
Inline adoc files when they are included exactly once. Also fix language tags because this inlining gives us better information on what language the code is written in.
48 lines
1006 B
Plaintext
48 lines
1006 B
Plaintext
include::../description.adoc[]
|
|
|
|
include::../ask-yourself.adoc[]
|
|
|
|
include::../recommended.adoc[]
|
|
|
|
== Sensitive Code Example
|
|
|
|
----
|
|
// The process object is a global that provides information about, and control over, the current Node.js process
|
|
// All uses of process.stdin are security-sensitive and should be reviewed
|
|
|
|
process.stdin.on('readable', () => {
|
|
const chunk = process.stdin.read(); // Sensitive
|
|
if (chunk !== null) {
|
|
dosomething(chunk);
|
|
}
|
|
});
|
|
|
|
const readline = require('readline');
|
|
readline.createInterface({
|
|
input: process.stdin // Sensitive
|
|
}).on('line', (input) => {
|
|
dosomething(input);
|
|
});
|
|
----
|
|
|
|
include::../see.adoc[]
|
|
|
|
ifdef::env-github,rspecator-view[]
|
|
|
|
'''
|
|
== Implementation Specification
|
|
(visible only on this page)
|
|
|
|
include::../message.adoc[]
|
|
|
|
'''
|
|
== Comments And Links
|
|
(visible only on this page)
|
|
|
|
=== on 6 Dec 2018, 23:57:06 Lars Svensson wrote:
|
|
https://nodejs.org/api/process.html#process_process_stdin
|
|
|
|
include::../comments-and-links.adoc[]
|
|
|
|
endif::env-github,rspecator-view[]
|