All Downloads are FREE. Search and download functionalities are using the official Maven repository.

io.codemodder.remediation.xss.XSSRemediator Maven / Gradle / Ivy

There is a newer version: 0.98.8
Show newest version
package io.codemodder.remediation.xss;

import com.github.javaparser.ast.CompilationUnit;
import io.codemodder.CodemodFileScanningResult;
import io.codemodder.codetf.DetectorRule;
import io.codemodder.remediation.FixCandidateSearcher;
import io.codemodder.remediation.Remediator;
import io.codemodder.remediation.SearcherStrategyRemediator;
import java.util.Collection;
import java.util.Optional;
import java.util.function.Function;

/** Remediator for XSS vulnerabilities. */
public final class XSSRemediator implements Remediator {

  private final SearcherStrategyRemediator searchStrategyRemediator;

  public XSSRemediator() {
    this.searchStrategyRemediator =
        new SearcherStrategyRemediator.Builder()
            .withSearcherStrategyPair(
                new FixCandidateSearcher.Builder()
                    .withMatcher(NakedVariableReturnFixStrategy::match)
                    .build(),
                new NakedVariableReturnFixStrategy())
            .withSearcherStrategyPair(
                new FixCandidateSearcher.Builder()
                    .withMatcher(PrintingMethodFixStrategy::match)
                    .build(),
                new PrintingMethodFixStrategy())
            .withSearcherStrategyPair(
                new FixCandidateSearcher.Builder()
                    .withMatcher(ResponseEntityConstructorFixStrategy::match)
                    .build(),
                new ResponseEntityConstructorFixStrategy())
            .withSearcherStrategyPair(
                new FixCandidateSearcher.Builder()
                    .withMatcher(ResponseEntityWriteFixStrategy::match)
                    .build(),
                new ResponseEntityWriteFixStrategy())
            .build();
  }

  @Override
  public CodemodFileScanningResult remediateAll(
      CompilationUnit cu,
      String path,
      DetectorRule detectorRule,
      Collection findingsForPath,
      Function findingIdExtractor,
      Function findingStartLineExtractor,
      Function> findingEndLineExtractor,
      Function> findingColumnExtractor) {
    return searchStrategyRemediator.remediateAll(
        cu,
        path,
        detectorRule,
        findingsForPath,
        findingIdExtractor,
        findingStartLineExtractor,
        findingEndLineExtractor,
        findingColumnExtractor);
  }
}




© 2015 - 2025 Weber Informatics LLC | Privacy Policy