Sha256: f8b22fd2095522220403094a23cc8cc5c861fcc845bafa91253b9cee4c458fb8

Contents?: true

Size: 1.16 KB

Versions: 5

Compression:

Stored size: 1.16 KB

Contents

require 'rails_best_practices/checks/check'

module RailsBestPractices
  module Checks
    # Check a controller to make sure using scope access
    #
    # Implementation: simply check if or unless compare with current_user or current_user.id and there is a redirect_to message in if or unless block
    class UseScopeAccessCheck < Check
      
      def interesting_nodes
        [:if, :unless]
      end
      
      def interesting_files
        CONTROLLER_FILES
      end
      
      def evaluate_start(node)
        add_error "use scope access" if current_user_redirect?(node)
      end
      
      private
      
      def current_user_redirect?(node)
        condition_node = node.call
        
        condition_node.message == :== and 
        (current_user?(condition_node.arguments.call) or current_user?(condition_node.subject)) and 
        (node.false_node.body.any? {|n| n.message == :redirect_to} or node.true_node.method_body.any? {|n| n.message == :redirect_to})
      end
      
      def current_user?(call_node)
        call_node.message == :current_user or (call_node.subject.message == :current_user and call_node.message == :id)
      end
      
    end
  end
end

Version data entries

5 entries across 5 versions & 1 rubygems

Version Path
rails_best_practices-0.3.1 lib/rails_best_practices/checks/use_scope_access_check.rb
rails_best_practices-0.3.0 lib/rails_best_practices/checks/use_scope_access_check.rb
rails_best_practices-0.2.16 lib/rails_best_practices/checks/use_scope_access_check.rb
rails_best_practices-0.2.15 lib/rails_best_practices/checks/use_scope_access_check.rb
rails_best_practices-0.2.14 lib/rails_best_practices/checks/use_scope_access_check.rb