rspec/rules/S3997/rule.adoc

50 lines
1.1 KiB
Plaintext
Raw Normal View History

== Why is this an issue?
2021-01-27 13:42:22 +01:00
String representations of URIs or URLs are prone to parsing and encoding errors which can lead to vulnerabilities. The ``++System.Uri++`` class is a safe alternative and should be preferred.
2021-02-02 15:02:10 +01:00
2021-01-27 13:42:22 +01:00
This rule raises an issue when two overloads differ only by the string / ``++Uri++`` parameter and the string overload doesn't call the ``++Uri++`` overload. It is assumed that the string parameter represents a URI because of the exact match besides that parameter type. It stands to reason that the safer overload should be used.
2020-06-30 12:48:39 +02:00
=== Noncompliant code example
2020-06-30 12:48:39 +02:00
2022-02-04 17:28:24 +01:00
[source,text]
2020-06-30 12:48:39 +02:00
----
using System;
namespace MyLibrary
{
public class MyClass
{
public void FetchResource(string uriString) // Noncompliant
{
// No calls to FetResource(Uri)
}
public void FetchResource(Uri uri) { }
}
}
----
=== Compliant solution
2020-06-30 12:48:39 +02:00
2022-02-04 17:28:24 +01:00
[source,text]
2020-06-30 12:48:39 +02:00
----
using System;
namespace MyLibrary
{
public class MyClass
{
public void FetchResource(string uriString)
{
FetchResource(new Uri(uriString));
}
public void FetchResource(Uri uri) { }
}
}
----