class Analyzer::Javascript::SocketIO

Overview

Surfaces Socket.IO real-time attack surface as ws:// endpoints. A Socket.IO server handles inbound client messages via socket.on("event", ...) handlers inside a connection callback; io.of("/namespace") scopes handlers to a namespace. Each inbound event becomes one endpoint ws://<namespace>/<event> (default namespace → ws://<event>), method "SEND", protocol "ws" — so the existing WebsocketTagger tags them. Outbound emit/send calls (server → client) are not attack surface and are ignored.

Per-file line scan (Socket.IO server setup and its handlers are co-located). A namespace cursor tracks which .of("/ns") connection block the current socket.on handlers belong to.

Defined in:

analyzer/analyzers/javascript/socketio.cr

Constant Summary

CONNECTION_HANDLER = /\b(\w+)\.on\(\s*["'](?:connection|connect)["']/

A connection handler on a receiver variable: admin.on("connection".

EVENT_HANDLER = /\b(\w+)\.on\(\s*["']([^"']+)["']/

Any <recv>.on("event", ...) handler.

NS_ASSIGN = /\b(\w+)\s*=\s*\w+\.of\(\s*["']([^"']+)["']/

const admin = io.of("/admin") — binds a variable to a namespace.

NS_INLINE_CONNECTION = /\.of\(\s*["']([^"']+)["']\s*\)\s*\.on\(\s*["'](?:connection|connect)["']/

A connection handler on an inline namespace: io.of("/x").on("connection".

RESERVED_EVENTS = Set {"connection", "connect", "connect_error", "disconnect", "disconnecting", "error", "new_namespace", "newListener", "removeListener", "ping", "pong", "reconnect", "reconnect_attempt", "reconnect_error", "reconnect_failed", "reconnecting"}

Socket.IO / EventEmitter reserved events that are lifecycle signals, not client-invocable application messages.

SOCKET_PARAM = /\.on\(\s*["'](?:connection|connect)["']\s*,\s*(?:async\s+)?(?:function\s*)?\(?\s*(\w+)/

The socket parameter bound by a connection callback: .on("connection", (socket) => …, … , async function (client) {, etc. Only .on(...) calls on such a bound variable are treated as socket event handlers, so unrelated emitters that co-locate with the server (process.on("SIGTERM"), httpServer.on("error")) don't leak phantom events.

Instance Method Summary

Instance methods inherited from class Analyzer

analyze analyze, base_path : String base_path, base_paths : Array(String) base_paths, callees_needed? : Bool callees_needed?, http_header_name(name : String) : String | Nil http_header_name, line_number_for_index(content : String, char_index : Int32) : Int32 line_number_for_index, logger : NoirLogger logger, parallel_analyze(files : Array(String), &block : String -> Nil) parallel_analyze, read_file_content(path : String) : String read_file_content, result : Array(Endpoint) result, unique_params(params : Array(Param)) : Array(Param) unique_params, url : String url, web_root_path(path : String, markers : Array(String)) : String web_root_path

Constructor methods inherited from class Analyzer

new(options : Hash(String, YAML::Any)) new

Instance methods inherited from module FileHelper

all_files : Array(String) all_files, get_files_by_extension(extension : String) : Array(String) get_files_by_extension, get_files_by_extensions(extensions : Array(String)) : Array(String) get_files_by_extensions, get_files_by_prefix(prefix : String) : Array(String) get_files_by_prefix, get_files_by_prefix_and_extension(prefix : String, extension : String) : Array(String) get_files_by_prefix_and_extension, get_public_dir_files(base_path : String, folder : String) : Array(String) get_public_dir_files, get_public_files(base_path : String, anchors : Array(String) = ["shard.yml", "Gemfile"]) : Array(String) get_public_files

Instance Method Detail

def analyze #

[View source]