brakeman.rb 5.9 KB
Newer Older
J
Justin Collins 已提交
1
require 'rubygems'
2 3
require 'yaml'
require 'set'
4 5

module Brakeman
J
Justin Collins 已提交
6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35

  #Run Brakeman scan. Returns Tracker object.
  #
  #Options:
  #
  #  * :app_path - path to root of Rails app (required)
  #  * :assume_all_routes - assume all methods are routes (default: false)
  #  * :check_arguments - check arguments of methods (default: true)
  #  * :collapse_mass_assignment - report unprotected models in single warning (default: true)
  #  * :combine_locations - combine warning locations (default: true)
  #  * :config_file - configuration file
  #  * :create_config - output configuration file
  #  * :escape_html - escape HTML by default (automatic)
  #  * :exit_on_warn - return error exit code on warnings (default: false)
  #  * :html_style - path to CSS file
  #  * :ignore_model_output - consider models safe (default: false)
  #  * :list_checks - list all checks (does not run scan)
  #  * :message_limit - limit length of messages
  #  * :min_confidence - minimum confidence (0-2, 0 is highest)
  #  * :output_file - file for output
  #  * :output_format - format for output (:to_s, :to_tabs, :to_csv, :to_html)
  #  * :parallel_checks - run checks in parallel (default: true)
  #  * :quiet - suppress most messages (default: false)
  #  * :rails3 - force Rails 3 mode (automatic)
  #  * :report_routes - show found routes on controllers (default: false)
  #  * :run_checks - array of checks to run (run all if not specified)
  #  * :safe_methods - array of methods to consider safe
  #  * :skip_libs - do not process lib/ directory (default: false)
  #  * :skip_checks - checks not to run (run all if not specified)
  #
36 37 38 39 40 41 42 43 44 45 46
  def self.run options
    if options[:list_checks]
      list_checks
      exit
    end

    if options[:create_config]
      dump_config options
      exit
    end

47 48 49 50
    if options[:quiet]
      $VERBOSE = nil
    end

51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117
    scan set_options(options)
  end

  private

  def self.set_options options
    options = load_options(options[:config_file]).merge! options
    options = get_defaults.merge! options
    options[:output_format] = get_output_format options

    #Check application path
    unless options[:app_path]
      if ARGV[-1].nil?
        options[:app_path] = File.expand_path "."
      else
        options[:app_path] = File.expand_path ARGV[-1]
      end
    end

    app_path = options[:app_path]

    abort("Please supply the path to a Rails application.") unless app_path and File.exist? app_path + "/app"

    if File.exist? app_path + "/script/rails"
      options[:rails3] = true
      warn "[Notice] Detected Rails 3 application. Enabling experimental Rails 3 support." 
    end

    options
  end

  def self.load_options config_file
    config_file ||= ""

    #Load configuation file
    [File.expand_path(config_file),
      File.expand_path("./config.yaml"),
      File.expand_path("~/.brakeman/config.yaml"),
      File.expand_path("/etc/brakeman/config.yaml"),
      "#{File.expand_path(File.dirname(__FILE__))}/../lib/config.yaml"].each do |f|

      if File.exist? f and not File.directory? f
        warn "[Notice] Using configuration in #{f}" unless options[:quiet]
        options = YAML.load_file f
        options.each do |k,v|
          if v.is_a? Array
            options[k] = Set.new v
          end
        end

        return options
      end
      end

    return {}
  end

  def self.get_defaults
    { :skip_checks => Set.new, 
      :check_arguments => true, 
      :safe_methods => Set.new,
      :min_confidence => 2,
      :combine_locations => true,
      :collapse_mass_assignment => true,
      :ignore_redirect_to_model => true,
      :ignore_model_output => false,
      :message_limit => 100,
118
      :parallel_checks => true,
J
Justin Collins 已提交
119
      :html_style => "#{File.expand_path(File.dirname(__FILE__))}/brakeman/format/style.css" 
120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154
    }
  end

  def self.get_output_format options
    #Set output format
    if options[:output_format]
      case options[:output_format]
      when :html, :to_html
        :to_html
      when :csv, :to_csv
        :to_csv
      when :pdf, :to_pdf
        :to_pdf
      when :tabs, :to_tabs
        :to_tabs
      else
        :to_s
      end
    else
      case options[:output_file]
      when /\.html$/i
        :to_html
      when /\.csv$/i
        :to_csv
      when /\.pdf$/i
        :to_pdf
      when /\.tabs$/i
        :to_tabs
      else
        :to_s
      end
    end
  end

  def self.list_checks
J
Justin Collins 已提交
155
    require 'brakeman/scanner'
156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191
    $stderr.puts "Available Checks:"
    $stderr.puts "-" * 30
    $stderr.puts Checks.checks.map { |c| c.to_s }.sort.join "\n"
  end

  def self.dump_config options
    if options[:create_config].is_a? String
      file = options[:create_config]
    else
      file = nil
    end

    options.delete :create_config

    options.each do |k,v|
      if v.is_a? Set
        options[k] = v.to_a
      end
    end

    if file
      File.open file, "w" do |f|
        YAML.dump options, f
      end
      puts "Output configuration to #{file}"
    else
      puts YAML.dump(options)
    end
    exit
  end

  def self.scan options
    #Load scanner
    warn "Loading scanner..."

    begin
J
Justin Collins 已提交
192
      require 'brakeman/scanner'
193 194 195 196 197
    rescue LoadError
      abort "Cannot find lib/ directory."
    end

    #Start scanning
198
    scanner = Scanner.new options
199 200 201 202 203 204 205 206 207 208

    warn "[Notice] Using Ruby #{RUBY_VERSION}. Please make sure this matches the one used to run your Rails application."

    warn "Processing application in #{options[:app_path]}"
    tracker = scanner.process

    warn "Running checks..."
    tracker.run_checks

    warn "Generating report..."
209 210 211
    if options[:output_file]
      File.open options[:output_file], "w" do |f|
        f.puts tracker.report.send(options[:output_format])
212
      end
213
      warn "Report saved in '#{options[:output_file]}'"
214
    else
215
      puts tracker.report.send(options[:output_format])
216
    end
217 218

    if options[:exit_on_warn]
219
      tracker.checks.all_warnings.each do |warning|
220 221 222 223 224 225
        next if warning.confidence > options[:min_confidence]
        return false
      end
    end
    return true

226 227
  end
end