Reporter is now a collector: checks declare a verdict (OK/Skip/Warn/Fail/ Fatal) plus findings, and a single central render() prints output. Default output is silent on pass/skip — only FAIL/WARN/ERR checks print, followed by one tally line, so a clean run is two lines. --verbose restores full per-check output. All ~30 checks were converted to this API; orphaned guidance/label helpers (printPerTargetOKLines, per-check *Help blocks, colors_format.go) were removed. The any-usage check (2e) now defaults to only the unstaged working-tree diff (changed lines), via a new per-repo git-diff index in changedlines.go; --all-any restores the full scan. Not-a-git-repo / no-diff warns on nothing. Golden fixtures regenerated; integration tests updated to the new format; added unit tests for the diff index. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
33 lines
937 B
Go
33 lines
937 B
Go
package main
|
|
|
|
func init() {
|
|
register(Check{
|
|
Seq: 150,
|
|
ID: "15",
|
|
Title: "No err.Error() leaked to HTTP clients",
|
|
Run: func(ctx *ScanContext, rep *Reporter) {
|
|
var errLeaks []errLeakViolation
|
|
for _, target := range ctx.backendTargets {
|
|
for _, v := range checkErrLeak(target.root) {
|
|
v.file = prefixDisplayPath(target.display, v.file)
|
|
errLeaks = append(errLeaks, v)
|
|
}
|
|
}
|
|
for _, target := range ctx.pluginTargets {
|
|
for _, v := range checkErrLeak(target.root) {
|
|
v.file = prefixDisplayPath(target.display, v.file)
|
|
errLeaks = append(errLeaks, v)
|
|
}
|
|
}
|
|
if len(errLeaks) > 0 {
|
|
rep.Fail("%d err.Error() leak(s) to HTTP clients — log via slog.Error() and return a user-friendly message", len(errLeaks))
|
|
for _, v := range errLeaks {
|
|
rep.Findingf("%s:%d %s", v.file, v.line, v.snippet)
|
|
}
|
|
} else {
|
|
rep.OK("No err.Error() leaked to HTTP clients")
|
|
}
|
|
},
|
|
})
|
|
}
|