Skip to content

Commit

Permalink
Merge pull request #82 from chef/insecure_url
Browse files Browse the repository at this point in the history
Add an autocorrect for insecure gitlab/github source/issue url metadata
  • Loading branch information
tas50 authored Jul 16, 2019
2 parents fbc0abc + af0eff5 commit b8685d6
Show file tree
Hide file tree
Showing 2 changed files with 63 additions and 0 deletions.
4 changes: 4 additions & 0 deletions config/cookstyle.yml
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,10 @@ Chef/LegacyBerksfileSource:
Description: Do not use legacy Berkfile community sources. Use Chef Supermarket instead.
Enabled: true

Chef/InsecureCookbookURL:
Description: Insecure http Github or Gitlab URLs for metadata source_url/issues_url fields
Enabled: true

#### The base rubocop 0.37 enabled.yml file we started with ####

Layout/AccessModifierIndentation:
Expand Down
59 changes: 59 additions & 0 deletions lib/rubocop/cop/chef/insecure_cookbook_url.rb
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
#
# Copyright:: Copyright 2019, Chef Software Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
module RuboCop
module Cop
module Chef
# Use secure Github and Gitlab URLs for source_url and issues_url
#
# @example
#
# # bad
# source_url 'http://github.com/something/something'
# source_url 'http://www.github.com/something/something'
# source_url 'http://www.gitlab.com/something/something'
# source_url 'http://gitlab.com/something/something'
#
# # good
# source_url 'http://github.com/something/something'
# source_url 'http://gitlab.com/something/something'
#
class InsecureCookbookURL < Cop
MSG = 'Insecure http Github or Gitlab URLs for metadata source_url/issues_url fields'.freeze

def_node_matcher :insecure_cb_url?, <<-PATTERN
(send nil? {:source_url :issues_url} (str #insecure_url?))
PATTERN

def insecure_url?(url)
# https://rubular.com/r/dS6L6bQZvwWxWq
url.match?(%r{http://(www.)*git(hub|lab)})
end

def on_send(node)
insecure_cb_url?(node) do
add_offense(node, location: :expression, message: MSG, severity: :warning)
end
end

def autocorrect(node)
lambda do |corrector|
corrector.replace(node.loc.expression, node.source.gsub(%r{http://(www.)*}, 'https://'))
end
end
end
end
end
end

0 comments on commit b8685d6

Please sign in to comment.