Re: Disable certain modules
Jim Baker <[email protected]>
| Newsgroups | gmane.comp.lang.jython.devel |
|---|---|
| Message-ID | <CAOhO=aPfv0j2_GC-W03JH0MbyPskO0zs39gqHf+TAe1WxPWztg@mail.gmail.com> |
You might get some success by applying the approach outlined here for JRuby: http://dior.ics.muni.cz/~makub/ruby/ I would be very interested to see a similar experiment with Jython. - Jim On Fri, Feb 13, 2015 at 10:03 AM, Jeff Emanuel <[email protected]> wrote: > > Instead of disabling imports, maybe a better approach is to use a Java > security manager. > That also might have difficulty distinguishing client code from jython > internals. > > > > On 2/13/2015 9:03 AM, Pradeep Badiger wrote: > > What if I don’t allow the user to import just “java”. Enforcing user to > provide the package that they want to use. > > > > Thanks, > > Pradeep V.B. > > > > *From:* Jeff Emanuel [mailto:[email protected] <[email protected]>] > *Sent:* Friday, February 13, 2015 12:36 AM > *To:* Pradeep Badiger; [email protected] > *Subject:* Re: [Jython-dev] Disable certain modules > > > > That won't work to deny access to classes in java packages. Consider > > import java > fw = java.io.FileWriter(aFilePath) > > This won't invoke __import__ with java.io as the first argument. I'm not > aware of > any way to deny script access to core Java classes. You can limit access > to classes > with a custom classloader set on PySystemState, but you'll break internals > if you prevent > loading core classes. For instance, the path module uses java.io.File. > > > On 2/12/2015 5:49 PM, Pradeep Badiger wrote: > > I had to add one more arg to the function. This works for both for the > module as well as the package. > > > > Let me know if this is the correct way to check the modules. > > > > > > import __builtin__ > > oldImport = __builtin__.__import__ > > notAllowedImports = [*'java.net <http://java.net>'*, *'java.io > <http://java.io>'*, *'shutil'*] > > def *myImport*(*args, **kwargs): > > if args[0] in notAllowedImports: > > raise ImportError(*"Import denied - "* + args[0]) > > return oldImport(*args, **kwargs) > > __builtin__.__import__ = myImport > > > > #Test > > # from java.net import Socket > > import shutil > > from email.parser import Parser > > > > Thanks, > > Pradeep V.B. > > > > *From:* Jeff Emanuel [mailto:[email protected] <[email protected]>] > *Sent:* Thursday, February 12, 2015 7:17 PM > *To:* Pradeep Badiger; [email protected] > *Subject:* Re: [Jython-dev] Disable certain modules > > > > This works for me on 2.5.3, but I'm not using PyScriptEngine. I use > PythonInterpreter directly. Does your 'from' import work > without intercepting __import__? Does it work with a trivial 'myImport' > as below? > > >>> import __builtin__ > >>> oldImport = __builtin__.__import__ > >>> def myImport(*args): > ... return oldImport(*args) > ... > >>> __builtin__.__import__=myImport > >>> import uuid > >>> from email.mime.image import MIMEImage > >>> from email.mime.multipart import MIMEMultipart > >>> > >>> print MIMEImage > email.mime.image.MIMEImage > >>> print MIMEMultipart > email.mime.multipart.MIMEMultipart > >>> > >>> import sys > >>> print sys.version > 2.5.3 (2.5:c56500f08d34+, Aug 13 2012, 14:48:36) > [Java HotSpot(TM) 64-Bit Server VM (Oracle Corporation)] > >>> > > > On 2/12/2015 1:11 PM, Pradeep Badiger wrote: > > I was trying import using “from” syntax and this logic doesn’t seem to > work. I mean I get import error from oldImport module. > > > > from email.mime.image import MIMEImage > > from email.mime.multipart import MIMEMultipart > > > > Exception in thread "main" *javax.script.ScriptException*: ImportError: > cannot import name MIMEImage in <script> at line number 122 > > at org.python.jsr223.PyScriptEngine.scriptException( > *PyScriptEngine.java:202*) > > at org.python.jsr223.PyScriptEngine.eval(*PyScriptEngine.java:42*) > > at org.python.jsr223.PyScriptEngine.eval(*PyScriptEngine.java:31*) > > > > Thanks, > > Pradeep V.B. > > > > *From:* Pradeep Badiger > *Sent:* Thursday, February 12, 2015 2:21 PM > *To:* 'Jeff Emanuel'; [email protected] > *Subject:* RE: [Jython-dev] Disable certain modules > > > > Interesting.. I will see if this fits my requirements. > > > > Thanks, > > Pradeep V.B. > > > > *From:* Jeff Emanuel [mailto:[email protected] <[email protected]>] > *Sent:* Thursday, February 12, 2015 1:53 PM > *To:* [email protected]; Pradeep Badiger > *Subject:* Re: [Jython-dev] Disable certain modules > > > > I don't know that this is fool-proof, but you can replace > __builtin__.