Class: Brakeman::Rails2XSSPluginErubis

Inherits:
Erubis::Eruby
  • Object
show all
Defined in:
lib/brakeman/parsers/rails2_xss_plugin_erubis.rb

Overview

This is from the rails_xss plugin for Rails 2

Constant Summary collapse

BLOCK_EXPR =
/\s+(do|\{)(\s*\|[^|]*\|)?\s*\Z/

Instance Method Summary collapse

Instance Method Details

#add_expr_escaped(src, code) ⇒ Object



39
40
41
# File 'lib/brakeman/parsers/rails2_xss_plugin_erubis.rb', line 39

def add_expr_escaped(src, code)
  src << '@output_buffer << ' << escaped_expr(code) << ';'
end

#add_expr_literal(src, code) ⇒ Object



31
32
33
34
35
36
37
# File 'lib/brakeman/parsers/rails2_xss_plugin_erubis.rb', line 31

def add_expr_literal(src, code)
  if code =~ BLOCK_EXPR
    src << "@output_buffer.safe_concat((" << $1 << ").to_s);"
  else
    src << '@output_buffer << ((' << code << ').to_s);'
  end
end

#add_postamble(src) ⇒ Object



43
44
45
# File 'lib/brakeman/parsers/rails2_xss_plugin_erubis.rb', line 43

def add_postamble(src)
  #src << '@output_buffer.to_s'
end

#add_preamble(src) ⇒ Object



3
4
5
# File 'lib/brakeman/parsers/rails2_xss_plugin_erubis.rb', line 3

def add_preamble(src)
  #src << "@output_buffer = ActiveSupport::SafeBuffer.new;"
end

#add_text(src, text) ⇒ Object

This is different from rails_xss - fixes some line number issues



8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
# File 'lib/brakeman/parsers/rails2_xss_plugin_erubis.rb', line 8

def add_text(src, text)
  if text == "\n"
    src << "\n"
  elsif text.include? "\n"
    lines = text.split("\n")
    if text.match(/\n\z/)
      lines.each do |line|
        src << "@output_buffer.safe_concat('" << escape_text(line) << "');\n"
      end
    else
      lines[0..-2].each do |line|
        src << "@output_buffer.safe_concat('" << escape_text(line) << "');\n"
      end

      src << "@output_buffer.safe_concat('" << escape_text(lines.last) << "');"
    end
  else
    src << "@output_buffer.safe_concat('" << escape_text(text) << "');"
  end
end