From: David Garamond Date: 2004-03-20T20:29:02+09:00 Subject: GString and XSS (Re: groovy) markusjais@yahoo.de wrote: >>Any comments? It seems to borrow some stuffs from Ruby, like closure >>(which is very much like Ruby's block), the =~ regex matching operator, >>and even the "Principle of Least Surprise". But syntax-wise it's >>basically a mixture of Python, Ruby, and Java. It has some stuffs that >>Ruby doesn't currently have like keyword arguments, easier embedding, >>and native threads, but it's still not Ruby :-) > > it looks cool. and it might improve the productivity for java programmers. > > I like java a lot but everytime I port one of my Java programs to Python or > Ruby I am annoyed about how much I have to type in Java (System.out.println > vs. puts/print, or opening and printing a file). > > so this might be a great addition to the java developer's toolbox. > > only future will tell if this will be a huge success or not. One interesting thing about Groovy is the GString class, which exposes the process of string interpolation to the programmer. We can extend this class to modify the behaviour of interpolation. This probably will be more interesting if implemented in Ruby because we can modify the existing builtin class, so for example we can change String so that all interpolation is HTML-escaped. This will become a very good protection for cross-site scripting. All of the web tools/template processor I've worked with, including PHP, Perl's HTML::Mason, Embperl, etc. unfortunately it seems that only Embperl puts an emphasis on escaping. By default, all strings output will be HTML-escaped or URL-escaped, depending on the context. If more tools were like this, then the occurence of SQL injection, cookie theft, and all that silly website deface could be reduced dramatically. Currently many many applications are vulnerable to XSS, the big offender being PHP and Perl/CGI scripts, but big apps like Oracle Suite are once vulnerable too. -- dave