2020-05-23 06:03:29 +02:00
|
|
|
<?php
|
2021-12-15 04:58:32 +01:00
|
|
|
|
2020-05-23 06:03:29 +02:00
|
|
|
namespace Psalm\Internal\Analyzer\Statements\Expression;
|
|
|
|
|
|
|
|
use PhpParser;
|
2021-06-08 04:55:21 +02:00
|
|
|
use Psalm\CodeLocation;
|
|
|
|
use Psalm\Context;
|
2020-05-23 06:03:29 +02:00
|
|
|
use Psalm\Internal\Analyzer\Statements\ExpressionAnalyzer;
|
|
|
|
use Psalm\Internal\Analyzer\StatementsAnalyzer;
|
2020-09-30 18:28:13 +02:00
|
|
|
use Psalm\Internal\Codebase\TaintFlowGraph;
|
2021-06-08 04:55:21 +02:00
|
|
|
use Psalm\Internal\DataFlow\TaintSink;
|
2021-11-07 21:06:22 +01:00
|
|
|
use Psalm\Issue\ForbiddenCode;
|
|
|
|
use Psalm\IssueBuffer;
|
2021-03-20 03:41:41 +01:00
|
|
|
use Psalm\Plugin\EventHandler\Event\AddRemoveTaintsEvent;
|
2021-12-03 20:11:20 +01:00
|
|
|
use Psalm\Type\TaintKind;
|
2020-05-23 06:03:29 +02:00
|
|
|
|
2021-12-03 21:07:25 +01:00
|
|
|
use function in_array;
|
|
|
|
|
2020-05-23 06:03:29 +02:00
|
|
|
/**
|
|
|
|
* @internal
|
|
|
|
*/
|
|
|
|
class EvalAnalyzer
|
|
|
|
{
|
|
|
|
public static function analyze(
|
|
|
|
StatementsAnalyzer $statements_analyzer,
|
|
|
|
PhpParser\Node\Expr\Eval_ $stmt,
|
2020-05-23 06:08:16 +02:00
|
|
|
Context $context
|
2021-12-05 18:51:26 +01:00
|
|
|
): void {
|
2020-05-23 06:03:29 +02:00
|
|
|
ExpressionAnalyzer::analyze($statements_analyzer, $stmt->expr, $context);
|
|
|
|
|
2021-11-07 21:06:22 +01:00
|
|
|
$codebase = $statements_analyzer->getCodebase();
|
|
|
|
|
2020-05-23 06:03:29 +02:00
|
|
|
$expr_type = $statements_analyzer->node_data->getType($stmt->expr);
|
|
|
|
|
|
|
|
if ($expr_type) {
|
2020-10-13 23:28:12 +02:00
|
|
|
if ($statements_analyzer->data_flow_graph instanceof TaintFlowGraph
|
2020-05-26 05:28:11 +02:00
|
|
|
&& $expr_type->parent_nodes
|
2021-12-03 21:07:25 +01:00
|
|
|
&& !in_array('TaintedInput', $statements_analyzer->getSuppressedIssues())
|
2020-05-26 05:28:11 +02:00
|
|
|
) {
|
2020-05-23 06:03:29 +02:00
|
|
|
$arg_location = new CodeLocation($statements_analyzer->getSource(), $stmt->expr);
|
|
|
|
|
2020-09-21 05:59:52 +02:00
|
|
|
$eval_param_sink = TaintSink::getForMethodArgument(
|
2020-05-23 06:03:29 +02:00
|
|
|
'eval',
|
|
|
|
'eval',
|
|
|
|
0,
|
|
|
|
$arg_location,
|
2022-12-18 17:15:15 +01:00
|
|
|
$arg_location,
|
2020-05-23 06:03:29 +02:00
|
|
|
);
|
|
|
|
|
2021-12-03 20:11:20 +01:00
|
|
|
$eval_param_sink->taints = [TaintKind::INPUT_EVAL];
|
2020-05-23 06:03:29 +02:00
|
|
|
|
2020-10-13 23:28:12 +02:00
|
|
|
$statements_analyzer->data_flow_graph->addSink($eval_param_sink);
|
2020-05-23 06:03:29 +02:00
|
|
|
|
2021-03-20 03:41:41 +01:00
|
|
|
$codebase = $statements_analyzer->getCodebase();
|
|
|
|
$event = new AddRemoveTaintsEvent($stmt, $context, $statements_analyzer, $codebase);
|
|
|
|
|
|
|
|
$added_taints = $codebase->config->eventDispatcher->dispatchAddTaints($event);
|
|
|
|
$removed_taints = $codebase->config->eventDispatcher->dispatchRemoveTaints($event);
|
|
|
|
|
2020-05-23 06:03:29 +02:00
|
|
|
foreach ($expr_type->parent_nodes as $parent_node) {
|
2021-03-20 03:41:41 +01:00
|
|
|
$statements_analyzer->data_flow_graph->addPath(
|
|
|
|
$parent_node,
|
|
|
|
$eval_param_sink,
|
|
|
|
'arg',
|
|
|
|
$added_taints,
|
2022-12-18 17:15:15 +01:00
|
|
|
$removed_taints,
|
2021-03-20 03:41:41 +01:00
|
|
|
);
|
2020-05-23 06:03:29 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-11-07 21:06:22 +01:00
|
|
|
if (isset($codebase->config->forbidden_functions['eval'])) {
|
2021-11-29 20:54:17 +01:00
|
|
|
IssueBuffer::maybeAdd(
|
2021-11-07 21:06:22 +01:00
|
|
|
new ForbiddenCode(
|
|
|
|
'You have forbidden the use of eval',
|
2022-12-18 17:15:15 +01:00
|
|
|
new CodeLocation($statements_analyzer, $stmt),
|
2021-11-07 21:06:22 +01:00
|
|
|
),
|
2022-12-18 17:15:15 +01:00
|
|
|
$statements_analyzer->getSuppressedIssues(),
|
2021-11-29 20:54:17 +01:00
|
|
|
);
|
2021-11-07 21:06:22 +01:00
|
|
|
}
|
|
|
|
|
2020-05-23 06:03:29 +02:00
|
|
|
$context->check_classes = false;
|
|
|
|
$context->check_variables = false;
|
|
|
|
}
|
|
|
|
}
|