UNPKG

sitecheck

Version:

Open Source web application security scanner

541 lines (540 loc) 17.2 kB
<!doctype html> <html lang="en"> <head> <title>Code coverage report for src\params.js</title> <meta charset="utf-8" /> <link rel="stylesheet" href="../prettify.css" /> <link rel="stylesheet" href="../base.css" /> <meta name="viewport" content="width=device-width, initial-scale=1"> <style type='text/css'> .coverage-summary .sorter { background-image: url(../sort-arrow-sprite.png); } </style> </head> <body> <div class='wrapper'> <div class='pad1'> <h1> <a href="../index.html">all files</a> / <a href="index.html">src/</a> params.js </h1> <div class='clearfix'> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Statements</span> <span class='fraction'>73/73</span> </div> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Branches</span> <span class='fraction'>38/38</span> </div> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Functions</span> <span class='fraction'>2/2</span> </div> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Lines</span> <span class='fraction'>72/72</span> </div> <div class='fl pad1y'> <span class="strong">1 statement, 2 branches</span> <span class="quiet">Ignored</span> &nbsp;&nbsp;&nbsp;&nbsp; </div> </div> </div> <div class='status-line high'></div> <pre><table class="coverage"> <tr><td class="line-count quiet">1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158</td><td class="line-coverage quiet"><span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes">16×</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">16×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">15×</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">16×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">14×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">13×</span> <span class="cline-any cline-yes">13×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">12×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-yes">66×</span> <span class="cline-any cline-yes">10×</span> <span class="cline-any cline-yes">10×</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-yes">10×</span> <span class="cline-any cline-yes">10×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">10×</span> <span class="cline-any cline-yes">10×</span> <span class="cline-any cline-yes">10×</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">10×</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">14×</span> <span class="cline-any cline-yes">14×</span> <span class="cline-any cline-yes">14×</span> <span class="cline-any cline-yes">14×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">12×</span> <span class="cline-any cline-yes">12×</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">36×</span> <span class="cline-any cline-yes">25×</span> <span class="cline-any cline-yes">25×</span> <span class="cline-any cline-yes">25×</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">12×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes">11×</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span></td><td class="text"><pre class="prettyprint lang-js">/** * @license Apache-2.0 * Copyright (C) 2016 The Sitecheck Project * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. */ "use strict"; &nbsp; var fs = require("fs"); var valid_url = require("valid-url"); var winston = require("winston"); const url = require('url'); &nbsp; function Params() { // common options this.allPages = false; // if true crawls the entire site. If false, just one page. &nbsp; // log level this.loglevel = "warn"; this.silent = false; this.logFile = undefined; &nbsp; // check list this.checks = []; &nbsp; // connection credentials this.loginPage = "/login"; this.user = "root"; this.password = ""; &nbsp; // map checkName -&gt; js file path this.checkMap = new Map(); &nbsp; /** * Build scan parameters from default params + config file + "manual" params * @param {Array} params - An array of scan parameters. * &lt;ul&gt; * &lt;li&gt;config : path to config file.&lt;/li&gt; * &lt;li&gt;url : Url to scan. Mandatory unless defined in config file.&lt;/li&gt; * &lt;li&gt;checks : An array of check names. Check names must match names of js files in src/checks/**, without ".js". Mandatory unless defined in config file.