1
0
mirror of https://github.com/danog/psalm.git synced 2024-12-15 19:07:00 +01:00
psalm/src/Psalm/Internal/Analyzer/Statements/Expression/EvalAnalyzer.php

57 lines
1.7 KiB
PHP
Raw Normal View History

2020-05-23 06:03:29 +02:00
<?php
namespace Psalm\Internal\Analyzer\Statements\Expression;
use PhpParser;
use Psalm\Internal\Analyzer\Statements\ExpressionAnalyzer;
use Psalm\Internal\Analyzer\StatementsAnalyzer;
use Psalm\Internal\Taint\Sink;
use Psalm\CodeLocation;
use Psalm\Context;
/**
* @internal
*/
class EvalAnalyzer
{
public static function analyze(
StatementsAnalyzer $statements_analyzer,
PhpParser\Node\Expr\Eval_ $stmt,
2020-05-23 06:08:16 +02:00
Context $context
2020-05-23 06:03:29 +02:00
) : void {
ExpressionAnalyzer::analyze($statements_analyzer, $stmt->expr, $context);
$expr_type = $statements_analyzer->node_data->getType($stmt->expr);
if ($expr_type) {
$codebase = $statements_analyzer->getCodebase();
2020-09-21 00:27:02 +02:00
if ($codebase->taint_graph
2020-05-26 05:28:11 +02:00
&& $expr_type->parent_nodes
&& $codebase->config->trackTaintsInPath($statements_analyzer->getFilePath())
&& !\in_array('TaintedInput', $statements_analyzer->getSuppressedIssues())
2020-05-26 05:28:11 +02:00
) {
2020-05-23 06:03:29 +02:00
$arg_location = new CodeLocation($statements_analyzer->getSource(), $stmt->expr);
$eval_param_sink = Sink::getForMethodArgument(
'eval',
'eval',
0,
$arg_location,
$arg_location
);
$eval_param_sink->taints = [\Psalm\Type\TaintKind::INPUT_TEXT];
2020-05-23 06:03:29 +02:00
2020-09-21 00:27:02 +02:00
$codebase->taint_graph->addSink($eval_param_sink);
2020-05-23 06:03:29 +02:00
foreach ($expr_type->parent_nodes as $parent_node) {
2020-09-21 00:27:02 +02:00
$codebase->taint_graph->addPath($parent_node, $eval_param_sink, 'arg');
2020-05-23 06:03:29 +02:00
}
}
}
$context->check_classes = false;
$context->check_variables = false;
}
}