class Analyzer::Elixir::Bandit

Overview

Bandit (https://github.com/mtrudel/bandit) is the modern HTTP server that ships with Phoenix 1.7+ and is increasingly used to host raw Plug.Router modules. Route registration syntax inside the router is identical to Plug.Router, so we reuse the Plug extraction logic and only rename the analyzer so endpoints get tagged with the elixir_bandit technology.

Defined in:

analyzer/analyzers/elixir/bandit.cr

Class Method Summary

Instance Method Summary

Instance methods inherited from class Analyzer::Elixir::Plug

analyze_content(content : String, file_path : String) : Array(Endpoint) analyze_content, analyze_file(path : String) : Array(Endpoint) analyze_file, extract_params_from_block(lines : Array(String), start_index : Int32, method : String, block_end : Int32 | Nil = nil) : Array(Param) extract_params_from_block, find_block_end(lines : Array(String), start_index : Int32) : Int32 find_block_end, line_to_endpoint(line : String) : Array(Endpoint) line_to_endpoint, tech : String tech

Class methods inherited from class Analyzer::Elixir::Plug

tech_name : String tech_name

Class methods inherited from class Analyzer::Elixir::ElixirEngine

test_path?(path : String) : Bool test_path?

Instance methods inherited from class FileScanEngine

analyze analyze, analyze_file(path : String) : Array(Endpoint) analyze_file

Instance methods inherited from class Analyzer

analyze analyze, base_path : String base_path, base_paths : Array(String) base_paths, base_relative_path(path : String) : String base_relative_path, callees_needed? : Bool callees_needed?, content_matches?(content : String, markers : Regex) : Bool content_matches?, http_header_name(name : String) : String | Nil http_header_name, line_number_for_index(content : String, char_index : Int32) : Int32 line_number_for_index, logger : NoirLogger logger, parallel_analyze(files : Array(String), &block : String -> Nil) parallel_analyze, read_file_content(path : String) : String read_file_content, result : Array(Endpoint) result, tech : String tech, unique_params(params : Array(Param)) : Array(Param) unique_params, url : String url, web_root_path(path : String, markers : Array(String)) : String web_root_path

Constructor methods inherited from class Analyzer

new(options : Hash(String, YAML::Any)) new

Macros inherited from class Analyzer

analyzer_for(tech) analyzer_for

Instance methods inherited from module FileHelper

all_files : Array(String) all_files, get_files_by_basename(basename : String) : Array(String) get_files_by_basename, get_files_by_extension(extension : String) : Array(String) get_files_by_extension, get_files_by_extensions(extensions : Array(String)) : Array(String) get_files_by_extensions, get_files_by_prefix(prefix : String) : Array(String) get_files_by_prefix, get_files_by_prefix_and_extension(prefix : String, extension : String) : Array(String) get_files_by_prefix_and_extension, get_files_by_relative_path(relative_path : String, root : String = "") : Array(String) get_files_by_relative_path, get_public_dir_files(base_path : String, folder : String) : Array(String) get_public_dir_files, get_public_files(base_path : String, anchors : Array(String) = ["shard.yml", "Gemfile"]) : Array(String) get_public_files, walked_path(expanded : String) : String walked_path

Class Method Detail

def self.tech_name : String #

[View source]

Instance Method Detail

def tech : String #

Instance-side view of the same declaration. The per-file rescues live on this base class, which has no way to name the analyzer that is running inside them, so a skipped file could not be attributed to a tech. Deriving it from analyzer_for keeps the name written exactly once.


[View source]