• Type: Improvement
    • Resolution: Unresolved
    • Priority: Major - P3
    • None
    • Affects Version/s: None
    • Component/s: None
    • DB Integration & Observability
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      We should add a new MessageHook like onUserJs which gets to inspect the javascript code each time we pass code provided from the user into the JS engine. This will give us the ability to detect and reject malicious JS.

      If the same code is passed to the engine multiple times in each request (eg if the engine is wiped, or there are multiple engines), it is sufficient to validate the JS once. However it is better to invoke the hook more often than needed, rather than missing some calls.

      If you grep the codebase for MessageHooks|on_reply_ready that should give you enough to go off of.

            Assignee:
            Unassigned
            Reporter:
            Mathias Stearn
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: