from spam import eggs, spam at runtime, how?

Rene Pijlman reply.in.the.newsgroup at my.address.is.invalid
Wed Dec 10 05:21:39 EST 2003


Stuart Bishop:
>Rene Pijlman:
>
>>    from skin import template
>>
>> where skin is only known at runtime (it's passed as a parameter or 
>> hidden field to my mod_python application).
>
>That is scary - you need to treat anything arriving from the client
>as an attack.

Yes, I verify the name of the skin before the import.

-- 
René Pijlman




More information about the Python-list mailing list