class
Analyzer::Javascript::SocketIO
Overview
Surfaces Socket.IO real-time attack surface as ws:// endpoints. A
Socket.IO server handles inbound client messages via
socket.on("event", ...) handlers inside a connection callback;
io.of("/namespace") scopes handlers to a namespace. Each inbound
event becomes one endpoint ws://<namespace>/<event> (default
namespace → ws://<event>), method "SEND", protocol "ws" — so the
existing WebsocketTagger tags them. Outbound emit/send calls
(server → client) are not attack surface and are ignored.
Per-file line scan (Socket.IO server setup and its handlers are
co-located). A namespace cursor tracks which .of("/ns") connection
block the current socket.on handlers belong to.
Defined in:
analyzer/analyzers/javascript/socketio.crConstant Summary
-
CONNECTION_HANDLER =
/\b(\w+)\.on\(\s*["'](?:connection|connect)["']/ -
A connection handler on a receiver variable:
admin.on("connection". -
EVENT_HANDLER =
/\b(\w+)\.on\(\s*["']([^"']+)["']/ -
Any
<recv>.on("event", ...)handler. -
NS_ASSIGN =
/\b(\w+)\s*=\s*\w+\.of\(\s*["']([^"']+)["']/ -
const admin = io.of("/admin")— binds a variable to a namespace. -
NS_INLINE_CONNECTION =
/\.of\(\s*["']([^"']+)["']\s*\)\s*\.on\(\s*["'](?:connection|connect)["']/ -
A connection handler on an inline namespace:
io.of("/x").on("connection". -
RESERVED_EVENTS =
Set {"connection", "connect", "connect_error", "disconnect", "disconnecting", "error", "new_namespace", "newListener", "removeListener", "ping", "pong", "reconnect", "reconnect_attempt", "reconnect_error", "reconnect_failed", "reconnecting"} -
Socket.IO / EventEmitter reserved events that are lifecycle signals, not client-invocable application messages.
-
SOCKET_PARAM =
/\.on\(\s*["'](?:connection|connect)["']\s*,\s*(?:async\s+)?(?:function\s*)?\(?\s*(\w+)/ -
The socket parameter bound by a connection callback:
.on("connection", (socket) => …,… , async function (client) {, etc. Only.on(...)calls on such a bound variable are treated as socket event handlers, so unrelated emitters that co-locate with the server (process.on("SIGTERM"),httpServer.on("error")) don't leak phantom events.
Class Method Summary
Instance Method Summary
- #analyze
-
#tech : String
Instance-side view of the same declaration.
Instance methods inherited from class Analyzer
analyze
analyze,
base_path : String
base_path,
base_paths : Array(String)
base_paths,
base_relative_path(path : String) : String
base_relative_path,
callees_needed? : Bool
callees_needed?,
content_matches?(content : String, markers : Regex) : Bool
content_matches?,
http_header_name(name : String) : String | Nil
http_header_name,
line_number_for_index(content : String, char_index : Int32) : Int32
line_number_for_index,
logger : NoirLogger
logger,
parallel_analyze(files : Array(String), &block : String -> Nil)
parallel_analyze,
read_file_content(path : String) : String
read_file_content,
result : Array(Endpoint)
result,
tech : String
tech,
unique_params(params : Array(Param)) : Array(Param)
unique_params,
url : String
url,
web_root_path(path : String, markers : Array(String)) : String
web_root_path
Constructor methods inherited from class Analyzer
new(options : Hash(String, YAML::Any))
new
Macros inherited from class Analyzer
analyzer_for(tech)
analyzer_for
Instance methods inherited from module FileHelper
all_files : Array(String)
all_files,
get_files_by_basename(basename : String) : Array(String)
get_files_by_basename,
get_files_by_extension(extension : String) : Array(String)
get_files_by_extension,
get_files_by_extensions(extensions : Array(String)) : Array(String)
get_files_by_extensions,
get_files_by_prefix(prefix : String) : Array(String)
get_files_by_prefix,
get_files_by_prefix_and_extension(prefix : String, extension : String) : Array(String)
get_files_by_prefix_and_extension,
get_files_by_relative_path(relative_path : String, root : String = "") : Array(String)
get_files_by_relative_path,
get_public_dir_files(base_path : String, folder : String) : Array(String)
get_public_dir_files,
get_public_files(base_path : String, anchors : Array(String) = ["shard.yml", "Gemfile"]) : Array(String)
get_public_files,
walked_path(expanded : String) : String
walked_path
Class Method Detail
Instance Method Detail
Instance-side view of the same declaration. The per-file rescues live on
this base class, which has no way to name the analyzer that is running
inside them, so a skipped file could not be attributed to a tech.
Deriving it from analyzer_for keeps the name written exactly once.