W3C home > Mailing lists > Public > public-web-security@w3.org > February 2011

defineProperty is a blacklist

From: gaz Heyes <gazheyes@gmail.com>
Date: Sun, 13 Feb 2011 20:57:41 +0000
Message-ID: <AANLkTinCor8tz79zA9FBn2Ht_yyHej59KjWURW9x4dTr@mail.gmail.com>
To: public-web-security@w3.org
Hey all

I'd like to emphasize my point made at the OWASP summit, defineProperty
rocks and the ES5 specification was created by the hands of js gods but for
all it's brilliance defineProperty is still a blacklist. We need the ability
to somehow create a whitelist of allowed properties and the ability to apply
a property descriptor to any properties that do not conform to this
whitelist.

Cheers

Gareth
Received on Sunday, 13 February 2011 20:58:13 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Sunday, 13 February 2011 20:58:14 GMT