How to configure sandbox security in in Rhino JavaScript engine

4.1k Views Asked by At

I want to interpret html pages scripts, but want to disable any posibility of harming my computer. Is there are any official tutorial or example how to configure such feature? (i dont find it in offcial site)

3

There are 3 best solutions below

0
On BEST ANSWER

I haven't seen any official example, but see this SO question and particularly this article on sandboxing in Rhino. The article gives a pretty good overview of the things you'll have to set up and guard against.

1
On

run an initial script like this:

java = undefined;
Packages = undefined;
org = undefined;
...

then it is sandboxed.

0
On

Beware reflection "out.println('outclass ' + out.getClass().forName('java.io.File'));"

There are many traps to this trade. Previous answer not good enough.