psalm-baseline-security.xml 4.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133
  1. <?xml version="1.0" encoding="UTF-8"?>
  2. <files psalm-version="5.26.1@d747f6500b38ac4f7dfc5edbcae6e4b637d7add0">
  3. <file src="apps/admin_audit/lib/Actions/Action.php">
  4. <TaintedHtml>
  5. <code><![CDATA[$params]]></code>
  6. </TaintedHtml>
  7. </file>
  8. <file src="apps/files_external/lib/Config/ConfigAdapter.php">
  9. <TaintedCallable>
  10. <code><![CDATA[$objectClass]]></code>
  11. </TaintedCallable>
  12. </file>
  13. <file src="apps/theming/lib/IconBuilder.php">
  14. <TaintedFile>
  15. <code><![CDATA[$appIcon]]></code>
  16. <code><![CDATA[$imageFile]]></code>
  17. </TaintedFile>
  18. </file>
  19. <file src="lib/base.php">
  20. <TaintedHeader>
  21. <code><![CDATA['Location: ' . $url]]></code>
  22. <code><![CDATA['Location: ' . \OC::$WEBROOT . '/']]></code>
  23. </TaintedHeader>
  24. </file>
  25. <file src="lib/private/AppFramework/Utility/SimpleContainer.php">
  26. <TaintedCallable>
  27. <code><![CDATA[$name]]></code>
  28. </TaintedCallable>
  29. </file>
  30. <file src="lib/private/Config.php">
  31. <TaintedHtml>
  32. <code><![CDATA[$this->cache]]></code>
  33. </TaintedHtml>
  34. </file>
  35. <file src="lib/private/EventSource.php">
  36. <TaintedHeader>
  37. <code><![CDATA['Location: ' . \OC::$WEBROOT]]></code>
  38. </TaintedHeader>
  39. </file>
  40. <file src="lib/private/Http/CookieHelper.php">
  41. <TaintedHeader>
  42. <code><![CDATA[$header]]></code>
  43. </TaintedHeader>
  44. </file>
  45. <file src="lib/private/Installer.php">
  46. <TaintedFile>
  47. <code><![CDATA[$baseDir]]></code>
  48. </TaintedFile>
  49. </file>
  50. <file src="lib/private/OCS/ApiHelper.php">
  51. <TaintedHtml>
  52. <code><![CDATA[$body]]></code>
  53. </TaintedHtml>
  54. <TaintedTextWithQuotes>
  55. <code><![CDATA[$body]]></code>
  56. </TaintedTextWithQuotes>
  57. </file>
  58. <file src="lib/private/Route/Router.php">
  59. <TaintedCallable>
  60. <code><![CDATA[$appNameSpace . '\\Controller\\' . basename($file->getPathname(), '.php')]]></code>
  61. </TaintedCallable>
  62. </file>
  63. <file src="lib/private/ServerContainer.php">
  64. <TaintedCallable>
  65. <code><![CDATA[$applicationClassName]]></code>
  66. </TaintedCallable>
  67. </file>
  68. <file src="lib/private/Session/CryptoWrapper.php">
  69. <TaintedCookie>
  70. <code><![CDATA[$this->passphrase]]></code>
  71. </TaintedCookie>
  72. </file>
  73. <file src="lib/private/Setup.php">
  74. <TaintedFile>
  75. <code><![CDATA[$dataDir]]></code>
  76. </TaintedFile>
  77. </file>
  78. <file src="lib/private/Setup/Sqlite.php">
  79. <TaintedFile>
  80. <code><![CDATA[$sqliteFile]]></code>
  81. </TaintedFile>
  82. </file>
  83. <file src="lib/private/legacy/OC_Helper.php">
  84. <TaintedFile>
  85. <code><![CDATA[$dest]]></code>
  86. <code><![CDATA[$dest]]></code>
  87. <code><![CDATA[$dir]]></code>
  88. <code><![CDATA[$dir]]></code>
  89. </TaintedFile>
  90. </file>
  91. <file src="lib/private/legacy/OC_JSON.php">
  92. <TaintedHeader>
  93. <code><![CDATA['Location: ' . \OC::$WEBROOT]]></code>
  94. </TaintedHeader>
  95. <TaintedHtml>
  96. <code><![CDATA[self::encode($data)]]></code>
  97. <code><![CDATA[self::encode($data)]]></code>
  98. </TaintedHtml>
  99. <TaintedTextWithQuotes>
  100. <code><![CDATA[self::encode($data)]]></code>
  101. <code><![CDATA[self::encode($data)]]></code>
  102. </TaintedTextWithQuotes>
  103. </file>
  104. <file src="lib/private/legacy/OC_Template.php">
  105. <TaintedHtml>
  106. <code><![CDATA[$exception->getTraceAsString()]]></code>
  107. </TaintedHtml>
  108. <TaintedTextWithQuotes>
  109. <code><![CDATA[$exception->getTraceAsString()]]></code>
  110. </TaintedTextWithQuotes>
  111. </file>
  112. <file src="lib/public/DB/QueryBuilder/IQueryBuilder.php">
  113. <TaintedSql>
  114. <code><![CDATA[$column]]></code>
  115. </TaintedSql>
  116. </file>
  117. <file src="lib/public/IDBConnection.php">
  118. <TaintedSql>
  119. <code><![CDATA[$sql]]></code>
  120. <code><![CDATA[$sql]]></code>
  121. <code><![CDATA[$sql]]></code>
  122. <code><![CDATA[$sql]]></code>
  123. </TaintedSql>
  124. </file>
  125. <file src="ocs-provider/index.php">
  126. <TaintedHtml>
  127. <code><![CDATA[$controller->buildProviderList()->render()]]></code>
  128. </TaintedHtml>
  129. <TaintedTextWithQuotes>
  130. <code><![CDATA[$controller->buildProviderList()->render()]]></code>
  131. </TaintedTextWithQuotes>
  132. </file>
  133. </files>