As someone pointed out to me recently, you also have to beware of arbitrary
code in regular expressions, like

perl -e 'my $txt = "howdy!";$txt =~ [EMAIL PROTECTED]@qx{ls -al /[EMAIL 
PROTECTED];print $txt'

I would be interested in ideas on how to avoid that as well.

Earl

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Chris Winters
Sent: Tuesday, October 05, 2004 10:58 AM
To: [EMAIL PROTECTED]
Subject: Re: [Templates] Limiting TT2's features


On Tue, 5 Oct 2004 12:54:26 -0400, Darren Chamberlain <[EMAIL PROTECTED]>
wrote:
> Template::Context.  Just subclass Template::Context and implement your
> own include method.  This has the advatange of changing the meaning of
> the INCLUDE directive, while not altering the grammar at all, so your
> users could still do:

Of course. You'd think I'd remember this since I wrote one of these already
:-)

http://cvs.sourceforge.net/viewcvs.py/openinteract/OpenInteract2/lib/OpenInt
eract2/TT2/Context.pm?rev=1.2&view=auto

Chris

-- 
Chris Winters ([EMAIL PROTECTED])
Building enterprise-capable snack solutions since 1988.

_______________________________________________
templates mailing list
[EMAIL PROTECTED]
http://lists.template-toolkit.org/mailman/listinfo/templates

_______________________________________________
templates mailing list
[EMAIL PROTECTED]
http://lists.template-toolkit.org/mailman/listinfo/templates

Reply via email to