Class: Brakeman::CheckSecrets

Inherits:
BaseCheck
  • Object
show all
Defined in:
lib/brakeman/checks/check_secrets.rb

Instance Method Summary collapse

Instance Method Details

#check_constantsObject



12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
# File 'lib/brakeman/checks/check_secrets.rb', line 12

def check_constants
  @warned = Set.new

  @tracker.constants.each do |constant|
    name = constant.name_array.last
    value = constant.value

    if string? value and not value.value.empty? and looks_like_secret? name
      match = [name, value, value.line]

      unless @warned.include? match
        @warned << match

        warn :warning_code => :secret_in_source,
          :warning_type => "Authentication",
          :message => msg("Hardcoded value for ", msg_code(name), " in source code"),
          :confidence => :medium,
          :file => constant.file,
          :line => constant.line,
          :cwe_id => [798]
      end
    end
  end
end

#looks_like_secret?(name) ⇒ Boolean

Returns:

  • (Boolean)


37
38
39
40
# File 'lib/brakeman/checks/check_secrets.rb', line 37

def looks_like_secret? name
  # REST_AUTH_SITE_KEY is the pepper in Devise
  name.match(/password|secret|(rest_auth_site|api)_key$/i)
end

#run_checkObject



8
9
10
# File 'lib/brakeman/checks/check_secrets.rb', line 8

def run_check
  check_constants
end