Implement a Safe Expression Evaluator
Problem
Implement a small, safe evaluator for user-provided expressions — arithmetic and variable interpolation like {{ user.name }} — WITHOUT using the host language's eval or any mechanism that could run arbitrary code.
Requirements
- Evaluate expressions against a provided scope object, e.g.
eval("{{a}} + {{b}}", {a:2, b:3})→ 5. - Support variable references (including dotted paths), arithmetic operators, and precedence / parentheses.
- Never execute arbitrary code; reject or safely handle malformed input.
Areas to design
- The tokenizer → parser → evaluator pipeline (or a shunting-yard evaluator).
- The scope-resolution model and how dotted paths are looked up.
- Sandboxing: which operations and property accesses are forbidden (e.g. prototype access), and how errors surface.
- Edge cases: undefined variables, division by zero, unbalanced braces/parens, type mismatches.
added …