Class: Brakeman::Config

Inherits:
Object
  • Object
show all
Includes:
Util
Defined in:
lib/brakeman/tracker/config.rb

Constant Summary

Constants included from Util

Util::ALL_COOKIES, Util::ALL_PARAMETERS, Util::COOKIES, Util::COOKIES_SEXP, Util::DIR_CONST, Util::LITERALS, Util::PARAMETERS, Util::PARAMS_SEXP, Util::PATH_PARAMETERS, Util::QUERY_PARAMETERS, Util::REQUEST_COOKIES, Util::REQUEST_ENV, Util::REQUEST_PARAMETERS, Util::REQUEST_PARAMS, Util::REQUEST_REQUEST_PARAMETERS, Util::SAFE_LITERAL, Util::SESSION, Util::SESSION_SEXP, Util::SIMPLE_LITERALS

Instance Attribute Summary collapse

Instance Method Summary collapse

Methods included from Util

#all_literals?, #array?, #block?, #call?, #camelize, #class_name, #constant?, #contains_class?, #cookies?, #dir_glob?, #false?, #hash?, #hash_access, #hash_insert, #hash_iterate, #hash_values, #integer?, #kwsplat?, #literal?, #make_call, #node_type?, #number?, #params?, #pluralize, #recurse_check?, #regexp?, #remove_kwsplat, #request_env?, #request_value?, #result?, #safe_literal, #safe_literal?, #safe_literal_target?, #set_env_defaults, #sexp?, #simple_literal?, #string?, #string_interp?, #symbol?, #template_path_to_name, #true?, #underscore

Constructor Details

#initialize(tracker) ⇒ Config

Returns a new instance of Config.



10
11
12
13
14
15
16
17
18
19
# File 'lib/brakeman/tracker/config.rb', line 10

def initialize tracker
  @tracker = tracker
  @rails = {}
  @gems = {}
  @settings = {}
  @escape_html = nil
  @erubis = nil
  @ruby_version = nil
  @rails_version = nil
end

Instance Attribute Details

#erubis=(value) ⇒ Object (writeonly)

Sets the attribute erubis

Parameters:

  • value

    the value to set the attribute erubis to.



8
9
10
# File 'lib/brakeman/tracker/config.rb', line 8

def erubis=(value)
  @erubis = value
end

#escape_html=(value) ⇒ Object (writeonly)

Sets the attribute escape_html

Parameters:

  • value

    the value to set the attribute escape_html to.



8
9
10
# File 'lib/brakeman/tracker/config.rb', line 8

def escape_html=(value)
  @escape_html = value
end

#gemsObject (readonly)

Returns the value of attribute gems.



7
8
9
# File 'lib/brakeman/tracker/config.rb', line 7

def gems
  @gems
end

#railsObject (readonly)

Returns the value of attribute rails.



7
8
9
# File 'lib/brakeman/tracker/config.rb', line 7

def rails
  @rails
end

#ruby_versionObject (readonly)

Returns the value of attribute ruby_version.



7
8
9
# File 'lib/brakeman/tracker/config.rb', line 7

def ruby_version
  @ruby_version
end

#trackerObject (readonly)

Returns the value of attribute tracker.



7
8
9
# File 'lib/brakeman/tracker/config.rb', line 7

def tracker
  @tracker
end

Instance Method Details

#add_gem(name, version, file, line) ⇒ Object



60
61
62
63
64
65
66
67
# File 'lib/brakeman/tracker/config.rb', line 60

def add_gem name, version, file, line
  name = name.to_sym
  @gems[name] = {
    :version => version,
    :file => file,
    :line => line
  }
end

#default_protect_from_forgery?Boolean

Returns:

  • (Boolean)


21
22
23
24
25
26
27
28
29
30
31
# File 'lib/brakeman/tracker/config.rb', line 21

def default_protect_from_forgery?
  if version_between? "5.2.0.beta1", "9.9.9"
    if @rails.dig(:action_controller, :default_protect_from_forgery) == Sexp.new(:false)
      return false
    else
      return true
    end
  end

  false
end

#erubis?Boolean

Returns:

