from spam import eggs, spam at runtime, how?
Rene Pijlman
reply.in.the.newsgroup at my.address.is.invalid
Wed Dec 10 05:21:39 EST 2003
Stuart Bishop:
>Rene Pijlman:
>
>> from skin import template
>>
>> where skin is only known at runtime (it's passed as a parameter or
>> hidden field to my mod_python application).
>
>That is scary - you need to treat anything arriving from the client
>as an attack.
Yes, I verify the name of the skin before the import.
--
René Pijlman
More information about the Python-list
mailing list