
When an include is not surrounded by empty lines, its content is inlined on the same line as the adjacent content. That can lead to broken tags and other display issues. This PR fixes all such includes and introduces a validation step that forbids introducing the same problem again.
64 lines
1.3 KiB
Plaintext
64 lines
1.3 KiB
Plaintext
include::../description.adoc[]
|
|
|
|
include::../ask-yourself.adoc[]
|
|
|
|
include::../recommended.adoc[]
|
|
|
|
== Sensitive Code Example
|
|
|
|
----
|
|
Imports System.Security.Cryptography
|
|
|
|
Sub ComputeHash()
|
|
|
|
' Review all instantiations of classes that inherit from HashAlgorithm, for example:
|
|
Dim hashAlgo As HashAlgorithm = HashAlgorithm.Create() ' Sensitive
|
|
Dim hashAlgo2 As HashAlgorithm = HashAlgorithm.Create("SHA1") ' Sensitive
|
|
Dim sha As SHA1 = New SHA1CryptoServiceProvider() ' Sensitive
|
|
Dim md5 As MD5 = New MD5CryptoServiceProvider() ' Sensitive
|
|
|
|
' ...
|
|
End Sub
|
|
|
|
Class MyHashAlgorithm
|
|
Inherits HashAlgorithm ' Sensitive
|
|
|
|
' ...
|
|
End Class
|
|
----
|
|
|
|
== Compliant Solution
|
|
|
|
[source,vbnet]
|
|
----
|
|
Imports System.Security.Cryptography
|
|
|
|
Sub ComputeHash()
|
|
Dim sha256 = New SHA256CryptoServiceProvider() ' Compliant
|
|
Dim sha384 = New SHA384CryptoServiceProvider() ' Compliant
|
|
Dim sha512 = New SHA512CryptoServiceProvider() ' Compliant
|
|
|
|
' ...
|
|
End Sub
|
|
----
|
|
|
|
include::../see.adoc[]
|
|
|
|
ifdef::env-github,rspecator-view[]
|
|
|
|
'''
|
|
== Implementation Specification
|
|
(visible only on this page)
|
|
|
|
include::../message.adoc[]
|
|
|
|
include::../highlighting.adoc[]
|
|
|
|
'''
|
|
== Comments And Links
|
|
(visible only on this page)
|
|
|
|
include::../comments-and-links.adoc[]
|
|
|
|
endif::env-github,rspecator-view[]
|