From: dblack@... Date: 2007-06-08T20:25:53+09:00 Subject: Re: How to use strings as code Hi -- On Fri, 8 Jun 2007, Robert Klemme wrote: > On 08.06.2007 02:36, Giles Bowkett wrote: >> On 6/7/07, Kyle Rabe wrote: >>> In short, I'm looking for a way to grab a string from a database and use >>> it as code in my rails app. I understand the security implications, but >>> it's still what I want to do (and I don't know what other options I >>> have!). >> >> it's pretty easy, but I wouldn't recommend doing it. >> >> string = "p 'hello world'" >> eval(string) > > To make it safer, he could do some checks to verify the filter is legal, > something like > > def convert(filter) > case filter > when /\A\d+\.{2,3}\d+\z/, /\A[+-]?\d+\z/ > eval filter > ... > else > raise "Filter Error: #{filter}" > end > end Another thought would be to store the ranges as non-code data, in their own table -- basically two integers per record -- and then construct the range dynamically (but just using regular range syntax, without eval) from those values. David -- Q. What is THE Ruby book for Rails developers? A. RUBY FOR RAILS by David A. Black (http://www.manning.com/black) (See what readers are saying! http://www.rubypal.com/r4rrevs.pdf) Q. Where can I get Ruby/Rails on-site training, consulting, coaching? A. Ruby Power and Light, LLC (http://www.rubypal.com)