From: zuzu Date: 2004-08-23T02:22:23+09:00 Subject: Re: Sandboxing librarys On Sun, 22 Aug 2004 21:05:48 +0900, Dominik Werder wrote: > Hello! > > In my program I try to allow any user to write own code (event handler > here) to be loaded and included automatically. > > To enhance security, can I prevent the author to use specific > functions like eval, exec, File.* and so on? > > If I can, is it then secure? My goal is to let the author only write > handler functions that return something but he must not for example > modify the system classes, write files, do network and something like > that.. > > Thanks for suggestions! > > Dominik check out the capability security model. http://www.erights.org/elib/capability/index.html http://www.skyhunter.com/marcs/capabilityIntro/index.html 'from objects to capabilities': http://www.erights.org/elib/capability/ode/ode-capabilities.html peace, -z