class Project
def name(val = NULL)
set_or_return(:name, val)
end
def description(val = NULL)
set_or_return(:description, val)
end
end
Slide 7
Slide 7 text
class
set_or_return(
set_or_return(
end
def name(val = NULL)
set_or_return(:name, val)
end
Slide 8
Slide 8 text
class
set_or_return(
set_or_return(
end
def description(val = NULL)
set_or_return(:description, val)
end
Slide 9
Slide 9 text
class
instance_variable_get(
instance_variable_set(
end
def set_or_return(key, val)
if val.equal?(NULL)
instance_variable_get(:"@#{key}")
else
instance_variable_set(:"@#{key}", val)
end
end
Slide 10
Slide 10 text
class
# @overload name(val)
# Sets the name of this project
# @param [String] val
# @overload name
# Returns this project's name
# @return [String]
end
# @overload name(val)
# Sets the name of this project
# @param [String] val
# @overload name
# Returns this project's name
# @return [String]
def name(val = NULL)
Slide 11
Slide 11 text
class
end
def name(val)
@name = val
end
def name
@name
end
class
set_or_return(
set_or_return(
# ...
end
name "Hamlet"
description "A classic"
Slide 28
Slide 28 text
class
set_or_return(
set_or_return(
# ...
end
name "Hamlet"
description "A classic"
name #=> "Hamlet"
Slide 29
Slide 29 text
class
set_or_return(
set_or_return(
# ...
end
name "Hamlet"
description "A #{name}"
Slide 30
Slide 30 text
class
set_or_return(
set_or_return(
# ...
end
name "Hamlet"
description "A Hamlet"
Slide 31
Slide 31 text
BasicObject#instance_eval
Evaluates a string containing Ruby
source code within the context of
the receiver.
Slide 32
Slide 32 text
BasicObject#instance_eval
... the variable self is set to obj
while the code is executing, giving
the code access to obj’s instance
variables
Slide 33
Slide 33 text
BasicObject#instance_eval
... the variable
while the code is executing,
the code access to
variables
giving
the code access to obj’s instance
variables
Slide 34
Slide 34 text
class Project
end
Slide 35
Slide 35 text
class Project
def self.load(path)
end
end
Slide 36
Slide 36 text
class Project
def self.load(path)
contents = IO.read(path)
end
end
Slide 37
Slide 37 text
class Project
def self.load(path)
contents = IO.read(path)
filename = File.basename(path)
end
end
Slide 38
Slide 38 text
class Project
def self.load(path)
contents = IO.read(path)
filename = File.basename(path)
new.tap do |i|
i.instance_eval(contents, filename, 1)
end
end
end
Slide 39
Slide 39 text
Project.load("/path/to/file")
Slide 40
Slide 40 text
>
RUBY CLASS
Slide 41
Slide 41 text
>
RUBY
INSTANCE
Slide 42
Slide 42 text
>
RUBY
INSTANCE
Slide 43
Slide 43 text
>
RUBY
INSTA
Slide 44
Slide 44 text
>
RUBY
INSTA
RUBY
Slide 45
Slide 45 text
>
RUBY
Slide 46
Slide 46 text
RUBY
name "hamlet"
description
# ...
Slide 47
Slide 47 text
RUBY
name "hamlet"
description
# ...
CLASS
Slide 48
Slide 48 text
RUBY
name "hamlet"
description
# ...
INSTANCE
Slide 49
Slide 49 text
RUBY
name "hamlet"
description
# ...
INSTANCE
Slide 50
Slide 50 text
RUBY
name "hamlet"
description
# ...
INSTA
Slide 51
Slide 51 text
RUBY
name "hamlet"
description
# ...
self.name
#=> "hamlet"
Slide 52
Slide 52 text
METHOD SCOPE
BIND #1
Slide 53
Slide 53 text
METHOD SCOPE
BIND #1
-JOKE
Slide 54
Slide 54 text
BECAUSE THERE IS
NO SCOPE
Slide 55
Slide 55 text
class Project
protected :name
private :description
end
Slide 56
Slide 56 text
No content
Slide 57
Slide 57 text
class Project
def method
# ...
end
end
Slide 58
Slide 58 text
class Project
def method
# ...
end
end
>
RUBY
Slide 59
Slide 59 text
class Project
def method
# ...
end
end
instance_eval >
RUBY
Slide 60
Slide 60 text
project.name
Slide 61
Slide 61 text
project.name
NoMethodError: protected method `name' called
Slide 62
Slide 62 text
project.name
NoMethodError: protected method `name' called
Slide 63
Slide 63 text
project.name
NoMethodError: protected method `name' called
project.instance_eval { name }
Slide 64
Slide 64 text
project.name
NoMethodError: protected method `name' called
project.instance_eval { name }
"hamlet"
Slide 65
Slide 65 text
SCOPE CREEP
BIND #2
Slide 66
Slide 66 text
A PROBABILITY FOR
COLLISION
Slide 67
Slide 67 text
class Project
def name(val = NULL)
set_or_return(:name, val)
end
end
Slide 68
Slide 68 text
class Project
def name(val = NULL)
set_or_return(:name, val)
end
private
def sanitize(val)
end
end
Slide 69
Slide 69 text
class Project
def name(val = NULL)
set_or_return(:name, val)
end
private
def sanitize(val)
return val if val.equal?(NULL)
end
end
Slide 70
Slide 70 text
class Project
def name(val = NULL)
set_or_return(:name, val)
end
private
def sanitize(val)
return val if val.equal?(NULL)
val.downcase.gsub(/\s+/, "-")
end
end
Slide 71
Slide 71 text
class Project
def name(val = NULL)
set_or_return(:name, sanitize(val))
end
private
def sanitize(val)
return val if val.equal?(NULL)
val.downcase.gsub(/\s+/, "-")
end
end
Slide 72
Slide 72 text
RUBY
name "Some String"
self.name
Slide 73
Slide 73 text
RUBY
name "Some String"
self.name
#=> "some-string"
Slide 74
Slide 74 text
RUBY
def sanitize(val)
val.upcase
end
name "Some String"
self.name
Slide 75
Slide 75 text
RUBY
def sanitize(val)
val.upcase
end
name "Some String"
self.name
#=> "SOME STRING"
Slide 76
Slide 76 text
USELESS VALIDATION
BIND #3
Slide 77
Slide 77 text
BasicObject#instance_eval
... the variable
while the code is executing,
the code access to
variables
giving
the code access to obj’s instance
variables
Slide 78
Slide 78 text
VALIDATION CAN BE
BYPASSED
Slide 79
Slide 79 text
class Project
def set_or_return(key, val)
if val.equal?(NULL)
instance_variable_get(:"@#{key}")
else
instance_variable_set(:"@#{key}", val)
end
end
end
Slide 80
Slide 80 text
class Project
def set_or_return(key, val)
if val.equal?(NULL)
instance_variable_get(:"@#{key}")
else
raise Error unless val.is_a?(String)
instance_variable_set(:"@#{key}", val)
end
end
end
Slide 81
Slide 81 text
RUBY
name Object.new
Slide 82
Slide 82 text
RUBY
name Object.new
Error!
Slide 83
Slide 83 text
RUBY
@name = Object.new
self.name
Slide 84
Slide 84 text
RUBY
self.name
#=> #
@name = Object.new
Slide 85
Slide 85 text
CLASS_EVAL
BIND #4
Slide 86
Slide 86 text
CAN PERMANENTLY
CHANGE CLASS
BEHAVIOR
Slide 87
Slide 87 text
RUBY
self
.class
.instance_eval do
def new_method
puts "hello"
end
end
CLASS
Slide 88
Slide 88 text
RUBY
self
.class
.class_eval do
def sanitize(*)
nil
end
end
self.name
Slide 89
Slide 89 text
RUBY
self
.class
.class_eval do
def sanitize(*)
nil
end
end
self.name
#=> nil
Slide 90
Slide 90 text
FOR ALL FUTURE
INSTANCES
Slide 91
Slide 91 text
Project.load("/path/to/file")
Slide 92
Slide 92 text
No content
Slide 93
Slide 93 text
Project.load("/insecure_file")
Slide 94
Slide 94 text
INTRODUCING THE
CLEANROOM
Slide 95
Slide 95 text
NON-CLEANROOM
Slide 96
Slide 96 text
>
RUBY
NON-CLEANROOM
Slide 97
Slide 97 text
>
RUBY CLASS
NON-CLEANROOM
Slide 98
Slide 98 text
INSTANCE
NON-CLEANROOM
>
RUBY
Slide 99
Slide 99 text
INSTANCE
NON-CLEANROOM
>
RUBY
Slide 100
Slide 100 text
INSTANCE
NON-CLEANROOM
>
RUBY
NO FILTER
Slide 101
Slide 101 text
INSTANCE
NON-CLEANROOM
>
RUBY
NO FILTER
NO GUARDS
Slide 102
Slide 102 text
CLEANROOM
Slide 103
Slide 103 text
>
RUBY
CLEANROOM
Slide 104
Slide 104 text
CLASS
>
RUBY
CLEANROOM
Slide 105
Slide 105 text
CLASS
>
RUBY
CLEANROOM
INSTANCE
Slide 106
Slide 106 text
CLASS
>
RUBY
CLEANROOM
INSTANCE
EXPOSED METHODS
Slide 107
Slide 107 text
CLASS
>
RUBY
CLEANROOM
INSTANCE
INSTANCE
EXPOSED METHODS
Slide 108
Slide 108 text
CLASS
>
RUBY
CLEANROOM
INSTANCE
INSTANCE
EXPOSED METHODS
(DYNAMIC)
Slide 109
Slide 109 text
CLASS
>
RUBY
CLEANROOM
INSTANCE
INSTANCE
EXPOSED METHODS
(DYNAMIC)
instance_eval
class Project
def name(val = NULL)
set_or_return(:name, val)
end
end
NON-CLEANROOM
Slide 116
Slide 116 text
class Project
def name(val = NULL)
set_or_return(:name, val)
end
end
CLEANROOM
Slide 117
Slide 117 text
class Project
include Cleanroom
def name(val = NULL)
set_or_return(:name, val)
end
end
CLEANROOM
Slide 118
Slide 118 text
class Project
include Cleanroom
def name(val = NULL)
set_or_return(:name, val)
end
expose :name
end
CLEANROOM
Slide 119
Slide 119 text
CLEANROOM
THAT'S IT!
Slide 120
Slide 120 text
CLEANROOM
class Project
def self.load(path)
contents = IO.read(path)
filename = File.basename(path)
new.tap do |i|
i.instance_eval(contents, filename, 1)
end
end
end
Slide 121
Slide 121 text
CLEANROOM
class
contents = IO.read(path)
filename = File.basename(path)
new.tap
i.instance_eval(contents, filename, 1)
end