$obj is defined in the calling code. That doesn't mean that it will be defined inside the sandbox. And doing "without quotes" also means that you are doing all of the work (and danger) outside of the sandbox and then just having the sandbox do eval on the results (which means you might as well not have the sandbox at all).
- tye (but my friends call me "Tye")In reply to (tye)Re2: Safe question
by tye
in thread Safe question
by djberg96
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |