2017-05-10 05:24:43 +01:00
|
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
// you may not use this file except in compliance with the License.
|
|
|
|
// You may obtain a copy of the License at
|
|
|
|
//
|
|
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
//
|
|
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
// See the License for the specific language governing permissions and
|
|
|
|
// limitations under the License.
|
|
|
|
|
2018-07-19 17:42:25 +01:00
|
|
|
package gosec
|
2017-05-10 05:24:43 +01:00
|
|
|
|
|
|
|
import (
|
|
|
|
"go/ast"
|
|
|
|
"reflect"
|
2023-02-15 19:44:13 +00:00
|
|
|
|
|
|
|
"github.com/securego/gosec/v2/issue"
|
2017-05-10 05:24:43 +01:00
|
|
|
)
|
|
|
|
|
2018-07-19 17:42:25 +01:00
|
|
|
// The Rule interface used by all rules supported by gosec.
|
2017-05-10 05:24:43 +01:00
|
|
|
type Rule interface {
|
2017-10-05 22:32:03 +01:00
|
|
|
ID() string
|
2023-02-15 19:44:13 +00:00
|
|
|
Match(ast.Node, *Context) (*issue.Issue, error)
|
2017-05-10 05:24:43 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// RuleBuilder is used to register a rule definition with the analyzer
|
2017-10-05 22:32:03 +01:00
|
|
|
type RuleBuilder func(id string, c Config) (Rule, []ast.Node)
|
2017-05-10 05:24:43 +01:00
|
|
|
|
2021-12-09 10:53:36 +00:00
|
|
|
// A RuleSet contains a mapping of lists of rules to the type of AST node they
|
|
|
|
// should be run on and a mapping of rule ID's to whether the rule are
|
|
|
|
// suppressed.
|
2018-10-11 13:45:31 +01:00
|
|
|
// The analyzer will only invoke rules contained in the list associated with the
|
2017-05-10 05:24:43 +01:00
|
|
|
// type of AST node it is currently visiting.
|
2021-12-09 10:53:36 +00:00
|
|
|
type RuleSet struct {
|
|
|
|
Rules map[reflect.Type][]Rule
|
|
|
|
RuleSuppressedMap map[string]bool
|
|
|
|
}
|
2017-05-10 05:24:43 +01:00
|
|
|
|
2017-12-13 07:39:00 +00:00
|
|
|
// NewRuleSet constructs a new RuleSet
|
2017-05-10 05:24:43 +01:00
|
|
|
func NewRuleSet() RuleSet {
|
2021-12-09 10:53:36 +00:00
|
|
|
return RuleSet{make(map[reflect.Type][]Rule), make(map[string]bool)}
|
2017-05-10 05:24:43 +01:00
|
|
|
}
|
|
|
|
|
2023-05-26 16:03:54 +01:00
|
|
|
// Register adds a trigger for the supplied rule for the
|
2017-05-10 05:24:43 +01:00
|
|
|
// specified ast nodes.
|
2021-12-09 10:53:36 +00:00
|
|
|
func (r RuleSet) Register(rule Rule, isSuppressed bool, nodes ...ast.Node) {
|
2017-05-10 05:24:43 +01:00
|
|
|
for _, n := range nodes {
|
|
|
|
t := reflect.TypeOf(n)
|
2021-12-09 10:53:36 +00:00
|
|
|
if rules, ok := r.Rules[t]; ok {
|
|
|
|
r.Rules[t] = append(rules, rule)
|
2017-05-10 05:24:43 +01:00
|
|
|
} else {
|
2021-12-09 10:53:36 +00:00
|
|
|
r.Rules[t] = []Rule{rule}
|
2017-05-10 05:24:43 +01:00
|
|
|
}
|
|
|
|
}
|
2021-12-09 10:53:36 +00:00
|
|
|
r.RuleSuppressedMap[rule.ID()] = isSuppressed
|
2017-05-10 05:24:43 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// RegisteredFor will return all rules that are registered for a
|
|
|
|
// specified ast node.
|
|
|
|
func (r RuleSet) RegisteredFor(n ast.Node) []Rule {
|
2021-12-09 10:53:36 +00:00
|
|
|
if rules, found := r.Rules[reflect.TypeOf(n)]; found {
|
2017-05-10 05:24:43 +01:00
|
|
|
return rules
|
|
|
|
}
|
|
|
|
return []Rule{}
|
|
|
|
}
|
2021-12-09 10:53:36 +00:00
|
|
|
|
|
|
|
// IsRuleSuppressed will return whether the rule is suppressed.
|
|
|
|
func (r RuleSet) IsRuleSuppressed(ruleID string) bool {
|
|
|
|
return r.RuleSuppressedMap[ruleID]
|
|
|
|
}
|