rubyonrailsin

A Ruby and Rails talk

Monday, March 29, 2010


[Rails] Re: Can the .read method execute any files?

by rubyonrailsin 0 comments

Tag


Share this post:
Design Float
StumbleUpon
Reddit

Thank you Frederick.
That's what I was thinking (hoping).

@pepe
I do check it's MIME type before uploading, but the file is actually
never saved. So as long as .read, or parsing, won't trigger the exe/
ruby/php script, then I think I'm ok.

On Mar 29, 3:56 am, Frederick Cheung <frederick.che...@gmail.com>
wrote:
> On Mar 29, 8:17 am, GoodGets <goodg...@gmail.com> wrote:
>
> > I need to read (and parse) a user uploaded file.  I check it's MIME
> > types, as well to see if includes proper headers by reading the file,
> > but I was wondering can something like params[:uploaded_file].read
> > trigger any EXEs or ruby/php/etc files?  Or, is "read" good to go?
>
> read does just return the bytes in the IO stream to you - it doesn't
> do anything with them.
>
> Fred

--
You received this message because you are subscribed to the Google Groups "Ruby on Rails: Talk" group.
To post to this group, send email to rubyonrails-talk@googlegroups.com.
To unsubscribe from this group, send email to rubyonrails-talk+unsubscribe@googlegroups.com.
For more options, visit this group at http://groups.google.com/group/rubyonrails-talk?hl=en.

No comments:

Post a Comment

Subscribe feeds via e-mail

Blog Archive