check-safety/check_htmlsanitize.go
Alex Dunmow c4d01de82c feat: concise output + diff-scoped any check
Reporter is now a collector: checks declare a verdict (OK/Skip/Warn/Fail/
Fatal) plus findings, and a single central render() prints output. Default
output is silent on pass/skip — only FAIL/WARN/ERR checks print, followed by
one tally line, so a clean run is two lines. --verbose restores full per-check
output. All ~30 checks were converted to this API; orphaned guidance/label
helpers (printPerTargetOKLines, per-check *Help blocks, colors_format.go) were
removed.

The any-usage check (2e) now defaults to only the unstaged working-tree diff
(changed lines), via a new per-repo git-diff index in changedlines.go; --all-any
restores the full scan. Not-a-git-repo / no-diff warns on nothing.

Golden fixtures regenerated; integration tests updated to the new format; added
unit tests for the diff index.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-04 01:16:56 +08:00

33 lines
1017 B
Go

package main
func init() {
register(Check{
Seq: 220,
ID: "22",
Title: "No hand-rolled HTML sanitization (use bluemonday)",
Run: func(ctx *ScanContext, rep *Reporter) {
var htmlSanViolations []htmlSanitizeViolation
for _, target := range ctx.backendTargets {
for _, v := range checkHTMLSanitize(target.root) {
v.file = prefixDisplayPath(target.display, v.file)
htmlSanViolations = append(htmlSanViolations, v)
}
}
for _, target := range ctx.pluginTargets {
for _, v := range checkHTMLSanitize(target.root) {
v.file = prefixDisplayPath(target.display, v.file)
htmlSanViolations = append(htmlSanViolations, v)
}
}
if len(htmlSanViolations) > 0 {
rep.Fail("%d hand-rolled HTML sanitization pattern(s) — use bluemonday", len(htmlSanViolations))
for _, v := range htmlSanViolations {
rep.Findingf("%s:%d [%s] %s", v.file, v.line, v.rule, v.snippet)
}
} else {
rep.OK("No hand-rolled HTML sanitization detected")
}
},
})
}