4 ms·
Lua is one of the easiest configuration file formats I've had the pleasure of working with. Readable. Has comments. Variables. Conditionals. Everyone (includin
by thadt 1y ago
Lua is one of the easiest configuration file formats I've had the pleasure of working with. Readable. Has comments. Variables. Conditionals.
Everyone (including me): "oh no, no, you don't want a full Turing complete language in your configuration file format"
Also Everyone: generating their configuration files with every bespoke templating language dreamed of by gods and men, with other Turing complete languages.
- mcdonje 1y agoIt's a security issue. Configs are user interfaces. Devs generating configs is irrelevant.
- thadt 1y agoIndeed - it would depend greatly one's workflow and threat model.
- ModernMech 1y agoYou could solve this with a capabilities permissions system. That way the config files can be written in the same language but have configured permissions that are different from the rest of the programming language. So you could restrict the config files from resources like threads, evaling source, making network requests and whatnot. Come to think of it you could even probably section off parts of the language behind capabilties such that the config files could be configured to be a not-Turing complete subset of the language.
- justincormack 1y agoLua started as a config language.