&lt;/li&gt; * &lt;li&gt;allPages : true to scan all pages of website. Default is false.&lt;/li&gt; * &lt;li&gt;log : true to activate log to file. Default is false.&lt;/li&gt; * &lt;li&gt;silent : true to prevent console logs. Default is false.&lt;/li&gt; * &lt;li&gt;loglevel : sets log level. Possible values are "error", "warn", "info", "verbose", "debug", "silly". Default is "warn".&lt;/li&gt; * &lt;/ul&gt; */ this.gatherScanParams = function (params) { var opts = require('rc')("sitecheck", this, params); &nbsp; // make sure "checks" field is an array if (typeof opts.checks === 'string' || opts.checks instanceof String) { opts.checks = [opts.checks]; } else { this.checks = opts.checks; } &nbsp; if (this.checks.constructor !== Array) { throw new Error("No checks. At least one check must be set to start scan. Operation canceled."); } &nbsp; // checks if (!this.checks || this.checks.length &lt; 1) { throw new Error("No checks. At least one check must be set to start scan. Operation canceled."); } &nbsp; // check url this.url = opts.url; if (!this.url) { throw new Error("No Url. An url must be set. Operation canceled."); } &nbsp; if (!valid_url.isWebUri(this.url)) { throw new Error("Invalid Url \"" + this.url + "\". Please submit a valid url. Operation canceled."); } &nbsp; var uri = new url.parse(this.url); &nbsp; // log system this.loglevel = opts.loglevel; var possibleLogLevels = ["error", "warn", "info", "verbose", "debug", "silly"]; var foundLogLevel = false; for (let i = 0; i &lt; possibleLogLevels.length; i++) { if (this.loglevel === possibleLogLevels[i]) { winston.level = possibleLogLevels[i]; foundLogLevel = true; } } if (!foundLogLevel) { winston.level = "debug"; winston.warn("Incorrect log level \"" + this.loglevel + "\" specified. Log level was set to 'debug'."); this.loglevel = winston.level; } &nbsp; if (opts.log) { var logdir = './log/'; if (!fs.existsSync(logdir)) { fs.mkdirSync(logdir); } var moment = require("moment"); var logfilename = logdir + uri.hostname.replace(/\./, "_") + "_" + moment.utc().format('YYMMDDHHmmss') + ".log"; winston.add(winston.transports.File, { filename: logfilename, handleExceptions: true, humanReadableUnhandledException: true, level: winston.level }); this.logFile = logfilename; } &nbsp; this.silent = opts.silent; /* istanbul ignore next */ // complex and useless to test <span class="skip-if-branch" title="if path not taken" >I</span>if (this.silent) { <span class="cstat-skip" title="statement not covered" > winston.remove(winston.transports.Console);</span> } &nbsp; // verify check names var verified_checks = []; for (let i in opts.checks) { /* istanbul ignore else */ <span class="skip-if-branch" title="else path not taken" >E</span>if (opts.checks.hasOwnProperty(i)) { let name = opts.checks[i]; let name_filtered = name.replace(/[^a-zA-Z0-9_]/g, ''); if (name_filtered !== name) { winston.warn("Invalid check name '" + name + "'. Check names can only contain [a-zA-Z0-9_] characters. Skipped."); } else { let found = false; var check_paths = ["checks/server/", "checks/page/", "checks/"]; &nbsp; for (let j in check_paths) if (!found &amp;&amp; check_paths.hasOwnProperty(j)) { var p = check_paths[j]; var fullpath = __dirname + "/" + p + "check_" + name + ".js"; if (!found &amp;&amp; fs.existsSync(fullpath)) { verified_checks.push(name); this.checkMap.set(name, fullpath); found = true; } } &nbsp; if (!found) { winston.warn("Invalid check name '" + name + "'. Could not find 'check_" + name + ".js'. Skipped."); } } } } this.checks = verified_checks; }; } &nbsp; var p = new Params(); module.exports = p;</pre></td></tr> </table></pre> <div class='push'></div><!-- for sticky footer --> </div><!-- /wrapper --> <div class='footer quiet pad2 space-top1 center small'> Code coverage generated by <a href="http://istanbul-js.org/" target="_blank">istanbul</a> at Thu Jan 12 2017 18:36:02 GMT+0100 (Paris, Madrid) </div> </div> <script src="../prettify.js"></script> <script> window.onload = function () { if (typeof prettyPrint === 'function') { prettyPrint(); } }; </script> <script src="../sorter.js"></script> </body> </html>