output_processor.rb 4.6 KB
Newer Older
J
Justin 已提交
1
require 'ruby2ruby'
J
Justin Collins 已提交
2
require 'brakeman/util'
J
Justin 已提交
3 4 5 6 7

#Produces formatted output strings from Sexps.
#Recommended usage is
#
#  OutputProcessor.new.format(Sexp.new(:str, "hello"))
J
Justin Collins 已提交
8 9
class Brakeman::OutputProcessor < Ruby2Ruby
  include Brakeman::Util
J
Justin 已提交
10 11 12

  #Copies +exp+ and then formats it.
  def format exp
13
    process(exp.deep_clone) || "[Format Error]"
J
Justin 已提交
14 15 16 17 18 19 20
  end

  alias process_safely format

  def process exp
    begin
      super exp if sexp? exp and not exp.empty?
21
    rescue => e
22
      Brakeman.debug "While formatting #{exp}: #{e}\n#{e.backtrace.join("\n")}"
J
Justin 已提交
23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100
    end
  end

  def process_lvar exp
    out = "(local #{exp[0]})"
    exp.clear
    out
  end

  def process_ignore exp
    exp.clear
    "[ignored]"
  end

  def process_params exp
    exp.clear
    "params"
  end

  def process_session exp
    exp.clear
    "session"
  end

  def process_cookies exp
    exp.clear
    "cookies"
  end

  def process_string_interp exp
    out = '"'
    exp.each do |e|
      if e.is_a? String
        out << e
      else
        res = process e
        out << res unless res == "" 
      end
    end
    out << '"'
    exp.clear
    out
  end

  def process_string_eval exp
    out = "\#{#{process(exp[0])}}"
    exp.clear
    out
  end

  def process_dxstr exp
    out = "`"
    out << exp.map! do |e|
      if e.is_a? String
        e
      elsif string? e
        e[1]
      else
        process e
      end
    end.join
    exp.clear
    out << "`"
  end

  def process_rlist exp
    out = exp.map do |e|
      res = process e
      if res == ""
        nil
      else
        res
      end
    end.compact.join("\n")
    exp.clear
    out
  end

101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123
  def process_defn exp
    # Copied from Ruby2Ruby except without the whole
    # "convert methods to attr_*" stuff
    name = exp.shift
    args = process exp.shift
    args = "" if args == "()"

    exp.shift if exp == s(s(:nil)) # empty it out of a default nil expression

    body = []
    until exp.empty? do
      body << indent(process(exp.shift))
    end

    body << indent("# do nothing") if body.empty?

    body = body.join("\n")

    return "def #{name}#{args}\n#{body}\nend".gsub(/\n\s*\n+/, "\n")
  end

  alias process_methdef process_defn

J
Justin 已提交
124 125
  def process_call_with_block exp
    call = process exp[0]
126
    block = process_rlist exp[2..-1]
J
Justin 已提交
127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147
    out = "#{call} do\n #{block}\n end"
    exp.clear
    out
  end

  def process_output exp
    out = if exp[0].node_type == :str
            ""
          else
            res = process exp[0]

            if res == ""
              ""
            else
              "[Output] #{res}"
            end
          end
    exp.clear
    out
  end

148
  def process_escaped_output exp
149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164
    out = if exp[0].node_type == :str
            ""
          else
            res = process exp[0]

            if res == ""
              ""
            else
              "[Escaped Output] #{res}"
            end
          end
    exp.clear
    out
  end


J
Justin 已提交
165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197
  def process_format exp
    out = if exp[0].node_type == :str or exp[0].node_type == :ignore
            ""
          else
            res = process exp[0]

            if res == ""
              ""
            else
              "[Format] #{res}"
            end
          end
    exp.clear
    out
  end

  def process_format_escaped exp
    out = if exp[0].node_type == :str or exp[0].node_type == :ignore
            ""
          else
            res = process exp[0]

            if res == ""
              ""
            else
              "[Escaped] #{res}"
            end
          end
    exp.clear
    out
  end

  def process_const exp
J
Justin Collins 已提交
198
    if exp[0] == Brakeman::Tracker::UNKNOWN_MODEL
J
Justin 已提交
199 200 201
      exp.clear
      "(Unresolved Model)"
    else
J
Justin Collins 已提交
202 203 204
      out = exp[0].to_s
      exp.clear
      out
J
Justin 已提交
205 206 207 208 209 210 211 212 213 214
    end
  end

  def process_render exp
    exp[1] = process exp[1] if sexp? exp[1]
    exp[2] = process exp[2] if sexp? exp[2]
    out = "render(#{exp[0]} => #{exp[1]}, #{exp[2]})"
    exp.clear
    out
  end
215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243

  #This is copied from Ruby2Ruby, except the :string_eval type has been added
  def util_dthing(type, exp)
    s = []

    # first item in sexp is a string literal
    s << dthing_escape(type, exp.shift)

    until exp.empty?
      pt = exp.shift
      case pt
      when Sexp then
        case pt.first
        when :str then
          s << dthing_escape(type, pt.last)
        when :evstr, :string_eval then
          s << '#{' << process(pt) << '}' # do not use interpolation here
        else
          raise "unknown type: #{pt.inspect}"
        end
      else
        # HACK: raise "huh?: #{pt.inspect}" -- hitting # constants in regexps
        # do nothing for now
      end
    end

    s.join
  end

J
Justin 已提交
244
end