arc> (let (x . y) '(a b c) y)
(b c)Anyway, is it safe to assume that you're not going to try to get me arrested or anything?
Do you mean your username is actually descriptive? Since you are obviously a Lisp hacker, I'd be happy to have a truce. Can you send me an email?
You could go a step further and have a special ignore symbol, (for instance * ) like most pattern matching languages/libraries have with the property that it can appear multiple times:
arc> (let (x * y . *) '(a b c d e f) y)
c (let (x . _) '(a b c) x)
It sounds like you're treating list destructuring like CL's mvbind. While it's subjective of course, I'm more comfortable with the runtime doing what I mean when I control the number of values (modulo `(apply values ...)').I'm not comfortable with destructuring values "flexibly" when I don't control the data coming in.
"nil" could be used instead, since nil isn't allowed to be rebound.
(let (x . nil) '(a b c) x)
even works already, since (unless it's been changed in some newer version of Arc I haven't installed yet) Arc just silently ignores the let-ing of nil: (let nil t nil) ---> nilI'm imagining you'd have some kind of Field record type, with isDisplayable and isModifyable fields. Instead of destructuring as a list (or tuple), you would explicitly look for isDisplayable and isModifyable.
But, of course, you could still make the same mistake in a statically typed language if you chose not to set up the data structure this way.
I think that people used to dynamic programming languages would normally pick the list rather than the tuple simply because it at first appears easier. I think Dijkstra had something to say on that particular subject :)
Out of curiosity, why did you take the site down two times before applying the fix?
If I'm not mistaken, that had nothing to do with SQL injection. The fnid basically was the authenticator that allowed a person to edit a page, regardless of who was logged in.
What about other HN-powered Arc sites? Are they vulnerable as well? I won't name names, because I'm guessing they are indeed vulnerable.
Edit: Yes, they are.
Anyway your mention of fnid prompted me to learn a bit about arc and the arc web server which looks very interesting. Might have to play with it a bit.