> +1 on pure Python configs.  They aren't much more complicated but are
> way more flexible.  We just have to be careful that we don't start
> seeing listcomps in them ;-)

I love having configs that are pure Python as they make life
tremendously simple in many ways... But they do open up some
interesting security issues that will mean you want to be slightly
more paranoid than usual (depending on implementation of course). 
Anything that gets imported or execed in order to get loaded into your
app has the possibility of executing code that might make you very
unhappy, if, say, a bad guy dropped a new config file into place while
you weren't looking.

Of course, if bad guys are on your box, you probably have multiple
other problems to worry about. ;-)


--
Mike Pirnat
[EMAIL PROTECTED]

Reply via email to