class
Analyzer::CSharp::SignalR
- Analyzer::CSharp::SignalR
- Analyzer
- Reference
- Object
Overview
Surfaces ASP.NET Core SignalR real-time attack surface as ws://
endpoints. A SignalR Hub subclass exposes public methods the client
invokes over a long-lived connection; MapHub<T>("/path") mounts the
hub at a route. Each callable hub method becomes one endpoint
ws://<hub-route>/<method> (bare ws://<hub-route> when a hub has no
callable methods), method "SEND", protocol "ws" — so the existing
WebsocketTagger tags them. Method parameters (minus DI/service types)
become params (param_type "json").
Line-scan analyzer (C# house style; there is no C# engine). Hub classes
and their MapHub<T> mounts routinely live in different files
(ChatHub.cs vs Program.cs), so routes and hubs are collected across
every .cs file first, then joined.
Included Modules
Defined in:
analyzer/analyzers/csharp/signalr.crConstant Summary
-
CLASS_OPEN =
/\bclass\s+(\w+)(?:\s*<[^>]*>)?\s*(?::[^{]*)?/ -
Any
class Name ...opener — used to bound a hub body and to detect a custom-base hub whose name was mounted via MapHub. -
HUB_CLASS =
/\bclass\s+(\w+)(?:\s*<[^>]*>)?\s*:\s*(?:[\w.]+\.)?(?:Hub(?:\s*<[^>]*>)?|DynamicHub)\b/ -
A hub class: the base list's first entry (C# requires the base class first) is
Hub,Hub<T>orDynamicHub, optionally namespace- qualified. Custom base hubs (: ChatHubBase) are still caught when the class is named in aMapHub<T>mount (seehub_class?). -
MAP_HUB =
/\bMapHub\s*<\s*([\w.]+)\s*>\s*\(\s*@?"([^"]+)"/ -
app.MapHub<ChatHub>("/chatHub")/endpoints.MapHub<ChatHub>("/hub"). -
NON_EVENT_METHODS =
Set {"OnConnectedAsync", "OnDisconnectedAsync", "OnConnected", "OnDisconnected", "OnReconnected", "Dispose", "DisposeAsync"} -
Lifecycle / infrastructure methods that are never client-invocable events even when declared
public. -
PUBLIC_METHOD =
/^\s*public\s+((?:(?:static|async|virtual|override|sealed|new|unsafe)\s+)*)(?:[\w<>\[\],.?]+\s+)+(\w+)\s*\(/ -
A public instance method — a SignalR client-callable event.
overrideis excluded (lifecycle hooksOnConnectedAsync/OnDisconnectedAsync), as are constructors andDispose. Requires an opening paren so properties/fields are skipped.
Class Method Summary
Instance Method Summary
- #analyze
-
#tech : String
Instance-side view of the same declaration.
Class methods inherited from module Analyzer::CSharp::Common
aspnet_core_source?(content : String) : Bool
aspnet_core_source?,
aspnet_framework_source?(content : String) : Bool
aspnet_framework_source?,
carter_module_source?(content : String) : Bool
carter_module_source?,
csharp_service_type?(type_name : String) : Bool
csharp_service_type?,
csharp_test_path?(relative_path : String) : Bool
csharp_test_path?,
explicit_binding_name(param_def : String) : String | Nil
explicit_binding_name,
project_root_for(path : String, roots : Array(String)) : String | Nil
project_root_for,
project_roots(csproj_paths : Array(String)) : Array(String)
project_roots,
route_placeholder_name(raw : String) : String
route_placeholder_name
Instance methods inherited from class Analyzer
analyze
analyze,
base_path : String
base_path,
base_paths : Array(String)
base_paths,
base_relative_path(path : String) : String
base_relative_path,
callees_needed? : Bool
callees_needed?,
content_matches?(content : String, markers : Regex) : Bool
content_matches?,
http_header_name(name : String) : String | Nil
http_header_name,
line_number_for_index(content : String, char_index : Int32) : Int32
line_number_for_index,
logger : NoirLogger
logger,
parallel_analyze(files : Array(String), &block : String -> Nil)
parallel_analyze,
read_file_content(path : String) : String
read_file_content,
result : Array(Endpoint)
result,
tech : String
tech,
unique_params(params : Array(Param)) : Array(Param)
unique_params,
url : String
url,
web_root_path(path : String, markers : Array(String)) : String
web_root_path
Constructor methods inherited from class Analyzer
new(options : Hash(String, YAML::Any))
new
Macros inherited from class Analyzer
analyzer_for(tech)
analyzer_for
Instance methods inherited from module FileHelper
all_files : Array(String)
all_files,
get_files_by_basename(basename : String) : Array(String)
get_files_by_basename,
get_files_by_extension(extension : String) : Array(String)
get_files_by_extension,
get_files_by_extensions(extensions : Array(String)) : Array(String)
get_files_by_extensions,
get_files_by_prefix(prefix : String) : Array(String)
get_files_by_prefix,
get_files_by_prefix_and_extension(prefix : String, extension : String) : Array(String)
get_files_by_prefix_and_extension,
get_files_by_relative_path(relative_path : String, root : String = "") : Array(String)
get_files_by_relative_path,
get_public_dir_files(base_path : String, folder : String) : Array(String)
get_public_dir_files,
get_public_files(base_path : String, anchors : Array(String) = ["shard.yml", "Gemfile"]) : Array(String)
get_public_files,
walked_path(expanded : String) : String
walked_path
Class Method Detail
Instance Method Detail
Instance-side view of the same declaration. The per-file rescues live on
this base class, which has no way to name the analyzer that is running
inside them, so a skipped file could not be attributed to a tech.
Deriving it from analyzer_for keeps the name written exactly once.