2018-11-15 04:50:04 -05:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
|
|
|
module RuboCop
|
|
|
|
module Cop
|
|
|
|
class SafeParams < RuboCop::Cop::Cop
|
2021-03-23 11:09:28 -04:00
|
|
|
MSG = 'Use `safe_params` instead of `params` in url_for.'
|
2018-11-15 04:50:04 -05:00
|
|
|
|
|
|
|
METHOD_NAME_PATTERN = :url_for
|
|
|
|
UNSAFE_PARAM = :params
|
|
|
|
|
|
|
|
def on_send(node)
|
|
|
|
return unless method_name(node) == METHOD_NAME_PATTERN
|
|
|
|
|
|
|
|
add_offense(node, location: :expression) unless safe_params?(node)
|
|
|
|
end
|
|
|
|
|
|
|
|
private
|
|
|
|
|
|
|
|
def safe_params?(node)
|
|
|
|
node.descendants.each do |param_node|
|
|
|
|
next unless param_node.descendants.empty?
|
|
|
|
|
|
|
|
return false if method_name(param_node) == UNSAFE_PARAM
|
|
|
|
end
|
|
|
|
|
|
|
|
true
|
|
|
|
end
|
|
|
|
|
|
|
|
def method_name(node)
|
|
|
|
node.children[1]
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|