Re: untaint'ing doesn't seem to work

Shugo Maeda <[email protected]>
Newsgroups gmane.comp.apache.mod-ruby
Message-ID <[email protected]>
Hi,

At Sun, 16 May 2004 00:39:58 -0400,
Jeffrey Dik <[email protected]> wrote:
> Thanks for the reply!  Unfortunately, I couldn't get that to work.  I
> tried all kinds of File.open(filename).untaint but the script always
> died when it tried to initialize the file object.
> 
> I did happen to stumble across something that "fixed" this.  I ran the
> script exactly as below on another computer and, presto, it worked.  I
> thought the two most relevant differences was that the computer on which
> the script worked runs Apache 2.0.40 and Ruby 1.8.0 and the computer on
> which the script failed runs Apache 2.0.49 and Ruby 1.8.1.  I recompiled
> various versions of Apache numerous times to no avail.  Finally, in a
> last ditch effort, I just copied the 1.8.0 version of cgi.rb over to the
> 1.8.1 directory.  Then the script started working.  After diff'ing for a
> while, I found out the script would work with the 1.8.1 version of
> cgi.rb if I changed line 1128 from
>         class Value < DelegateClass(String)
> to
>         class Value < String
> 
> I'm not sure what "The Right Way" is here.  From the information in the
> mod_ruby FAQ, I think this script should work, but, of course, I'm
> guessing the error is in my script and not actually in cgi.rb.  Any
> ideas?

It's a problem of cgi.rb.

CGI#[] doesn't return String objects, so the return value can't
be used where String expected.
If you want String, you should use query.params["filename"][0].

  require 'cgi'

  query = CGI.new
  filename = query.params["filename"][0].dup
  filename.untaint
  File.open(filename) { |f|
    f.each_line { |l|
      print l
    }
  }

Shugo
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.