Skip to content

fix: allow safe builtins in when: fault conditions - #20

Merged
MarouaBoud merged 1 commit into
mainfrom
fix/when-safe-builtins
Sep 4, 2026
Merged

MarouaBoud merged 1 commit into
mainfrom
fix/when-safe-builtins

Conversation

@MarouaBoud

Copy link
Copy Markdown
Member

A when: condition using len() (e.g. len(params.text) > 4000) silently never fired: the evaluator stripped all builtins, so len raised NameError, which eval_condition swallows to False — quietly disabling the fault. Now a small allowlist (len/min/max/abs/round/sum/int/float/str/bool/any/all) is available; unsafe access (imports, open, attribute gadgets) still fails closed.

Found while authoring the community slack mock (msg_too_long when len(text) > 4000). Unreleased; rides the next tag.

@MarouaBoud
MarouaBoud merged commit 8689114 into main Sep 4, 2026
@MarouaBoud MarouaBoud mentioned this pull request Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant