3 ms·
`exec #{Rails.root}/tmp/go_#{m} #{arguments}` The escaping leaves a bit to be desired.
by cotillion 12y ago
`exec #{Rails.root}/tmp/go_#{m} #{arguments}`
The escaping leaves a bit to be desired.
- steventhedev 12y agoMore than just the escaping. You should also clean your environment, providing the child process with a bare minimum of information it needs to do its job. Otherwise you leave yourself open to future security issues, especially if you keep API keys or DB passwords in ENV.
- DrJokepu 12y agoAlso, it's generally a good idea to write code where the original developer's intent can be easily figured out by looking at the code. If the code is too compact, does too much magic (or it's too verbose, which is the other extreme) it can be difficult to tell what was intentional, how it was meant to work, if something is a bug or not. The code should "tell a story", so to speak.