  • (Boolean)


33
34
35
# File 'lib/brakeman/tracker/config.rb', line 33

def erubis?
  @erubis
end

#escape_filter_interpolations?Boolean

Returns:

  • (Boolean)


46
47
48
49
50
# File 'lib/brakeman/tracker/config.rb', line 46

def escape_filter_interpolations?
  # TODO see if app is actually turning this off itself
  has_gem?(:haml) and
    version_between? "5.0.0", "5.99", gem_version(:haml)
end

#escape_html?Boolean

Returns:

  • (Boolean)


37
38
39
# File 'lib/brakeman/tracker/config.rb', line 37

def escape_html?
  @escape_html
end

#escape_html_entities_in_json?Boolean

Returns:

  • (Boolean)


41
42
43
44
# File 'lib/brakeman/tracker/config.rb', line 41

def escape_html_entities_in_json?
  #TODO add version-specific information here
  true? @rails.dig(:active_support, :escape_html_entities_in_json)
end

#extract_version(version) ⇒ Object



136
137
138
139
140
# File 'lib/brakeman/tracker/config.rb', line 136

def extract_version version
  return unless version.is_a? String

  version[/\d+\.\d+(\.\d+.*)?/]
end

#gem_version(name) ⇒ Object



56
57
58
# File 'lib/brakeman/tracker/config.rb', line 56

def gem_version name
  extract_version @gems.dig(name.to_sym, :version)
end

#get_gem(name) ⇒ Object



73
74
75
# File 'lib/brakeman/tracker/config.rb', line 73

def get_gem name
  @gems[name.to_sym]
end

#has_gem?(name) ⇒ Boolean

Returns:

  • (Boolean)


69
70
71
# File 'lib/brakeman/tracker/config.rb', line 69

def has_gem? name
  !!@gems[name.to_sym]
end

#load_rails_defaultsObject

Load defaults based on config.load_defaults value as documented here: guides.rubyonrails.org/configuring.html#results-of-config-load-defaults



190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
# File 'lib/brakeman/tracker/config.rb', line 190

def load_rails_defaults
  return unless number? tracker.config.rails[:load_defaults]

  version = tracker.config.rails[:load_defaults].value
  true_value = Sexp.new(:true)
  false_value = Sexp.new(:false)

  if version >= 5.0
    set_rails_config(true_value, :action_controller, :per_form_csrf_tokens)
    set_rails_config(true_value, :action_controller, :forgery_protection_origin_check)
    set_rails_config(true_value, :active_record, :belongs_to_required_by_default)
    # Note: this may need to be changed, because ssl_options is a Hash
    set_rails_config(true_value, :ssl_options, :hsts, :subdomains)
  end

  if version >= 5.1
    set_rails_config(false_value, :assets, :unknown_asset_fallback)
    set_rails_config(true_value, :action_view, :form_with_generates_remote_forms)
  end

  if version >= 5.2
    set_rails_config(true_value, :active_record, :cache_versioning)
    set_rails_config(true_value, :action_dispatch, :use_authenticated_cookie_encryption)
    set_rails_config(true_value, :active_support, :use_authenticated_message_encryption)
    set_rails_config(true_value, :active_support, :use_sha1_digests)
    set_rails_config(true_value, :action_controller, :default_protect_from_forgery)
    set_rails_config(true_value, :action_view, :form_with_generates_ids)
  end

  if version >= 6.0
    set_rails_config(Sexp.new(:lit, :zeitwerk), :autoloader)
    set_rails_config(false_value, :action_view, :default_enforce_utf8)
    set_rails_config(true_value, :action_dispatch, :use_cookies_with_metadata)
    set_rails_config(false_value, :action_dispatch, :return_only_media_type_on_content_type)
    set_rails_config(Sexp.new(:str, 'ActionMailer::MailDeliveryJob'), :action_mailer, :delivery_job)
    set_rails_config(true_value, :active_job, :return_false_on_aborted_enqueue)
    set_rails_config(Sexp.new(:lit, :active_storage_analysis), :active_storage, :queues, :analysis)
    set_rails_config(Sexp.new(:lit, :active_storage_purge), :active_storage, :queues, :purge)
    set_rails_config(true_value, :active_storage, :replace_on_assign_to_many)
    set_rails_config(true_value, :active_record, :collection_cache_versioning)
  end
end

