Skip to content
This repository has been archived by the owner on Jun 2, 2022. It is now read-only.

Commit

Permalink
feat: allow lazy || wrapper classes
Browse files Browse the repository at this point in the history
  • Loading branch information
FauxFaux committed Jul 11, 2019
1 parent 626c3b7 commit f58306c
Show file tree
Hide file tree
Showing 2 changed files with 19 additions and 0 deletions.
4 changes: 4 additions & 0 deletions lib/ast.js
Original file line number Diff line number Diff line change
Expand Up @@ -96,6 +96,10 @@ function inspectNode(node, path, cb, expectingAnonymousDeclaration) {
inspectNode(node.right, path.concat(unpackName(node.left)), cb, true);
break;
}
case 'LogicalExpression':
inspectNode(node.left, path, cb);
inspectNode(node.right, path, cb);
break;
case 'UnaryExpression':
inspectNode(node.argument, path, cb);
break;
Expand Down
15 changes: 15 additions & 0 deletions test/method-detection.test.js
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,21 @@ if (console.both) {
t.end();
});

test('test lazy class declaration', function (t) {
const contents = `
var Class = Class || (function (Object) {
function foo() {}
});
`;
const methods = ['Class.foo'];
const found = ast.findAllVulnerableFunctionsInScript(
contents, methods,
);
t.same(sorted(Object.keys(found)), sorted(methods));
t.equal(found[methods[0]].start.line, 3, 'foo');
t.end();
});

test('test st method detection', function (t) {
const content = fs.readFileSync(__dirname + '/fixtures/st/node_modules/st.js');
const methods = ['Mount.prototype.getPath'];
Expand Down

0 comments on commit f58306c

Please sign in to comment.