lua-users home
lua-l archive

[Date Prev][Date Next][Thread Prev][Thread Next] [Date Index] [Thread Index]


On 04/10/11 22:50, Petite Abeille wrote:
[...]
> The content of the string could be anything. I would rather not execute it. Just unquote it.

The content of the string is guaranteed to be a *string* --- that's part
of what %q is for. Commands can't escape from %q, so you don't have to
worry about arbitrary code execution.

-- 
┌─── dg@cowlark.com ───── http://www.cowlark.com ─────
│
│ "Under communism, man exploits man. Under capitalism, it's just the
│ opposite." --- John Kenneth Galbrith

Attachment: signature.asc
Description: OpenPGP digital signature