Class: Brakeman::TemplateProcessor

Inherits:
BaseProcessor
  • Object
show all
Defined in:
lib/brakeman/processors/template_processor.rb

Overview

Base Processor for templates/views

Instance Method Summary collapse

Constructor Details

#initialize(tracker, template_name, called_from = nil, current_file = nil) ⇒ TemplateProcessor

Initializes template information.



8
9
10
11
12
13
14
15
16
17
18
19
20
# File 'lib/brakeman/processors/template_processor.rb', line 8

def initialize tracker, template_name, called_from = nil, current_file = nil
  super(tracker)
  @current_template = Brakeman::Template.new template_name, called_from, current_file, tracker
  @current_file = @current_template.file

  if called_from
    template_name = (template_name.to_s + "." + called_from.to_s).to_sym
  end

  tracker.templates[template_name] = @current_template

  @inside_concat = false
end

Instance Method Details

#add_escaped_output(output) ⇒ Object



75
76
77
# File 'lib/brakeman/processors/template_processor.rb', line 75

def add_escaped_output output
  add_output output, :escaped_output
end

#add_output(output, type = :output) ⇒ Object



79
80
81
82
83
84
85
86
87
88
# File 'lib/brakeman/processors/template_processor.rb', line 79

def add_output output, type = :output
  if node_type? output, :or
    Sexp.new(:or, add_output(output.lhs, type), add_output(output.rhs, type)).line(output.line)
  else
    s = Sexp.new(type, output)
    s.line(output.line)
    @current_template.add_output s
    s
  end
end

#normalize_output(arg) ⇒ Object

Pull out actual output value from template



57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
# File 'lib/brakeman/processors/template_processor.rb', line 57

def normalize_output arg
  if call? arg and [:to_s, :html_safe!, :freeze].include? arg.method
    normalize_output(arg.target) # sometimes it's foo.to_s.to_s
  elsif node_type? arg, :if
    branches = [arg.then_clause, arg.else_clause].compact

    if branches.empty?
      s(:nil).line(arg.line)
    elsif branches.length == 2
      Sexp.new(:or, *branches).line(arg.line)
    else
      branches.first
    end
  else
    arg
  end
end

#process(exp) ⇒ Object

Process the template Sexp.



23
24
25
26
27
28
29
30
31
# File 'lib/brakeman/processors/template_processor.rb', line 23

def process exp
  begin
    super
  rescue => e
    except = e.exception("Error when processing #{@current_template.name}: #{e.message}")
    except.set_backtrace(e.backtrace)
    raise except
  end
end

#process_escaped_output(exp) ⇒ Object



52
53
54
# File 'lib/brakeman/processors/template_processor.rb', line 52

def process_escaped_output exp
  process_output exp
end

#process_lasgn(exp) ⇒ Object

Ignore initial variable assignment



34
35
36
37
38
39
40
41
42
43
# File 'lib/brakeman/processors/template_processor.rb', line 34

def process_lasgn exp
  if exp.lhs == :_erbout and exp.rhs.node_type == :str  #ignore
    ignore
  elsif exp.lhs == :_buf and exp.rhs.node_type == :str
    ignore
  else
    exp.rhs = process exp.rhs
    exp
  end
end

#process_output(exp) ⇒ Object

Adds output to the list of outputs.



46
47
48
49
50
# File 'lib/brakeman/processors/template_processor.rb', line 46

def process_output exp
  exp.value = process exp.value
  @current_template.add_output exp unless exp.original_line
  exp
end