2017-05-05 09:05:53 +00:00
|
|
|
" Author: Eddie Lebow https://github.com/elebow
|
|
|
|
" Description: Brakeman, a static analyzer for Rails security
|
|
|
|
|
2018-08-24 15:33:59 +00:00
|
|
|
call ale#Set('ruby_brakeman_options', '')
|
|
|
|
call ale#Set('ruby_brakeman_executable', 'brakeman')
|
2018-09-14 12:24:59 +00:00
|
|
|
call ale#Set('ruby_brakeman_options', '')
|
2018-08-24 15:33:59 +00:00
|
|
|
|
2017-05-05 09:05:53 +00:00
|
|
|
function! ale_linters#ruby#brakeman#Handle(buffer, lines) abort
|
|
|
|
let l:output = []
|
2017-07-26 23:45:25 +00:00
|
|
|
let l:json = ale#util#FuzzyJSONDecode(a:lines, {})
|
2017-09-13 22:33:13 +00:00
|
|
|
let l:sep = has('win32') ? '\' : '/'
|
|
|
|
" Brakeman always outputs paths relative to the Rails app root
|
|
|
|
let l:rails_root = ale#ruby#FindRailsRoot(a:buffer)
|
2017-05-05 09:05:53 +00:00
|
|
|
|
2017-07-26 23:45:25 +00:00
|
|
|
for l:warning in get(l:json, 'warnings', [])
|
2017-05-05 09:05:53 +00:00
|
|
|
let l:text = l:warning.warning_type . ' ' . l:warning.message . ' (' . l:warning.confidence . ')'
|
|
|
|
let l:line = l:warning.line != v:null ? l:warning.line : 1
|
|
|
|
|
|
|
|
call add(l:output, {
|
2017-09-13 22:33:13 +00:00
|
|
|
\ 'filename': l:rails_root . l:sep . l:warning.file,
|
|
|
|
\ 'lnum': l:line,
|
|
|
|
\ 'type': 'W',
|
|
|
|
\ 'text': l:text,
|
2017-05-05 09:05:53 +00:00
|
|
|
\})
|
|
|
|
endfor
|
|
|
|
|
|
|
|
return l:output
|
|
|
|
endfunction
|
|
|
|
|
|
|
|
function! ale_linters#ruby#brakeman#GetCommand(buffer) abort
|
2017-07-12 09:43:47 +00:00
|
|
|
let l:rails_root = ale#ruby#FindRailsRoot(a:buffer)
|
2017-05-05 09:05:53 +00:00
|
|
|
|
2017-08-08 07:39:13 +00:00
|
|
|
if l:rails_root is? ''
|
2017-05-05 09:05:53 +00:00
|
|
|
return ''
|
|
|
|
endif
|
|
|
|
|
2018-09-14 12:24:59 +00:00
|
|
|
let l:executable = ale#Var(a:buffer, 'ruby_brakeman_executable')
|
|
|
|
|
2019-08-13 05:52:13 +00:00
|
|
|
return ale#ruby#EscapeExecutable(l:executable, 'brakeman')
|
2018-08-24 15:33:59 +00:00
|
|
|
\ . ' -f json -q '
|
2017-05-05 09:05:53 +00:00
|
|
|
\ . ale#Var(a:buffer, 'ruby_brakeman_options')
|
2017-06-21 21:33:34 +00:00
|
|
|
\ . ' -p ' . ale#Escape(l:rails_root)
|
2017-05-05 09:05:53 +00:00
|
|
|
endfunction
|
|
|
|
|
|
|
|
call ale#linter#Define('ruby', {
|
|
|
|
\ 'name': 'brakeman',
|
2019-02-22 18:05:04 +00:00
|
|
|
\ 'executable': {b -> ale#Var(b, 'ruby_brakeman_executable')},
|
|
|
|
\ 'command': function('ale_linters#ruby#brakeman#GetCommand'),
|
2017-05-05 09:05:53 +00:00
|
|
|
\ 'callback': 'ale_linters#ruby#brakeman#Handle',
|
|
|
|
\ 'lint_file': 1,
|
|
|
|
\})
|