Uploaded image for project: 'SonarJava'
  1. SonarJava
  2. SONARJAVA-3248

Rule S2068: support url userinfo component

    XMLWordPrintable

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 6.1
    • Component/s: Rules
    • Labels:

      Description

      The URL user info component can contain a hardcoded password:

      String url1 = "scheme://user:azerty123@domain.com"; // Sensitive
      String url2 = "scheme://user:@domain.com"; // Compliant
      String url3 = "scheme://user@domain.com:80"; // Compliant
      String url4 = "scheme://user@domain.com"; // Compliant
      String url5 = "scheme://domain.com/user:azerty123"; // Compliant
      

      Exception: no issue should be raised if user and password part of the userinfo component are the same:

      String url1 = "scheme://admin:admin@domain.com"; // Compliant
      

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              alban.auzeill Alban Auzeill
              Reporter:
              pierre-loup.tristant Pierre-Loup Tristant
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Dates

                Due:
                Created:
                Updated:
                Resolved: