can | contribute it back to the central untaint project. Someone writing a new | database lib could simply call untaint(:sql), for instance. Are the semantics of untainting not really dependent on what one wants to protect against ? That said, I agree that having some general purpose untainting is a good thing. As long as it does not trick you into a false sense of security. I still like the 'just pass in the numbers and decode what they mean on the server side' approach. kaspar semantics & semiotics code manufacture www.tua.ch/ruby -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFA1/1WFifl4CA0ImQRAm0wAKChdaS5Pqi+SsdRRRh0TBLiGdxI2gCfWw9t nkqcjQ0b7CBetjxah5vycmw= =XIF+ -----END PGP SIGNATURE-----