this post was submitted on 21 Mar 2025
658 points (99.5% liked)

Programmer Humor

21829 readers
1793 users here now

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

founded 2 years ago
MODERATORS
 

Original post: hachyderm.io (Mastodon)

you are viewing a single comment's thread
view the rest of the comments
[โ€“] pHr34kY@lemmy.world 6 points 1 day ago (1 children)

The backend and frontend on the product I work on are like this.

As long as you remember that booleans are not strings and should always be parsed if they are, this won't be a problem.

I am yet to see a boolean.parse() implementation in the wild that is case sensitive.

[โ€“] computergeek125@lemmy.world 2 points 18 hours ago

The could be using .js and .py files directly as config files and letting the language interpreter so the heavy lifting. Just like ye olde config.php.

And yes this absolutely will allow code injection by a config admin.