views:

38

answers:

1

Are SAFE levels supported in JRuby? If not, is there other ways of safely running user supplied code in server?

+1  A: 
Jörg W Mittag
$SAFE and the JVM security are completely different concepts. $SAFE is all about stopping taint/sink based attacks by looking at where user supplied data is coming form. A JVM is a padded room, a room where you can still get pwn3d with SQL Injection.
Rook