Class: Scryer::Rules::WeakSessionCookieRule
- Inherits:
-
Scryer::Rule
- Object
- Scryer::Rule
- Scryer::Rules::WeakSessionCookieRule
- Defined in:
- lib/scryer/rules/weak_session_cookie_rule.rb
Overview
Flags config.session_store :cookie_store, ... with no secure: true
in its options — without it, the session cookie can be sent over plain
HTTP, not just HTTPS. Only :cookie_store is checked (the default and
most common store); other stores (:redis_session_store, ...) don't
carry the same cookie-content risk and are out of scope here.
Instance Attribute Summary
Attributes inherited from Scryer::Rule
Instance Method Summary collapse
Methods inherited from Scryer::Rule
Constructor Details
This class inherits a constructor from Scryer::Rule
Instance Method Details
#scan ⇒ Object
14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 |
# File 'lib/scryer/rules/weak_session_cookie_rule.rb', line 14 def scan findings = [] Ast.each_node(sexp) do |node| next unless Ast.tagged?(node, :command, :command_call, :method_add_arg) inner = Ast.tagged?(node, :method_add_arg) ? node[1] : node receiver_and_name = Ast.call_name(inner) next unless receiver_and_name _receiver, method_name = receiver_and_name next unless method_name == "session_store" args = Ast.call_arguments(node) next unless args.any? { |a| Ast.literal_text(a) == "cookie_store" } next if Ast.true_literal?(Ast.keyword_arg(args, "secure")) line = Ast.line_of(node) findings << finding( line: line, message: "`session_store :cookie_store` has no `secure: true` — the session cookie " \ "can be transmitted over plain HTTP, where it's exposed to network " \ "eavesdropping (e.g. on shared/untrusted Wi-Fi).", suggested_fix: "Add `secure: true` to the session_store options (typically only in " \ "production, since local HTTP development doesn't have TLS): " \ "`config.session_store :cookie_store, key: '_app_session', secure: " \ "Rails.env.production?`." ) end findings end |