From: Tanaka Akira Date: 2004-03-24T20:50:17+09:00 Subject: Re: GString and XSS (Re: groovy) In article <405C2AEA.9000605@zara.6.isreserved.com>, David Garamond writes: > One interesting thing about Groovy is the GString class, which exposes > the process of string interpolation to the programmer. We can extend > this class to modify the behaviour of interpolation. This probably will > be more interesting if implemented in Ruby because we can modify the > existing builtin class, so for example we can change String so that all > interpolation is HTML-escaped. This will become a very good protection > for cross-site scripting. > > All of the web tools/template processor I've worked with, including PHP, > Perl's HTML::Mason, Embperl, etc. unfortunately it seems that only > Embperl puts an emphasis on escaping. By default, all strings output > will be HTML-escaped or URL-escaped, depending on the context. > > If more tools were like this, then the occurence of SQL injection, > cookie theft, and all that silly website deface could be reduced > dramatically. Currently many many applications are vulnerable to XSS, > the big offender being PHP and Perl/CGI scripts, but big apps like > Oracle Suite are once vulnerable too. I considered similar idea for similar needs. However I found that it can be used for various purposes other than sanitizing. For example, gettext can know literal part of "...#{...}...". This makes possible to use only literal part as a key for i18n message dictionaly. This eases i18n application development. Another example is confusing String#gsub's 2nd argument. gsub can interpret "...#{1}..." as '...\1...'. This avoids confusing escape mechanism. I'd like to see it in Ruby. RCR? -- Tanaka Akira