From: ts Date: 2004-09-03T20:11:36+09:00 Subject: Re: Not just $SAFE, but damn $SAFE >>>>> "F" == Florian Gross writes: F> Because sometimes the user wants to do a non-stupid, but still F> unexpected thing and then flexibility is good. But I think it would F> maybe be a good idea to allow white lists via an option to the safe()-call. and where is the problem ? There are 2 cases : * some classes are safe, because you can safely use a method to create an object. For example Symbol, NilClass, TrueClass, FalseClass, Fixnum, Bignum, Float, String, Exception, Regexp, Time, Range, Array, Hash your module can handle these classes * for other classes, define a protocol - when you enter in #safe store in an array, all classes which are not tainted (test it with Kernel#tainted?) and which define the method ::secure_it - when the class of the result respond to this method, call it with the result of #eval kl.secure_it(obj) now this is the responsibilty to the user to make the "right" thing and at least it will not be the fault of *your* module if the user has a problem. It's evident that all this must be done at $SAFE >=4 Guy Decoux