I’m interesting in providing my clients the ability to upload
expressions that I can evaluate to determine the values of various
components of some business calculations. Eval’ing the expressions is
the simplest solution, but it’s of course unsafe. Can anyone help me
flesh out my list of options:
-
Why’s sandbox, which has been forked on github but doesn’t seem to
be undergoing ongoing maintenance:
GitHub - Sophrinix/sandbox: freaky-freaky security and multiplicity of ruby interps, and thus will probably be a
problem once ruby-1.9 rolls around -
Write my own parser and interpreter - any ruby libraries that would
be particularly helpful in this regard? -
Marshal the binding and the expression out to a javascript or other
safe interpreter for evaluation -
Require the expressions to be blessed by trustees before being
evaluated
Any other suggestions?
- donald