Re: Disable certain modules

Pradeep Badiger <[email protected]>
Newsgroups gmane.comp.lang.jython.devel
Message-ID <DDFE6B42B194104F903A334F685DC89919444EB6@mbx025-wd-ca-2.exch025.domain.local>
What if I don't allow the user to import just "java". Enforcing user to provide the package that they want to use.

Thanks,
Pradeep V.B.

From: Jeff Emanuel [mailto:[email protected]]
Sent: Friday, February 13, 2015 12:36 AM
To: Pradeep Badiger; [email protected]
Subject: Re: [Jython-dev] Disable certain modules

That won't work to deny access to classes in java packages.  Consider

import java
fw = java.io.FileWriter(aFilePath)

This won't invoke __import__ with java.io as the first argument.  I'm not aware of
any way to deny script access to core Java classes.   You can limit access to classes
with a custom classloader set on PySystemState, but you'll break internals if you prevent
loading core classes.  For instance, the path module uses java.io.File.


On 2/12/2015 5:49 PM, Pradeep Badiger wrote:
I had to add one more arg to the function. This works for both for the module as well as the package.

Let me know if this is the correct way to check the modules.


import __builtin__
oldImport = __builtin__.__import__
notAllowedImports = ['java.net', 'java.io', 'shutil']
def myImport(*args, **kwargs):
    if args[0] in notAllowedImports:
        raise ImportError("Import denied - " + args[0])
    return oldImport(*args, **kwargs)
__builtin__.__import__ = myImport

#Test
# from java.net import Socket
import shutil
from email.parser import Parser

Thanks,
Pradeep V.B.

From: Jeff Emanuel [mailto:[email protected]]
Sent: Thursday, February 12, 2015 7:17 PM
To: Pradeep Badiger; [email protected]<mailto:[email protected]>
Subject: Re: [Jython-dev] Disable certain modules

This works for me on 2.5.3, but I'm not using PyScriptEngine.  I use PythonInterpreter directly.  Does your 'from' import work
without intercepting __import__?   Does it work with a trivial 'myImport' as below?

>>>  import __builtin__
>>>  oldImport = __builtin__.__import__
>>>  def myImport(*args):
...    return oldImport(*args)
...
>>>  __builtin__.__import__=myImport
>>>  import uuid
>>>  from email.mime.image import MIMEImage
>>>  from email.mime.multipart import MIMEMultipart
>>>
>>>  print MIMEImage
email.mime.image.MIMEImage
>>>  print MIMEMultipart
email.mime.multipart.MIMEMultipart
>>>
>>>  import sys
>>>  print sys.version
2.5.3 (2.5:c56500f08d34+, Aug 13 2012, 14:48:36)
[Java HotSpot(TM) 64-Bit Server VM (Oracle Corporation)]
>>>


On 2/12/2015 1:11 PM, Pradeep Badiger wrote:
I was trying import using "from" syntax and this logic doesn't seem to work. I mean I get import error from oldImport module.

from email.mime.image import MIMEImage
from email.mime.multipart import MIMEMultipart

Exception in thread "main" javax.script.ScriptException: ImportError: cannot import name MIMEImage in <script> at line number 122
       at org.python.jsr223.PyScriptEngine.scriptException(PyScriptEngine.java:202)
       at org.python.jsr223.PyScriptEngine.eval(PyScriptEngine.java:42)
       at org.python.jsr223.PyScriptEngine.eval(PyScriptEngine.java:31)

Thanks,
Pradeep V.B.

From: Pradeep Badiger
Sent: Thursday, February 12, 2015 2:21 PM
To: 'Jeff Emanuel'; [email protected]<mailto:[email protected]>
Subject: RE: [Jython-dev] Disable certain modules

Interesting.. I will see if this fits my requirements.

Thanks,
Pradeep V.B.

From: Jeff Emanuel [mailto:[email protected]]
Sent: Thursday, February 12, 2015 1:53 PM
To: [email protected]<mailto:[email protected]>; Pradeep Badiger
Subject: Re: [Jython-dev] Disable certain modules

I don't know that this is fool-proof, but you can replace __builtin__.__import__ with your own implementation that checks the module name.

>>> import __builtin__
>>> oldImport = __builtin__.__import__
>>> def myImport(*args):
...   if args[0]=='symbol':  # Disallowing symbol module
...     raise ImportError("Import denied")
...   return oldImport(*args)
...
>>> __builtin__.__import__=myImport
>>> import symbol  # fails
Traceback (most recent call last):
  File "<input>", line 1, in <module>
  File "<input>", line 3, in myImport
ImportError: Import denied
>>> import traceback # works
>>>


On 2/12/2015 8:37 AM, Pradeep Badiger wrote:
Hi,

I am trying to disable certain modules which I don't want my users to use. How can I do that?

I tried del function to delete the module programmatically. But this doesn't work if you import the module again.

Can someone provide me the pointers?

Thanks,
Pradeep V.B.


This email and any files transmitted with it are confidential, proprietary and intended solely for the individual or entity to whom they are addressed. If you have received this email in error please delete it immediately.




------------------------------------------------------------------------------

Dive into the World of Parallel Programming. The Go Parallel Website,

sponsored by Intel and developed in partnership with Slashdot Media, is your

hub for all things parallel software development, from weekly thought

leadership blogs to news, videos, case studies, tutorials and more. Take a

look and join the conversation now. http://goparallel.sourceforge.net/





_______________________________________________

Jython-dev mailing list

[email protected]<mailto:[email protected]>

https://lists.sourceforge.net/lists/listinfo/jython-dev


This email and any files transmitted with it are confidential, proprietary and intended solely for the individual or entity to whom they are addressed. If you have received this email in error please delete it immediately.


This email and any files transmitted with it are confidential, proprietary and intended solely for the individual or entity to whom they are addressed. If you have received this email in error please delete it immediately.



------------------------------------------------------------------------------

Dive into the World of Parallel Programming. The Go Parallel Website,

sponsored by Intel and developed in partnership with Slashdot Media, is your

hub for all things parallel software development, from weekly thought

leadership blogs to news, videos, case studies, tutorials and more. Take a

look and join the conversation now. http://goparallel.sourceforge.net/




_______________________________________________

Jython-dev mailing list

[email protected]<mailto:[email protected]>

https://lists.sourceforge.net/lists/listinfo/jython-dev


This email and any files transmitted with it are confidential, proprietary and intended solely for the individual or entity to whom they are addressed. If you have received this email in error please delete it immediately.

------------------------------------------------------------------------------
Dive into the World of Parallel Programming. The Go Parallel Website,
sponsored by Intel and developed in partnership with Slashdot Media, is your
hub for all things parallel software development, from weekly thought
leadership blogs to news, videos, case studies, tutorials and more. Take a
look and join the conversation now. http://goparallel.sourceforge.net/

_______________________________________________
Jython-dev mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/jython-dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.