// Copyright (c) Microsoft Corporation. All rights reserved. // Licensed under the MIT License. using System; using System.Collections.Generic; using System.Linq; using System.Management.Automation.Language; using Microsoft.Windows.PowerShell.ScriptAnalyzer.Generic; #if !CORECLR using System.ComponentModel.Composition; #endif using System.Globalization; namespace Microsoft.Windows.PowerShell.ScriptAnalyzer.BuiltinRules { /// /// AvoidUsingConvertToSecureStringWithPlainText: Check that convertto-securestring does not use plaintext. /// #if !CORECLR [Export(typeof(IScriptRule))] #endif public class AvoidUsingConvertToSecureStringWithPlainText : AvoidParameterGeneric { List CTSTCmdlet; /// /// Condition on the cmdlet that must be satisfied for the error to be raised /// /// /// public override bool CommandCondition(CommandAst CmdAst) { if (CTSTCmdlet == null) { CTSTCmdlet = Helper.Instance.CmdletNameAndAliases("convertto-securestring"); } return CmdAst != null && CmdAst.GetCommandName() != null && CTSTCmdlet.Contains(CmdAst.GetCommandName(), StringComparer.OrdinalIgnoreCase); } /// /// Condition on the parameter that must be satisfied for the error to be raised. /// /// /// /// public override bool ParameterCondition(CommandAst CmdAst, CommandElementAst CeAst) { return CeAst is CommandParameterAst && String.Equals((CeAst as CommandParameterAst).ParameterName, "AsPlainText", StringComparison.OrdinalIgnoreCase); } /// /// Retrieves the error message /// /// /// /// public override string GetError(string fileName, CommandAst cmdAst) { if (String.IsNullOrWhiteSpace(fileName)) { return String.Format(CultureInfo.CurrentCulture, Strings.AvoidUsingConvertToSecureStringWithPlainTextErrorScriptDefinition); } else { return String.Format(CultureInfo.CurrentCulture, Strings.AvoidUsingConvertToSecureStringWithPlainTextError, System.IO.Path.GetFileName(fileName)); } } /// /// GetName: Retrieves the name of this rule. /// /// The name of this rule public override string GetName() { return string.Format(CultureInfo.CurrentCulture, Strings.NameSpaceFormat, GetSourceName(), Strings.AvoidUsingConvertToSecureStringWithPlainTextName); } /// /// GetCommonName: Retrieves the common name of this rule. /// /// The common name of this rule public override string GetCommonName() { return string.Format(CultureInfo.CurrentCulture, Strings.AvoidUsingConvertToSecureStringWithPlainTextCommonName); } /// /// GetDescription: Retrieves the description of this rule. /// /// The description of this rule public override string GetDescription() { return string.Format(CultureInfo.CurrentCulture, Strings.AvoidUsingConvertToSecureStringWithPlainTextDescription); } /// /// GetSourceType: Retrieves the type of the rule: builtin, managed or module. /// public override SourceType GetSourceType() { return SourceType.Builtin; } /// /// GetSeverity: Retrieves the severity of the rule: error, warning or information. /// /// public override RuleSeverity GetSeverity() { return RuleSeverity.Error; } /// /// DiagnosticSeverity: Retrieves the severity of the rule of type DiagnosticSeverity: error, warning or information. /// /// public override DiagnosticSeverity GetDiagnosticSeverity() { return DiagnosticSeverity.Error; } /// /// GetSourceName: Retrieves the module/assembly name the rule is from. /// public override string GetSourceName() { return string.Format(CultureInfo.CurrentCulture, Strings.SourceName); } } }