[picocontainer-dev] Injecting the container
"Putrycz, Erik" <[email protected]>
| Newsgroups | gmane.comp.java.picocontainer.devel |
|---|---|
| Message-ID | <[email protected]> |
I had commented on this some time ago but it's a feature that saves me code. I think this comes again to the security problem. I'd really like to understand in which context allowing the container to inject itself into other classes would be a security issue. The only case I can imagine is that pico creates an instance of an external malicious class that does operations with the container which could harm the system. Is this the possible security issue? I know the workaround is to create a "service manager" but I don't find this elegant especially when it comes to hierarchies of containers. Any comments on this issue? Erik Putrycz, Ph.D - Research Associate / <mailto:[email protected]> [email protected] / (613) 990 0681 Institute for Information Technology - Software Engineering Group National Research Council, Canada - Building M-50, 1200 Montreal Road Ottawa, Ontario, CANADA K1A 0R6