From: harryo@... (Harry Ohlsen) Date: 2002-04-05T10:33:16+09:00 Subject: Re: Is eval a code/design smell? > I know I would. To me, that is indeed a language flaw. There should be > methods that don't open up the security holes of eval() for > finding/setting attributes of an object. I'm not quite sure what security holes you imagine can be opened up by a piece of code like ... obj.instance_eval "@{name} = value" > Your specific need for no > initialize() still seems weird to me The point is that, since you're going to overwrite every single attribute with its value from the XML then what does calling initialize achieve? On top of that, there's a major issue to do with working out what values to pass to initialize. They may not simply be the attributes of the class. > but if it is necessary, and the > language restricts you from doing it, then either the language is flawed > or you are using the wrong langauge for the task. Agreed (on the *ahem* "language is flawed" suggestion). I haven't read about the allocate() method that's been added in 1.7 yet, but I have a feeling it will be precisely what is required. > People have built applications that do everything Ruby can do in C, and > done it faster than the Ruby interpreter could do it (although with a > lot more work than Ruby would require) without ever having an eval() for > C code. ~,^ Agreed. Of course, the nice thing about Ruby is that even though this issue doesn't seem to have been handled cleanly (yet), at least I can get around it, so I'm happy ... and I think Chris is almost happy, too :-). Harry O.