3 ms·
Q: What happens when you combine this with the default Ruby OpenSSL certificate verification level? (Hint: the default verify setting is 'none'.) I'm also not
by rcoder 17y ago
Q: What happens when you combine this with the default Ruby OpenSSL certificate verification level? (Hint: the default verify setting is 'none'.)
I'm also not sure this is worth an entire blog post, given how little code is required to implement it:
require 'open-uri'
module Kernel
alias :_orig_require :require
def require(mod)
mod =~ %r{^https?://} ? eval(open(mod).read) : _orig_require(mod)
end
end
Edit: I should have phrased that a little more constructively. My point was not to suggest that small snippets of code are unworthy of blog discussion; rather, it was to show that the code in question really was equivalent to any case of 'eval' applied to untrusted input. I.e., a Bad Idea.