3 ms·
You can do that in Haskell easily. data UnsafeString = Unsafe String htmlencode :: String -> String sanitizeUnsafeStr :: UnsafeString -> String sanitiz
by rtra 18y ago
You can do that in Haskell easily.
data UnsafeString = Unsafe String
htmlencode :: String -> String
sanitizeUnsafeStr :: UnsafeString -> String
sanitizeUnsafeStr (Unsafe cs) = htmlencode cs
- rtra 18y agoTo further expand on this, we would have a request function returning type IO UnsafeString, and all output functions would have type IO String. By abstracting the UnsafeString type we would make sure its users don't use the type's internal representation (I don't yet know if this is possible in Haskell,) so the only way to use input as of type String would be by asking a private module for a conversion, which would sanitize any dangerous input. Now you only have to look to the input methods to be sure no unsafe input is getting through.
- Jebdm 18y agoYou can do it in any OO language easily as well. For instance, in Python: class UnsafeString: def __init__(self, str): self._str = str self._sanitized = None def __str__(self): return self.sanitize() def unsafe(self): return self._str def sanitize(self): if self._sanitized != None: return self._sanitized else: self._sanitized = sanitize(self._sanitized) return self._sanitized That way, as long as you wrap all input in the UnsafeString class, you'll have to be explicit if you want the unsafe version and you'll get the safe version by default.
- rtra 18y agoPrecisely. Isn't user input handled like this on most web code? It seems the most sensible way to do it.