in reply to Re: proper untainting and use of ref
in thread proper untainting and use of ref
my problem is i've already untainted this data once.
so the data in %params should be untainted, no? but when it's accessed later, via# ...snip... # untaint parameters for( keys %params ) { # !!!TODO!!! check 'ref' line for subtle bugs ( display_message( $messages{error} ) && exit ) unless ref($valid_params{$_}) eq 'Regexp'; if( $params{$_} =~ /$valid_params{$_}/ ) { $params{$_} = $1; } else { display_message( $messages{error} ) && exit; } }
$userfile is now tainted, even though $params{username} should be untainted. am i missing something?my $userfile = get_userfile( $config, $params{username} );
Update: modifying the get_userfile() sub like so:
so $config and its data are not tainted. why is $params{ username } still tainted?sub get_userfile { my ( $config, $username ) = ( shift, shift ); # add only this line: still tainted # ( $config->{ users } ) = ( $config->{ users } =~ /^(.+)$/ ); # add only this line: untainted # ( $username ) = ( $username =~ /^(.+)$/ ); $config->{ users } . $username; }
~Particle ;Þ
|
---|
In Section
Seekers of Perl Wisdom