PasswordSecureTransferRule   A
last analyzed

Complexity

Total Complexity 6

Size/Duplication

Total Lines 41
Duplicated Lines 0 %

Coupling/Cohesion

Components 1
Dependencies 3

Importance

Changes 0
Metric Value
wmc 6
lcom 1
cbo 3
dl 0
loc 41
rs 10
c 0
b 0
f 0

1 Method

Rating   Name   Duplication   Size   Complexity  
B doValidation() 0 34 6
1
<?php
2
3
namespace whm\Smoke\Rules\Security;
4
5
use Psr\Http\Message\ResponseInterface;
6
use Symfony\Component\DomCrawler\Crawler;
7
use whm\Smoke\Http\Response;
8
use whm\Smoke\Rules\Rule;
9
use whm\Smoke\Rules\StandardRule;
10
11
/**
12
 * This rule checks if a https request contains any insecure includes via http.
13
 */
14
class PasswordSecureTransferRule extends StandardRule
15
{
16
    protected $contentTypes = array('text/html');
17
18
    private $knownIdentifier = array();
19
20
    protected function doValidation(ResponseInterface $response)
21
    {
22
        $crawler = new Crawler((string)$response->getBody());
23
        $actionNodes = $crawler->filterXPath('//form[//input[@type="password"]]');
24
25
        $url = (string)$response->getUri();
0 ignored issues
show
Bug introduced by
It seems like you code against a concrete implementation and not the interface Psr\Http\Message\ResponseInterface as the method getUri() does only exist in the following implementations of said interface: phm\HttpWebdriverClient\...t\Chrome\ChromeResponse, phm\HttpWebdriverClient\...t\Guzzle\GuzzleResponse, phm\HttpWebdriverClient\...\Client\Guzzle\Response, phm\HttpWebdriverClient\...esponse\BrowserResponse, whm\Smoke\Http\ConnectionRefusedResponse, whm\Smoke\Http\ErrorResponse.

Let’s take a look at an example:

interface User
{
    /** @return string */
    public function getPassword();
}

class MyUser implements User
{
    public function getPassword()
    {
        // return something
    }

    public function getDisplayName()
    {
        // return some name.
    }
}

class AuthSystem
{
    public function authenticate(User $user)
    {
        $this->logger->info(sprintf('Authenticating %s.', $user->getDisplayName()));
        // do something.
    }
}

In the above example, the authenticate() method works fine as long as you just pass instances of MyUser. However, if you now also want to pass a different implementation of User which does not have a getDisplayName() method, the code will break.

Available Fixes

  1. Change the type-hint for the parameter:

    class AuthSystem
    {
        public function authenticate(MyUser $user) { /* ... */ }
    }
    
  2. Add an additional type-check:

    class AuthSystem
    {
        public function authenticate(User $user)
        {
            if ($user instanceof MyUser) {
                $this->logger->info(/** ... */);
            }
    
            // or alternatively
            if ( ! $user instanceof MyUser) {
                throw new \LogicException(
                    '$user must be an instance of MyUser, '
                   .'other instances are not supported.'
                );
            }
    
        }
    }
    
Note: PHP Analyzer uses reverse abstract interpretation to narrow down the types inside the if block in such a case.
  1. Add the method to the interface:

    interface User
    {
        /** @return string */
        public function getPassword();
    
        /** @return string */
        public function getDisplayName();
    }
    
Loading history...
26
27
        foreach ($actionNodes as $node) {
28
            $action = $node->getAttribute('action');
29
30
            if (strpos($action, 'https://') === 0) {
31
                continue;
32
            }
33
34
            $fullPath = $node->tagName;
35
            $parent = $node->parentNode;
36
37
            while ($parent = $parent->parentNode) {
38
                if (property_exists($parent, 'tagName')) {
39
                    $fullPath = $parent->tagName . '/' . $fullPath;
40
                } else {
41
                    break;
42
                }
43
            }
44
45
            if (in_array($fullPath, $this->knownIdentifier, true)) {
46
                continue;
47
            }
48
49
            $this->knownIdentifier[] = $fullPath;
50
51
            $this->assert(strpos($url, 'https://') !== false, 'Password is transferred insecure using HTTP.');
52
        }
53
    }
54
}
55