From: zimbatm Date: 2006-01-09T19:18:02+09:00 Subject: Re: "Living Dangerous" stage 2, summarizing ideas Hi, I wanted to change the wiki but I'm not sure what I think is right really is. It seems to me that you forgot two cases where ruby's open nature is an inconvenient. Due to ruby's open-class and lack of contraints, it seems to me that you can't trust ruby code right away. You can't execute an external code in your application in a specific boundary. You can't trust it to be "evil" without reviewing it. I have two example in mind. First example. Imaging you're building a big web application where users can submit their templates (eg. blog or wiki hosting) and you're using embedded ruby in html. How can you trust that the user won't send an "evil" template without reviewing it ? (disregarding javascript XSS exploits) Second example. You're implementing a remote execution mechanism with agents. Like Java's JINI, you want clients to send pieces of code that will be executed in the server's environment and then give the result back. It's a bit like the client would send blocks to the server. How do you avoid the client sending "evil" code that would redefine how the server would work ? I'm curious how these issues can be solved. I think _why used obfuscation for http://tryruby.hobix.com/ but it's not applicable for open-source projects. There is also the SAFE variable that limit ruby's capabilities. But I think it's only applicable to the whole code, so it's not a solution. Finally, you can taint classes to make the unmutable but then you loose ruby's dynamicness. Cheers, zimba.tm