Class: Scryer::Rules::ActionCableForgeryProtectionRule
- Inherits:
-
Scryer::Rule
- Object
- Scryer::Rule
- Scryer::Rules::ActionCableForgeryProtectionRule
- Defined in:
- lib/scryer/rules/action_cable_forgery_protection_rule.rb
Overview
Flags config.action_cable.disable_request_forgery_protection = true
— an explicit opt-out of Action Cable's default check that a
WebSocket connection's request Origin header matches the app's own
allowed origins, which otherwise blocks cross-site WebSocket hijacking.
Same shape/reasoning as ForceSslRule: only the explicit opt-in to the
insecure behavior is flagged, not its absence.
Instance Attribute Summary
Attributes inherited from Scryer::Rule
Instance Method Summary collapse
Methods inherited from Scryer::Rule
Constructor Details
This class inherits a constructor from Scryer::Rule
Instance Method Details
#scan ⇒ Object
15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 |
# File 'lib/scryer/rules/action_cable_forgery_protection_rule.rb', line 15 def scan findings = [] Ast.each_node(sexp) do |node| next unless Ast.tagged?(node, :assign) target = node[1] next unless Ast.tagged?(target, :field) next unless Ast.ident_text(target[3]) == "disable_request_forgery_protection" value = node[2] next unless Ast.true_literal?(value) line = Ast.line_of(node) findings << finding( line: line, message: "`config.action_cable.disable_request_forgery_protection = true` explicitly " \ "disables Action Cable's default check that a WebSocket connection's " \ "`Origin` header matches an allowed origin — without it, another site can " \ "open a WebSocket connection to this app in a visitor's browser and act as " \ "that visitor (cross-site WebSocket hijacking).", suggested_fix: "Remove this override and set `config.action_cable.allowed_request_origins` " \ "to the app's real origin(s) instead, unless request forgery protection is " \ "deliberately being handled some other way — if so, leave a comment " \ "explaining that." ) end findings end |