#rails_versionObject



126
127
128
129
130
# File 'lib/brakeman/tracker/config.rb', line 126

def rails_version
  # This needs to be here because Util#rails_version calls Tracker::Config#rails_version
  # but Tracker::Config includes Util...
  @rails_version
end

#session_settingsObject



156
157
158
# File 'lib/brakeman/tracker/config.rb', line 156

def session_settings
  @rails.dig(:action_controller, :session)
end

#set_rails_config(value, *path) ⇒ Object

Set Rails config option value where path is an array of attributes, e.g.

:action_controller, :perform_caching

then this will set

rails[:action_controller][:perform_caching] = value


169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
# File 'lib/brakeman/tracker/config.rb', line 169

def set_rails_config value, *path
  config = self.rails

  path[0..-2].each do |o|
    config[o] ||= {}

    option = config[o]

    if not option.is_a? Hash
      Brakeman.debug "[Notice] Skipping config setting: #{path.map(&:to_s).join(".")}"
      return
    end

    config = option
  end

  config[path.last] = value
end

#set_rails_version(version = nil) ⇒ Object



77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
# File 'lib/brakeman/tracker/config.rb', line 77

def set_rails_version version = nil
  version = if version
              # Only used by Rails2ConfigProcessor right now
              extract_version(version)
            else
              gem_version(:rails) ||
                gem_version(:railties) ||
                gem_version(:activerecord)
            end

  if version
    @rails_version = version

    if tracker.options[:rails3].nil? and tracker.options[:rails4].nil?
      if @rails_version.start_with? "3"
        tracker.options[:rails3] = true
        Brakeman.notify "[Notice] Detected Rails 3 application"
      elsif @rails_version.start_with? "4"
        tracker.options[:rails3] = true
        tracker.options[:rails4] = true
        Brakeman.notify "[Notice] Detected Rails 4 application"
      elsif @rails_version.start_with? "5"
        tracker.options[:rails3] = true
        tracker.options[:rails4] = true
        tracker.options[:rails5] = true
        Brakeman.notify "[Notice] Detected Rails 5 application"
      elsif @rails_version.start_with? "6"
        tracker.options[:rails3] = true
        tracker.options[:rails4] = true
        tracker.options[:rails5] = true
        tracker.options[:rails6] = true
        Brakeman.notify "[Notice] Detected Rails 6 application"
      elsif @rails_version.start_with? "7"
        tracker.options[:rails3] = true
        tracker.options[:rails4] = true
        tracker.options[:rails5] = true
        tracker.options[:rails6] = true
        tracker.options[:rails7] = true
        Brakeman.notify "[Notice] Detected Rails 7 application"
      end
    end
  end

  if get_gem :rails_xss
    @escape_html = true
    Brakeman.notify "[Notice] Escaping HTML by default"
  end
end

#set_ruby_version(version) ⇒ Object



132
133
134
# File 'lib/brakeman/tracker/config.rb', line 132

def set_ruby_version version
  @ruby_version = extract_version(version)
end

#version_between?(low_version, high_version, current_version = nil) ⇒ Boolean

Returns true if low_version <= RAILS_VERSION <= high_version

If the Rails version is unknown, returns false.

Returns:

  • (Boolean)


145
146
147
148
149
150
151
152
153
154
# File 'lib/brakeman/tracker/config.rb', line 145

def version_between? low_version, high_version, current_version = nil
  current_version ||= rails_version
  return false unless current_version

  low = Gem::Version.new(low_version)
  high = Gem::Version.new(high_version)
  current = Gem::Version.new(current_version)

  current.between?(low, high)
end

#whitelist_attributes?Boolean

Returns:

  • (Boolean)


52
53
54
# File 'lib/brakeman/tracker/config.rb', line 52

def whitelist_attributes?
  @rails.dig(:active_record, :whitelist_attributes) == Sexp.new(:true)
end