dongsu4345 2018-03-14 21:50
浏览 248

Eval()函数替代

I have a json file where i am rendering the template and have an object like

"templateLabelEval":"return $row->['document_code'];"

I am rendering the label by using

eval(templateLabelEval);

Is there any other alternative way where i could avoid using eval as it is considered to be a bad practice

  • 写回答

1条回答 默认 最新

  • dqyl2374 2018-03-14 21:53
    关注

    Given that the code string has a return statement, eval alone wouldn't work anyway, but you could use Function().

    var result = Function(data.templateLabelEval)();
    

    This has nearly all the same security concerns, but not so much the performance issues that eval has (or had). So of course, you should only execute code that is secure.

    To explain the code, passing the string to the Function constructor creates a new function object with that strings as its body. (I assume the function needs no parameters defined for now.) So the trailing () invokes the function immediately and the result is stored in result.

    You could store the function itself if you want, and then invoke it later as many times as you'd like.

    评论

报告相同问题?

悬赏问题

  • ¥15 华为ensp模拟器中S5700交换机在配置过程中老是反复重启
  • ¥15 java写代码遇到问题,求帮助
  • ¥15 uniapp uview http 如何实现统一的请求异常信息提示?
  • ¥15 有了解d3和topogram.js库的吗?有偿请教
  • ¥100 任意维数的K均值聚类
  • ¥15 stamps做sbas-insar,时序沉降图怎么画
  • ¥15 买了个传感器,根据商家发的代码和步骤使用但是代码报错了不会改,有没有人可以看看
  • ¥15 关于#Java#的问题,如何解决?
  • ¥15 加热介质是液体,换热器壳侧导热系数和总的导热系数怎么算
  • ¥100 嵌入式系统基于PIC16F882和热敏电阻的数字温度计