Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.javascript > #17105
| Path | csiph.com!usenet.pasdenom.info!aioe.org!.POSTED!not-for-mail |
|---|---|
| From | Cezary Tomczyk <cezary.tomczyk@gmail.com> |
| Newsgroups | comp.lang.javascript |
| Subject | Re: eval - how to |
| Date | Fri, 09 Nov 2012 22:28:44 +0100 |
| Organization | Aioe.org NNTP Server |
| Lines | 111 |
| Message-ID | <k7jsi7$h6a$1@speranza.aioe.org> (permalink) |
| References | <k7iqg9$n49$1@speranza.aioe.org> <ad4ffcf9-f94f-44c4-b425-7310b78e92bb@m13g2000vbd.googlegroups.com> |
| NNTP-Posting-Host | RMrsF+s1qSnxq5Qkkqjnpw.user.speranza.aioe.org |
| Mime-Version | 1.0 |
| Content-Type | text/plain; charset=ISO-8859-1; format=flowed |
| Content-Transfer-Encoding | 7bit |
| X-Complaints-To | abuse@aioe.org |
| User-Agent | Mozilla/5.0 (Windows NT 6.1; WOW64; rv:16.0) Gecko/20121026 Thunderbird/16.0.2 |
| X-Notice | Filtered by postfilter v. 0.8.2 |
| Xref | csiph.com comp.lang.javascript:17105 |
Show key headers only | View raw
W dniu 2012-11-09 14:53, Asen Bozhilov pisze:
> Cezary Tomczyk wrote:
>> According to "Better not use eval() because ... ":
>>
>> How to use eval in a correct way?
>>
>> For example when I'll get the JavaScript (or any other EcmaScript
>> implementation) code through XMLHttpRequest then how to safely eval the
>> code?
>
> Your question skips your intentions of using `eval'. Without them, it
> is almost impossible to tell you what is the correct way to use
> `eval`. Now every usage of `eval` seems wrong. You should be more
> concrete about it.
Right. I would like to get data from server using XMLHttpRequest and
then, based on header from server response and data type, parse and run
JavaScript code.
> The problem with the `eval` except the performance is that it uses the
> Variable Object of the calling execution context during variable
> instantiation. It is easy to shot you in your foot in other words. In
> regular ECMAScript3 environment you can use:
>
> (function () {
> eval(code);
> })();
>
> It creates new execution context with separate variable object from
> the surrounding execution context. Now the variable instantiation of
> the eval is safer. It works exactly how ES5 strict-mode eval works. In
> ES5 strict-mode, direct call of `eval` will create new Lexical
> Environment which is used for the variables in eval code. Of course it
> is still the problem that code passed to eval, could alter existing
> variable in the scope chain or some global variables. In case you want
> to truncate the scope chain for the `eval` call, you should not use
> `eval` at all. Using Function constructor will do exactly that.
> Function constructor never creates closure with the calling execution
> context. Its internal [[Scope]] property always refers to Global
> Object.
>
> (function () {
> var a = 10;
> Function('a = 20')();
> console.log(a); //10
> })();
> console.log(a); //20
Correct me if I am wrong, but if I will use closure around my methods
and variables then they are not outside available. So, potentially bad
code, which can be run using Function, have no access to my variables
and methods, right? Example:
var t = 50;
(function(){
var s = 100;
})();
(function () {
var a = 10;
Function('a = 20; b = t; c = s;')();
console.log(a,b,c); //10,50
})();
console.log(a,b,c); //20,50
Then I've got from console "ReferenceError: s is not defined" which is
expected by me.
But I am afraid that in real life I have to expose some variables and
methods outside of closure. I mean, as a global variables or methods.
So, if we speaking about getting string from server (XMLHttpRequest) and
execute code what exactly means that using eval is insecure? Or maybe I
misunderstanding something. :-(
> First console.log output 10, which means the code passed to the
> function is not able to alter the value of `a`. It is because the
> function created by Function constructor does not form a closure with
> surrounding function.
> The second console.log, outputs 20, because in ES3 undeclared
> variables "leak" to the Global Object. In ECMAScript 5 strict-mode all
> the variables should be declared otherwise it is ReferenceError when
> you try to assign a value to undeclared variable.
>
> There is other story of undirected `eval` in ECMAScript 5.
>
> (function () {
> var ev = eval, //Store a reference to built-in eval
> a = 10;
> ev('var a = 20');
> console.log(a); //10
> })();
> console.log(a); //20
>
> Now you would expect that calling `ev` the passed code will use the
> Variable Object of the calling execution context, but this is not
> true. This is because that is indirect calling of `eval`. According
> ECMAScript5 10.4.2 Entering Eval Code, the indirect calls of the eval,
> will evaluate the passed code, as it was a code in global execution
> context. In other words the code will use the Global Object for its
> variable and function declaration.
> But indeed, you should write your intention to use eval and probably
> there would be better responses.
The question is above.
--
Cezary Tomczyk
http://www.ctomczyk.pl/
Back to comp.lang.javascript | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-09 12:47 +0100
Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-09 05:53 -0800
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-09 22:28 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 10:23 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 11:15 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-11 00:35 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 20:34 +0100
Re: eval - how to Dr J R Stockton <reply1245@merlyn.demon.co.uk.invalid> - 2012-11-10 22:42 +0000
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-09 17:46 +0100
Re: eval - how to Tim Streater <timstreater@greenbee.net> - 2012-11-09 17:00 +0000
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-09 18:19 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-09 22:49 +0100
Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-09 16:40 -0800
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 11:36 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-10 13:29 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 13:55 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-10 14:17 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 20:50 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-10 22:54 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 15:22 +0100
Re: eval - how to Cezary Tomczyk <cezary.tomczyk@gmail.com> - 2012-11-11 16:24 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 19:23 +0100
Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-11 10:40 -0800
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 20:41 +0100
Re: eval - how to Asen Bozhilov <asen.bozhilov@gmail.com> - 2012-11-11 13:34 -0800
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-11 23:03 +0100
Re: eval - how to Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-11-10 10:21 +0100
Re: eval - how to SAM <stephanemoriaux.NoAdmin@wanadoo.fr.invalid> - 2012-11-10 04:16 +0100
csiph-web