logoalt Hacker News

minus7today at 4:06 PM3 repliesview on HN

The `eval` alone should be enough of a red flag


Replies

jeltztoday at 5:27 PM

Yeah, I would have loved to see an example where it was not obvious that there is an exploit. Where it would be possible for a reviewer to actually miss it.

godelskitoday at 7:08 PM

I'm not a JS person, but taking the line at face value shouldn't it to nothing? Which, if I understand correctly, should never be merged. Why would you merge no-ops?

kordlessagaintoday at 4:18 PM

No it’s not.

show 5 replies