Search the web
Sign In
New User? Sign Up
caplet · The Caplet Group
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 166 - 195 of 309   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
166
Is there any documentation available on the specific attacks that the various rules in ADsafe are protecting against? Most of the rules are pretty obvious, but...
Kris Zyp
kriszyp
Online Now Send Email
Apr 4, 2008
7:50 pm
167
I want .get and .set to work without blacklists. They are intended to get and set data members in objects. So that is all they will allow. They will not get or...
Douglas Crockford
douglascrock...
Offline Send Email
Apr 5, 2008
2:46 pm
168
I relaxed the restriction on the [ ] operator slightly. It will now accept subscript values that are number literals or string literals that are not legal...
Douglas Crockford
douglascrock...
Offline Send Email
Apr 5, 2008
3:02 pm
169
... I recommend also accepting all so-called "stringified numbers", i.e., all x for which x === String(Number(x)) all these are implicitly and necessarily...
Mark Miller
capsecure
Offline Send Email
Apr 5, 2008
3:09 pm
170
Great, thank you for the info. Kris ... From: Douglas Crockford To: caplet@yahoogroups.com Sent: Saturday, April 05, 2008 8:46 AM Subject: [caplet] Re: ADsafe...
Kris Zyp
kriszyp
Online Now Send Email
Apr 5, 2008
3:57 pm
171
Function mutability can be a source of undefined behavior since the spec allows but doesn't require "joining" of functions that have the same body and scope...
Mike Samuel
mikesamuel
Offline Send Email
Apr 6, 2008
3:42 am
172
AFAIK, no implementation has ever actually done this "joining", and I believe ES3.1 and ES4 will very likely dissallow joining to prevent it from ever...
Kris Zyp
kriszyp
Online Now Send Email
Apr 6, 2008
4:10 am
173
... Yes, that's what we decided. ES3.1 and ES4 will be deterministic in this regard. No joining. -- Text by me above is hereby placed in the public domain ...
Mark Miller
capsecure
Offline Send Email
Apr 6, 2008
9:40 am
174
... If functions were immutable, joining would be a transparent optimization. Apart from the theoretical potential for backward incompatibility, why isn't this...
David-Sarah Hopwood
david.hopwood@...
Send Email
Apr 6, 2008
3:17 pm
175
... Actually not quite, because it would still be observable by using ===. ... -- David-Sarah Hopwood...
David-Sarah Hopwood
david.hopwood@...
Send Email
Apr 6, 2008
3:19 pm
176
... Really? It is actually even used in ADsafe's core library. Mutating functions is pretty core functionality, and AFAIK it is necessary to form multi-level...
Kris Zyp
kriszyp
Online Now Send Email
Apr 6, 2008
4:15 pm
177
Does anyone know the rationale for putting joining in the spec in the first place? mike...
Mike Samuel
mikesamuel
Offline Send Email
Apr 6, 2008
7:30 pm
178
... and "-Infinity"...
Mike Samuel
mikesamuel
Offline Send Email
Apr 6, 2008
7:54 pm
179
... You're right, I don't know what I was thinking of. Making functions immutable in ES3.1/4 is not practical. -- David-Sarah Hopwood...
David-Sarah Hopwood
david.hopwood@...
Send Email
Apr 6, 2008
8:46 pm
180
... I purposely left that out because it would already be covered by Crock's "not legal identifiers" rule. -- Text by me above is hereby placed in the public...
Mark Miller
capsecure
Offline Send Email
Apr 6, 2008
8:54 pm
181
... I'd guess it was to enable the optimization that David was suggesting. But I don't actually know. -- Cheers, --MarkM...
Mark S. Miller
erights@...
Send Email
Apr 6, 2008
9:02 pm
182
... optimization. ... functions is pretty core functionality, and AFAIK it is necessary to form multi-level prototypical inheritance. If I want object A to ...
Douglas Crockford
douglascrock...
Offline Send Email
Apr 8, 2008
4:43 pm
183
I am relaxing ADsafe to allow access to these standard globals: Array Boolean Date decodeURI decodeURIComponent encodeURI encodeURIComponent Error escape...
Douglas Crockford
douglascrock...
Offline Send Email
Apr 9, 2008
11:48 pm
184
... Is it really worth including {,un}escape in light of http://msdn2.microsoft.com/en-us/library/9yzah1fh(VS.85).aspx ? Is it a goal to support older versions...
Mike Samuel
mikesamuel
Offline Send Email
Apr 10, 2008
12:00 am
185
... No confirm, alert, or prompt? Preventing annoyance exploits? ;) Or is there another exploit I am not aware of? Kris ... From: Douglas Crockford To:...
Kris Zyp
kriszyp
Online Now Send Email
Apr 10, 2008
5:18 am
186
... is there another exploit I am not aware of? Those are not standard globals. They are creatures of the DOM. Currently, ADsafe is not granting any access to...
Douglas Crockford
douglascrock...
Offline Send Email
Apr 10, 2008
2:52 pm
187
... Did you mean Math.PI, or is X.PI allowed for any X? -- Mike Stay stay@......
♘ stay
staym_datawe...
Offline Send Email
Apr 10, 2008
3:37 pm
188
... I can see the B-movie poster now :-) More seriously, all of the objects that Doug just granted access to, with the exception of Date, provide no authority...
David-Sarah Hopwood
david.hopwood@...
Send Email
Apr 10, 2008
4:28 pm
189
... Yes. It is in anticipation of a decimal package of some sort....
Douglas Crockford
douglascrock...
Offline Send Email
Apr 10, 2008
4:28 pm
190
On 10/04/2008, David-Sarah Hopwood ... Date also provides info about the user's locale, but so does Number to some degree....
Mike Samuel
mikesamuel
Offline Send Email
Apr 10, 2008
5:09 pm
191
... Currently, ADsafe is still approximately a subset of Caja. Were these added, it would cause significant breakage of the subset relationship. -- Cheers, ...
Mark S. Miller
erights@...
Send Email
Apr 10, 2008
5:15 pm
192
... IIUC, foo['-Infinity'] would be, but foo[-Infinity] wouldn't. -- David-Sarah Hopwood...
David-Sarah Hopwood
david.hopwood@...
Send Email
Apr 11, 2008
3:16 pm
193
On 11/04/2008, David-Sarah Hopwood <david.hopwood@...> ... douglas@...> ... The two are identical. From ES262 S11.2.1 ...
Mike Samuel
mikesamuel
Offline Send Email
Apr 11, 2008
7:54 pm
194
... They are evaluated identically (if Infinity is an unshadowable constant), but they have different syntax trees. Crock' rule was defined syntactically; ...
David-Sarah Hopwood
david.hopwood@...
Send Email
Apr 11, 2008
8:04 pm
195
On 11/04/2008, David-Sarah Hopwood ... Ok. Understood....
Mike Samuel
mikesamuel
Offline Send Email
Apr 11, 2008
8:12 pm
Messages 166 - 195 of 309   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help