Add models for Commons-Lang's RegExUtils class

This commit is contained in:
Chris Smowton
2021-03-05 14:39:16 +00:00
parent 19b74e6e01
commit 9163893879
3 changed files with 127 additions and 0 deletions

View File

@@ -0,0 +1,45 @@
import org.apache.commons.lang3.RegExUtils;
import java.util.regex.Pattern;
public class RegExUtilsTest {
String taint() { return "tainted"; }
void sink(Object o) {}
void test() throws Exception {
Pattern cleanPattern = Pattern.compile("clean");
Pattern taintedPattern = Pattern.compile(taint());
sink(RegExUtils.removeAll(taint(), cleanPattern)); // $hasTaintFlow=y
sink(RegExUtils.removeAll(taint(), "clean")); // $hasTaintFlow=y
sink(RegExUtils.removeFirst(taint(), cleanPattern)); // $hasTaintFlow=y
sink(RegExUtils.removeFirst(taint(), "clean")); // $hasTaintFlow=y
sink(RegExUtils.removePattern(taint(), "clean")); // $hasTaintFlow=y
sink(RegExUtils.replaceAll(taint(), cleanPattern, "replacement")); // $hasTaintFlow=y
sink(RegExUtils.replaceAll(taint(), "clean", "replacement")); // $hasTaintFlow=y
sink(RegExUtils.replaceFirst(taint(), cleanPattern, "replacement")); // $hasTaintFlow=y
sink(RegExUtils.replaceFirst(taint(), "clean", "replacement")); // $hasTaintFlow=y
sink(RegExUtils.replacePattern(taint(), "clean", "replacement")); // $hasTaintFlow=y
sink(RegExUtils.replaceAll("original", cleanPattern, taint())); // $hasTaintFlow=y
sink(RegExUtils.replaceAll("original", "clean", taint())); // $hasTaintFlow=y
sink(RegExUtils.replaceFirst("original", cleanPattern, taint())); // $hasTaintFlow=y
sink(RegExUtils.replaceFirst("original", "clean", taint())); // $hasTaintFlow=y
sink(RegExUtils.replacePattern("original", "clean", taint())); // $hasTaintFlow=y
// Subsequent calls don't propagate taint, as regex search patterns don't propagate to the return value.
sink(RegExUtils.removeAll("original", taintedPattern));
sink(RegExUtils.removeAll("original", taint()));
sink(RegExUtils.removeFirst("original", taintedPattern));
sink(RegExUtils.removeFirst("original", taint()));
sink(RegExUtils.removePattern("original", taint()));
sink(RegExUtils.replaceAll("original", taintedPattern, "replacement"));
sink(RegExUtils.replaceAll("original", taint(), "replacement"));
sink(RegExUtils.replaceFirst("original", taintedPattern, "replacement"));
sink(RegExUtils.replaceFirst("original", taint(), "replacement"));
sink(RegExUtils.replacePattern("original", taint(), "replacement"));
sink(RegExUtils.replaceAll("original", taintedPattern, "replacement"));
sink(RegExUtils.replaceAll("original", taint(), "replacement"));
sink(RegExUtils.replaceFirst("original", taintedPattern, "replacement"));
sink(RegExUtils.replaceFirst("original", taint(), "replacement"));
sink(RegExUtils.replacePattern("original", taint(), "replacement"));
}
}

View File

@@ -0,0 +1,62 @@
/*
* Licensed to the Apache Software Foundation (ASF) under one or more
* contributor license agreements. See the NOTICE file distributed with
* this work for additional information regarding copyright ownership.
* The ASF licenses this file to You under the Apache License, Version 2.0
* (the "License"); you may not use this file except in compliance with
* the License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.apache.commons.lang3;
import java.util.regex.Pattern;
public class RegExUtils {
public static String removeAll(final String text, final Pattern regex) {
return null;
}
public static String removeAll(final String text, final String regex) {
return null;
}
public static String removeFirst(final String text, final Pattern regex) {
return null;
}
public static String removeFirst(final String text, final String regex) {
return null;
}
public static String removePattern(final String text, final String regex) {
return null;
}
public static String replaceAll(final String text, final Pattern regex, final String replacement) {
return null;
}
public static String replaceAll(final String text, final String regex, final String replacement) {
return null;
}
public static String replaceFirst(final String text, final Pattern regex, final String replacement) {
return null;
}
public static String replaceFirst(final String text, final String regex, final String replacement) {
return null;
}
public static String replacePattern(final String text, final String regex, final String replacement) {
return null;
}
}