class PerlAuthTagger
- PerlAuthTagger
- FrameworkTagger
- Tagger
- Reference
- Object
Overview
Identifies authentication / authorization guards in Perl web apps.
Dancer2 leans on Dancer2::Plugin::Auth::Extensible, which guards routes either inline on the declaration:
get '/admin' => require_role Admin => sub { ... }; get '/me' => require_login sub { ... };
or globally through a hook before that calls logged_in_user /
redirect. Catalyst and Mojolicious use handler-body checks
($c->user_exists, $c->assert_user_roles, $c->require_login,
$self->is_user_authenticated). This tagger surfaces all of them as a
single auth tag so reviewers can spot the unprotected routes.
Defined in:
tagger/framework_taggers/perl/perl_auth.crConstant Summary
-
BODY_PATTERNS =
[{/\blogged_in_user\b/, "Dancer2 logged_in_user"}, {/\buser_has_role\b/, "Dancer2 user_has_role"}, {/\bauthenticate_user\b/, "Dancer2 authenticate_user"}, {/->\s*assert_user_roles\b/, "Catalyst assert_user_roles"}, {/->\s*check_user_roles\b/, "Catalyst check_user_roles"}, {/->\s*user_exists\b/, "Catalyst user_exists"}, {/\$c\s*->\s*require_login\b/, "Catalyst require_login"}, {/\$c\s*->\s*authenticate\b/, "Catalyst authenticate"}, {/->\s*is_user_authenticated\b/, "Mojolicious is_user_authenticated"}] -
Checks that appear inside the handler body (or a nearby helper).
-
GLOBAL_GUARD_BLOCK_START =
/\bhook\s+before\b|\bbefore\s*=>\s*sub\b|\bsub\s+auto\b|\bsub\s+begin\b/ -
GLOBAL_GUARD_KEYWORDS =
/\brequire_login\b|\brequire_role\b|\blogged_in_user\b|\buser_has_role\b|->\s*authenticate\b|->\s*user_exists\b|->\s*require_login\b|redirect\b.*\blogin\b/ -
Keywords that make a
hook before/ Catalystsub autoblock an application-wide guard covering every route in the file. -
ROUTE_WRAPPER_PATTERNS =
[{/\brequire_all_roles\b/, "Dancer2 require_all_roles"}, {/\brequire_any_role\b/, "Dancer2 require_any_role"}, {/\brequire_role\b/, "Dancer2 require_role"}, {/\brequire_login\b/, "Dancer2 require_login"}] -
Inline route wrappers from Dancer2::Plugin::Auth::Extensible. These sit between the path and the
sub { ... }on the route declaration.
Class Method Summary
Instance Method Summary
-
#perform(endpoints : Array(Endpoint)) : Array(Endpoint)
The per-endpoint shape: look at each endpoint, tag in place, hand the array back.
Instance methods inherited from class FrameworkTagger
base_relative_path(path : String) : String
base_relative_path,
class_level_annotation(path : String, lines : Array(String), annotation_name : String) : String | Nil
class_level_annotation,
collect_files_by_extension(extension : String) : Array(String)
collect_files_by_extension,
perform(endpoints : Array(Endpoint)) : Array(Endpoint)
perform,
read_file(path : String) : String | Nil
read_file,
read_file_lines(path : String) : Array(String) | Nil
read_file_lines,
read_source_context(endpoint : Endpoint) : Array(SourceContext)
read_source_context,
static_asset_route?(url : String) : Bool
static_asset_route?
Constructor methods inherited from class FrameworkTagger
new(options : Hash(String, YAML::Any))
new
Class methods inherited from class FrameworkTagger
target_techs : Array(String)
target_techs
Instance methods inherited from module FileHelper
all_files : Array(String)
all_files,
get_files_by_basename(basename : String) : Array(String)
get_files_by_basename,
get_files_by_extension(extension : String) : Array(String)
get_files_by_extension,
get_files_by_extensions(extensions : Array(String)) : Array(String)
get_files_by_extensions,
get_files_by_prefix(prefix : String) : Array(String)
get_files_by_prefix,
get_files_by_prefix_and_extension(prefix : String, extension : String) : Array(String)
get_files_by_prefix_and_extension,
get_files_by_relative_path(relative_path : String, root : String = "") : Array(String)
get_files_by_relative_path,
get_public_dir_files(base_path : String, folder : String) : Array(String)
get_public_dir_files,
get_public_files(base_path : String, anchors : Array(String) = ["shard.yml", "Gemfile"]) : Array(String)
get_public_files,
walked_path(expanded : String) : String
walked_path
Instance methods inherited from class Tagger
name : String
name,
perform(endpoints : Array(Endpoint)) : Array(Endpoint)
perform
Constructor methods inherited from class Tagger
new(options : Hash(String, YAML::Any))
new
Class methods inherited from class Tagger
tagger_key : String
tagger_key
Class Method Detail
Instance Method Detail
The per-endpoint shape: look at each endpoint, tag in place, hand the
array back. Fifteen framework taggers carried a byte-identical copy of
this; they now declare only check_endpoint.
Not every framework tagger fits it — eleven still override #perform
because they need a pre-scan over the project (config files, middleware
registration) before the per-endpoint pass, or they group endpoints
first. Those keep their own.