in reply to Re: (Ovid) Re: A Quest for Taint
in thread A Quest for Taint
This is more than just something that would be 'nice' to have. I'm working hard to get perl accepted as a approved development language where I work, and insisting on taint mode is a big key on selling perl security.
We are a large corporation with tons of beaurocratic steps at every phase of development, staging, and production. We have one brave development group that's pushing forward with a huge perl dependant application that's just hit a huge problem with taint mode.
The application is actually part of numerous enviornments so the paths to the libraries change with each execution depending upon $ENV{USR_LOCAL_LIB_PATH}. With no way to untaint the $ENV{USR_LOCAL_LIB_PATH} prior to execution time there is no way to update the @INC at compile time.
The only way I can see around this is to establish separate perl binaries/libraries for each enviornment... not an easy thing to do with separate sysadmin, security, and development beaurocracies all with hands mucking up the machinery of progress.
I don't suppose anyone see's another way around this? (Hardcoding the lib paths is NOT an option.)
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Re: (Ovid) Re: A Quest for Taint
by chipmunk (Parson) on Dec 13, 2000 at 10:49 UTC | |
by coreolyn (Parson) on Dec 13, 2000 at 11:16 UTC | |
by chipmunk (Parson) on Dec 14, 2000 at 01:31 UTC | |
by coreolyn (Parson) on Dec 14, 2000 at 01:36 UTC |