__import__ with your own implementation that checks the module > name. > > >>> import __builtin__ > >>> oldImport = __builtin__.__import__ > >>> def myImport(*args): > ... if args[0]=='symbol': # Disallowing symbol module > ... raise ImportError("Import denied") > ... return oldImport(*args) > ... > >>> __builtin__.__import__=myImport > >>> import symbol # fails > Traceback (most recent call last): > File "<input>", line 1, in <module> > File "<input>", line 3, in myImport > ImportError: Import denied > >>> import traceback # works > >>> > > > > On 2/12/2015 8:37 AM, Pradeep Badiger wrote: > > Hi, > > > > I am trying to disable certain modules which I don’t want my users to use. > How can I do that? > > > > I tried del function to delete the module programmatically. But this > doesn’t work if you import the module again. > > > > Can someone provide me the pointers? > > > > Thanks, > > Pradeep V.B. > > > > > This email and any files transmitted with it are confidential, proprietary > and intended solely for the individual or entity to whom they are > addressed. If you have received this email in error please delete it > immediately. > > > > ------------------------------------------------------------------------------ > > Dive into the World of Parallel Programming. The Go Parallel Website, > > sponsored by Intel and developed in partnership with Slashdot Media, is your > > hub for all things parallel software development, from weekly thought > > leadership blogs to news, videos, case studies, tutorials and more. Take a > > look and join the conversation now. http://goparallel.sourceforge.net/ > > > > > > _______________________________________________ > > Jython-dev mailing list > > [email protected] > > https://lists.sourceforge.net/lists/listinfo/jython-dev > > > > > This email and any files transmitted with it are confidential, proprietary > and intended solely for the individual or entity to whom they are > addressed. If you have received this email in error please delete it > immediately. > > > > > This email and any files transmitted with it are confidential, proprietary > and intended solely for the individual or entity to whom they are > addressed. If you have received this email in error please delete it > immediately. > > > ------------------------------------------------------------------------------ > > Dive into the World of Parallel Programming. The Go Parallel Website, > > sponsored by Intel and developed in partnership with Slashdot Media, is your > > hub for all things parallel software development, from weekly thought > > leadership blogs to news, videos, case studies, tutorials and more. Take a > > look and join the conversation now. http://goparallel.sourceforge.net/ > > > > > _______________________________________________ > > Jython-dev mailing list > > [email protected] > > https://lists.sourceforge.net/lists/listinfo/jython-dev > > > > This email and any files transmitted with it are confidential, proprietary > and intended solely for the individual or entity to whom they are > addressed. If you have received this email in error please delete it > immediately. > > > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming. The Go Parallel Website, > sponsored by Intel and developed in partnership with Slashdot Media, is > your > hub for all things parallel software development, from weekly thought > leadership blogs to news, videos, case studies, tutorials and more. Take a > look and join the conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > Jython-dev mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/jython-dev > > -- - Jim jim.baker@{colorado.edu|python.org|rackspace.com|zyasoft.com} twitter.com/jimbaker github.com/jimbaker bitbucket.com/jimbaker ------------------------------------------------------------------------------ Dive into the World of Parallel Programming. The Go Parallel Website, sponsored by Intel and developed in partnership with Slashdot Media, is your hub for all things parallel software development, from weekly thought leadership blogs to news, videos, case studies, tutorials and more. Take a look and join the conversation now. http://goparallel.sourceforge.net/ _______________________________________________ Jython-dev mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/jython-dev