FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Address a TODO in Contrast reader. · feixiaoan/BenchmarkJava@e91a7b1 · GitHub

Repository navigation

Commit e91a7b1

Browse files
Dave Wichers
committed
Address a TODO in Contrast reader.
1 parent 1cfe52e commit e91a7b1

1 file changed

Lines changed: 11 additions & 6 deletions

File tree

‎src/main/java/org/owasp/benchmark/score/parsers/ContrastReader.java‎

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,7 @@
2222
import java.io.FileReader;
2323
import java.text.SimpleDateFormat;
2424
import java.util.Date;
25+
import org.apache.commons.lang3.StringUtils;
2526
import org.json.JSONObject;
2627
import org.owasp.benchmark.score.BenchmarkScore;
2728

@@ -37,6 +38,10 @@ public TestResults parse(File f) throws Exception {
3738
TestResults tr = new TestResults("Contrast", true, TestResults.ToolType.IAST);
3839

3940
BufferedReader reader = new BufferedReader(new FileReader(f));
41+
String FIRSTLINEINDICATOR =
42+
BenchmarkScore.TESTCASENAME
43+
+ StringUtils.repeat("0", BenchmarkScore.TESTIDLENGTH - 1)
44+
+ "1";
4045
String firstLine = null;
4146
String lastLine = "";
4247
String line = "";
@@ -50,10 +55,8 @@ public TestResults parse(File f) throws Exception {
5055
String version =
5156
line.substring(line.indexOf("Version:") + "Version:".length());
5257
tr.setToolVersion(version.trim());
53-
// TODO: expand length of "00001" to match length of TESTCASE_NAME rather
54-
// than exactly 5
5558
} else if (line.contains("DEBUG - >>> [URL")
56-
&& line.contains(BenchmarkScore.TESTCASENAME + "00001")) {
59+
&& line.contains(FIRSTLINEINDICATOR)) {
5760
firstLine = line;
5861
} else if (line.contains("DEBUG - >>> [URL")) {
5962
lastLine = line;
@@ -92,9 +95,10 @@ private void parseContrastFinding(TestResults tr, String json) throws Exception
9295
}
9396
}
9497
} catch (Exception e) {
95-
// There are a few crypto-bad-mac findings not associated with a request, so ignore
96-
// errors associated with those.
97-
if (!json.contains("\"ruleId\":\"crypto-bad-mac\"")) {
98+
// There are a few crypto-bad-mac & crypto-weak-randomness findings not associated with
99+
// a request, so ignore errors associated with those.
100+
if (!json.contains("\"ruleId\":\"crypto-bad-mac\"")
101+
&& !json.contains("\"ruleId\":\"crypto-weak-randomness\"")) {
98102
System.err.println("Contrast Results Parse error for: " + json);
99103
e.printStackTrace();
100104
}
@@ -169,3 +173,4 @@ private String calculateTime(String firstLine, String lastLine) {
169173
return null;
170174
}
171175
}
176+

0 commit comments

Comments
 (0)

Back | FazBrowse Home | New Git URL