Search the web
Sign In
New User? Sign Up
caplet · The Caplet Group
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 145 - 174 of 309   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
145
... ... Now that ANTLR 3 has a retargetable backend, this might be a good motivation to get a JavaScript backend implemented. ActionScript, perl, Python &...
Monty Zukowski
monty_zukowski
Offline Send Email
Feb 1, 2008
3:50 pm
146
I updated JSLint today in a step to bring more truth to this expression: JSON < ADsafe < Cajita < Caja < ES3 < Proposed ES4 ADsafe now allows all strings as...
Douglas Crockford
douglascrock...
Offline Send Email
Feb 19, 2008
9:03 pm
147
I relaxed the ADsafe.get(object, name) function. The only names it excludes now are the _hanging_underbar_ names. It allows all other names. It requires that...
Douglas Crockford
douglascrock...
Offline Send Email
Feb 20, 2008
11:38 pm
148
I have been thinking about capabilities-based security and ES subsets like ADsafe and Caja, and was thinking about another subset that is intriguing to me and...
Kris Zyp
kriszyp
Online Now Send Email
Feb 27, 2008
9:02 pm
149
I am the co-chair of the second workshop on Web 2.0 Security and Privacy (http://seclab.cs.rice.edu/w2sp/2008/cfp.html). It will be held the day after the IEEE...
Larry Koved
larrykoved
Offline Send Email
Mar 5, 2008
3:13 am
150
Doug/ADsafe people, Has there been any efforts to produce a lightweight minimal-sized ADsafe validator? With the coming browser capabilities in Cross-site XHR...
Kris Zyp
kriszyp
Online Now Send Email
Mar 17, 2008
1:40 am
151
... ADsafe validator? With the coming browser capabilities in Cross-site XHR (MS's XDR and W3C/AC proposal) and the new postMessage API, it seems there will be...
Douglas Crockford
douglascrock...
Offline Send Email
Mar 17, 2008
1:11 pm
152
Results of a quick experiment: Pulling stuff out of JSLint.js that is not needed for ADsafe validation of JavaScript produced an adsafe.js file that is 34K. I...
Douglas Crockford
douglascrock...
Offline Send Email
Mar 17, 2008
5:05 pm
153
... A validator for a Javascript subset like ADsafe does have to check for syntactic validity, because: - it cannot trust the browser's eval to accept only...
David-Sarah Hopwood
david.hopwood@...
Send Email
Mar 17, 2008
5:05 pm
154
Here is my attempt at an ADsafe validator: http://www.persvr.org/test/capability-validate.html Let me know if anyone can find any false acceptances (scripts...
Kris Zyp
kriszyp
Online Now Send Email
Mar 18, 2008
8:19 pm
155
... get successfully eval'ed that are unsafe). ... presume that it is also a lot faster since it is using simpler regex-based checking rather than full AST...
Douglas Crockford
douglascrock...
Offline Send Email
Mar 20, 2008
1:57 pm
156
... Yes, regular expression based validation does seem impropable. However, it seems like you could also make an argument that it easier to reason about and...
Kris Zyp
kriszyp
Online Now Send Email
Mar 20, 2008
2:50 pm
157
... Do we have a regression test suite of tricky examples? For instance, I don't see the string "cc_on" in Kris' validator, but that feature tripped up ADsafe...
Adam Barth
hk9565
Offline Send Email
Mar 20, 2008
6:35 pm
158
... That would be awesome. ... Thanks for the heads, fixed it. Thanks, Kris...
Kris Zyp
kriszyp
Online Now Send Email
Mar 21, 2008
7:21 pm
159
... Can you disallow @ outside of string literals entirely? What if ADSafe code is included in a container that has @cc_on, and does an @set that overrides a...
Mike Samuel
mikesamuel
Offline Send Email
Mar 21, 2008
7:40 pm
160
... '@' does not appear anywhere in the ES3 grammar outside string literals, regexp literals, and comments, right? Isn't ADsafe defined to be a subset of ES3? ...
David-Sarah Hopwood
david.hopwood@...
Send Email
Mar 21, 2008
11:09 pm
161
On 21/03/2008, David-Sarah Hopwood ... Yep. @ often appears in JSDoc style comments: http://jsdoc.sourceforge.net/#tagref so banning @ in comments might make...
Mike Samuel
mikesamuel
Offline Send Email
Mar 22, 2008
12:05 am
162
... Certainly seems reasonable to insist that containers don't do the eval inside a @cc_on. Kris...
Kris Zyp
kriszyp
Online Now Send Email
Mar 22, 2008
3:02 am
163
... I meant my point a bit more generally: Assume that any extension to strict ES3 is designed by an evil genius trying to break ADsafe (or Caja, or whatever),...
David-Sarah Hopwood
david.hopwood@...
Send Email
Mar 22, 2008
3:04 am
164
On 21/03/2008, David-Sarah Hopwood ... Or a committee of evil geniuses. ... Caja deals with many of these problems by rewriting. We can deal perfectly well...
Mike Samuel
mikesamuel
Offline Send Email
Mar 22, 2008
3:20 am
165
... Also, because with the new cross-site XHR and XDR capabilities, web sites can directly request the scripts from other sites, which can potentially be...
Kris Zyp
kriszyp
Online Now Send Email
Mar 22, 2008
3:35 am
166
Is there any documentation available on the specific attacks that the various rules in ADsafe are protecting against? Most of the rules are pretty obvious, but...
Kris Zyp
kriszyp
Online Now Send Email
Apr 4, 2008
7:50 pm
167
I want .get and .set to work without blacklists. They are intended to get and set data members in objects. So that is all they will allow. They will not get or...
Douglas Crockford
douglascrock...
Offline Send Email
Apr 5, 2008
2:46 pm
168
I relaxed the restriction on the [ ] operator slightly. It will now accept subscript values that are number literals or string literals that are not legal...
Douglas Crockford
douglascrock...
Offline Send Email
Apr 5, 2008
3:02 pm
169
... I recommend also accepting all so-called "stringified numbers", i.e., all x for which x === String(Number(x)) all these are implicitly and necessarily...
Mark Miller
capsecure
Offline Send Email
Apr 5, 2008
3:09 pm
170
Great, thank you for the info. Kris ... From: Douglas Crockford To: caplet@yahoogroups.com Sent: Saturday, April 05, 2008 8:46 AM Subject: [caplet] Re: ADsafe...
Kris Zyp
kriszyp
Online Now Send Email
Apr 5, 2008
3:57 pm
171
Function mutability can be a source of undefined behavior since the spec allows but doesn't require "joining" of functions that have the same body and scope...
Mike Samuel
mikesamuel
Offline Send Email
Apr 6, 2008
3:42 am
172
AFAIK, no implementation has ever actually done this "joining", and I believe ES3.1 and ES4 will very likely dissallow joining to prevent it from ever...
Kris Zyp
kriszyp
Online Now Send Email
Apr 6, 2008
4:10 am
173
... Yes, that's what we decided. ES3.1 and ES4 will be deterministic in this regard. No joining. -- Text by me above is hereby placed in the public domain ...
Mark Miller
capsecure
Offline Send Email
Apr 6, 2008
9:40 am
174
... If functions were immutable, joining would be a transparent optimization. Apart from the theoretical potential for backward incompatibility, why isn't this...
David-Sarah Hopwood
david.hopwood@...
Send Email
Apr 6, 2008
3:17 pm
Messages 145 - 174 of 309   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help