Class: Brakeman::CheckRender

Inherits:
BaseCheck show all
Defined in:
lib/brakeman/checks/check_render.rb

Overview

Check calls to render() for dangerous values

Constant Summary

Constants inherited from BaseCheck

BaseCheck::CONFIDENCE

Constants included from Util

Util::ALL_PARAMETERS, Util::COOKIES, Util::COOKIES_SEXP, Util::PARAMETERS, Util::PARAMS_SEXP, Util::PATH_PARAMETERS, Util::QUERY_PARAMETERS, Util::REQUEST_ENV, Util::REQUEST_PARAMETERS, Util::REQUEST_PARAMS, Util::SESSION, Util::SESSION_SEXP

Constants inherited from SexpProcessor

SexpProcessor::VERSION

Instance Attribute Summary

Attributes inherited from BaseCheck

#tracker, #warnings

Attributes inherited from SexpProcessor

#context, #env, #expected

Instance Method Summary collapse

Methods inherited from BaseCheck

#add_result, inherited, #initialize, #process_call, #process_cookies, #process_default, #process_dstr, #process_if, #process_params

Methods included from Util

#array?, #block?, #call?, #camelize, #class_name, #contains_class?, #context_for, #cookies?, #false?, #file_by_name, #file_for, #github_url, #hash?, #hash_access, #hash_insert, #hash_iterate, #integer?, #make_call, #node_type?, #number?, #params?, #pluralize, #rails_version, #regexp?, #relative_path, #request_env?, #request_value?, #result?, #set_env_defaults, #sexp?, #string?, #string_interp?, #symbol?, #table_to_csv, #template_path_to_name, #true?, #truncate_table, #underscore

Methods included from ProcessorHelper

#process_all, #process_all!, #process_call_args, #process_call_defn?, #process_class, #process_module

Methods inherited from SexpProcessor

#in_context, #initialize, #process, processors, #scope

Constructor Details

This class inherits a constructor from Brakeman::BaseCheck

Instance Method Details

#check_for_dynamic_path(result) ⇒ Object

Check if path to action or file is determined dynamically



31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
# File 'lib/brakeman/checks/check_render.rb', line 31

def check_for_dynamic_path result
  view = result[:call][2]

  if sexp? view and not duplicate? result
    add_result result


    if input = has_immediate_user_input?(view)
      if string_interp? view
        confidence = CONFIDENCE[:med]
      else
        confidence = CONFIDENCE[:high]
      end
    elsif input = include_user_input?(view)
      confidence = CONFIDENCE[:low]
    else
      return
    end

    return if input.type == :model #skip models

    message = "Render path contains #{friendly_type_of input}"

    warn :result => result,
      :warning_type => "Dynamic Render Path",
      :warning_code => :dynamic_render_path,
      :message => message,
      :user_input => input,
      :confidence => confidence
  end
end

#process_render_result(result) ⇒ Object



15
16
17
18
19
20
21
22
23
24
25
26
27
28
# File 'lib/brakeman/checks/check_render.rb', line 15

def process_render_result result
  return unless node_type? result[:call], :render

  case result[:call].render_type
  when :partial, :template, :action, :file
    check_for_dynamic_path result
  when :inline
  when :js
  when :json
  when :text
  when :update
  when :xml
  end
end

#run_checkObject



9
10
11
12
13
# File 'lib/brakeman/checks/check_render.rb', line 9

def run_check
  tracker.find_call(:target => nil, :method => :render).each do |result|
    process_render_result result
  end
end