class
Analyzer::Elixir::PhoenixChannel
- Analyzer::Elixir::PhoenixChannel
- Analyzer
- Reference
- Object
Overview
Surfaces Phoenix Channels real-time attack surface as ws://
endpoints. A channel module (use Phoenix.Channel / use MyAppWeb, :channel) handles client messages via handle_in/3 clauses; the
socket module maps a topic pattern to the channel with
channel "room:*", RoomChannel. Each handle_in event becomes one
endpoint ws://<topic>/<event> (bare ws://<topic> when a channel has
no handle_in clauses), method "SEND", protocol "ws" — so the existing
WebsocketTagger tags them.
Line-scan analyzer. The topic↔module map lives in the socket module
while handle_in clauses live in the channel module, so channel
declarations are collected across every .ex file first, then joined
onto each channel module.
Defined in:
analyzer/analyzers/elixir/phoenix_channel.crConstant Summary
-
CHANNEL_DECL =
/^\s*channel\s+["']([^"']+)["']\s*,\s*([\w.]+)/ -
channel "room:*", RoomChannel/channel "room:" <> _, MyApp.RoomChannel. -
CHANNEL_USE =
/\buse\s+Phoenix\.Channel\b|\buse\s+[A-Z][\w.]*\s*,\s*:channel\b/ -
A channel module opts into the behaviour with one of these.
-
DEFMODULE =
/^\s*defmodule\s+([\w.]+)\s+do\b/ -
defmodule MyAppWeb.RoomChannel do. -
HANDLE_IN =
/\bhandle_in\s*\(?\s*["']([^"']+)["']/ -
handle_in("new_msg", payload, socket)/handle_in "ping", _p, socket. A catch-allhandle_in(_event, ...)has no string literal, so it is skipped.