develooper Front page | perl.perl5.porters | Postings from September 2012

Re: Use Module::Load More Pervasively (was Re: Re: Taking CPANPLUSout of core)

Thread Previous | Thread Next
From:
Leon Timmermans
Date:
September 29, 2012 13:36
Subject:
Re: Use Module::Load More Pervasively (was Re: Re: Taking CPANPLUSout of core)
Message ID:
CAHhgV8h98f9fSJ-rG26S0XnJ1ySxHZ_+R-MkLfvrU-PqrRYn8Q@mail.gmail.com
On Sat, Sep 29, 2012 at 7:03 PM, chromatic <chromatic@wgz.org> wrote:
> On Saturday, September 29, 2012 06:25:10 PM Leon Timmermans wrote:
>
>> I definitely think Module::Load should stay in, it's one of those
>> things that shouldn't have needed a module in the first place IMO.
>
> If it can replace the eval "require $module; 1" idiom in core modules, so much
> the better. Some of those instances of $module in the core don't check that
> $module can *only* contain valid module names or file paths.
>
> This probably deserves an audit.

It doesn't help that the require documentatoin shows this trick
without pointing out the security implications.

Leon

Thread Previous | Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About