class ExpressAuthTagger

Included Modules

Defined in:

tagger/framework_taggers/javascript/express_auth.cr

Constant Summary

AUTH_MIDDLEWARE_NAMES = [/\brequireAuth\b/, /\bisAuth\b/, /\bisAuthenticated\b/, /\bensureLoggedIn\b/, /\bensureAuthenticated\b/, /\bauthorize\b/, /\brequireLogin\b/, /\bauthMiddleware\b/, /\bverifyToken\b/, /\bcheckAuth\b/]
BARE_USE = /\b(\w+)\.use\s*\(/

x.use(authMiddleware) — no path argument. Which routes this guards is a property of the object x, not of any URL, so the receiver is captured.

JWT_MIDDLEWARE_PATTERNS = [/expressjwt\s*\(/, /expressJwt\s*\(/]
MOUNTED_USE = /(?:app|router)\.use\s*\(\s*['"]([^'"]+)['"]/

app.use('/prefix', authMiddleware) — the guarded path is spelled out, so the rule can be matched against endpoint URLs anywhere in the scan (the routes it guards are usually mounted from another file).

PASSPORT_PATTERNS = [/passport\.authenticate\s*\(/]
ROUTE_DECLARATION = /\.\s*(?:get|post|put|patch|delete|options|head|all|use|route)\s*\(/

The start of a route registration, used as a statement boundary so a window around one route never reads the next one's middleware.

ROUTE_RECEIVER = /\b(\w+)\s*\.\s*(?:get|post|put|patch|delete|options|head|all|use|route)\s*\(/

A route registration, and who it was registered on: app.get('/x', …), router.post(…), app.route('/x').

Constructors

Class Method Summary

Instance Method Summary

Instance methods inherited from module PrefixScope

prefix_covers?(prefix : String, url : String) : Bool prefix_covers?

Instance methods inherited from class FrameworkTagger

base_relative_path(path : String) : String base_relative_path, class_level_annotation(path : String, lines : Array(String), annotation_name : String) : String | Nil class_level_annotation, collect_files_by_extension(extension : String) : Array(String) collect_files_by_extension, perform(endpoints : Array(Endpoint)) : Array(Endpoint) perform, read_file(path : String) : String | Nil read_file, read_file_lines(path : String) : Array(String) | Nil read_file_lines, read_source_context(endpoint : Endpoint) : Array(SourceContext) read_source_context, static_asset_route?(url : String) : Bool static_asset_route?

Constructor methods inherited from class FrameworkTagger

new(options : Hash(String, YAML::Any)) new

Class methods inherited from class FrameworkTagger

target_techs : Array(String) target_techs

Instance methods inherited from module FileHelper

all_files : Array(String) all_files, get_files_by_basename(basename : String) : Array(String) get_files_by_basename, get_files_by_extension(extension : String) : Array(String) get_files_by_extension, get_files_by_extensions(extensions : Array(String)) : Array(String) get_files_by_extensions, get_files_by_prefix(prefix : String) : Array(String) get_files_by_prefix, get_files_by_prefix_and_extension(prefix : String, extension : String) : Array(String) get_files_by_prefix_and_extension, get_files_by_relative_path(relative_path : String, root : String = "") : Array(String) get_files_by_relative_path, get_public_dir_files(base_path : String, folder : String) : Array(String) get_public_dir_files, get_public_files(base_path : String, anchors : Array(String) = ["shard.yml", "Gemfile"]) : Array(String) get_public_files, walked_path(expanded : String) : String walked_path

Instance methods inherited from class Tagger

name : String name, perform(endpoints : Array(Endpoint)) : Array(Endpoint) perform

Constructor methods inherited from class Tagger

new(options : Hash(String, YAML::Any)) new

Class methods inherited from class Tagger

tagger_key : String tagger_key

Constructor Detail

def self.new(options : Hash(String, YAML::Any)) #

[View source]

Class Method Detail

def self.target_techs : Array(String) #

[View source]

Instance Method Detail

def perform(endpoints : Array(Endpoint)) : Array(Endpoint) #
Description copied from class FrameworkTagger

The per-endpoint shape: look at each endpoint, tag in place, hand the array back. Fifteen framework taggers carried a byte-identical copy of this; they now declare only check_endpoint.

Not every framework tagger fits it — eleven still override #perform because they need a pre-scan over the project (config files, middleware registration) before the per-endpoint pass, or they group endpoints first. Those keep their own.


[View source]