Class: Scryer::Rules::ActiveStorageInlineDispositionRule
- Inherits:
-
Scryer::Rule
- Object
- Scryer::Rule
- Scryer::Rules::ActiveStorageInlineDispositionRule
- Defined in:
- lib/scryer/rules/active_storage_inline_disposition_rule.rb
Overview
Flags an explicit disposition: "inline"/:inline on a blob/variant
URL helper (rails_blob_path, rails_blob_url, url_for, a
.variant(...) chain). Serving user-uploaded content inline (rendered
directly in the browser, rather than downloaded) can lead to stored
XSS if the uploaded file's content-type isn't tightly restricted — an
uploaded SVG or HTML file executes in the page's own origin.
Instance Attribute Summary
Attributes inherited from Scryer::Rule
Instance Method Summary collapse
Methods inherited from Scryer::Rule
Constructor Details
This class inherits a constructor from Scryer::Rule
Instance Method Details
#scan ⇒ Object
15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 |
# File 'lib/scryer/rules/active_storage_inline_disposition_rule.rb', line 15 def scan findings = [] Ast.each_node(sexp) do |node| next unless Ast.tagged?(node, :method_add_arg, :command, :command_call) inner = Ast.tagged?(node, :method_add_arg) ? node[1] : node name_pair = Ast.call_name(inner) next unless name_pair args = Ast.call_arguments(node) disposition = Ast.keyword_arg(args, "disposition") next unless disposition && Ast.literal_text(disposition) == "inline" line = Ast.line_of(node) findings << finding( line: line, message: "`disposition: \"inline\"` renders this attachment's content directly in " \ "the browser instead of downloading it — if the attachment's content-type " \ "isn't tightly restricted, a user-uploaded SVG or HTML file served this way " \ "executes as if it were part of the site.", suggested_fix: "Prefer the default `disposition: \"attachment\"` (or drop the option " \ "entirely) unless inline rendering is genuinely required — and if it " \ "is, make sure the attachment has a strict `content_type:` allowlist " \ "(e.g. image types only) so nothing executable can reach this code path." ) end findings end |