Problem
is_doc_file() in security_scanner.rs uses rsplit(.).next() to extract the file extension. For a filename with no dot (e.g., org, tex, md), rsplit(.).next() returns the whole string — so is_doc_file("org") returns true.
Impact
| Input |
Expected |
Actual |
is_doc_file("README.md") |
true |
true ✅ |
is_doc_file("src/org") |
false |
true ❌ (Go package dir) |
is_doc_file("tex") |
false |
true ❌ (binary named tex) |
is_doc_file("CHANGELOG") |
false |
false ✅ |
Low real-world probability but logically incorrect.
Fix
Check that the path contains a . before extracting extension:
fn is_doc_file(path: &str) -> bool {
let ext = match path.rsplit('.').next() {
Some(e) if e.len() < path.len() => e, // Has a dot
_ => return false, // No dot, no extension
};
matches!(ext, "md" | "markdown" | "txt" | ...)
}
Related
Problem
is_doc_file()insecurity_scanner.rsusesrsplit(.).next()to extract the file extension. For a filename with no dot (e.g.,org,tex,md),rsplit(.).next()returns the whole string — sois_doc_file("org")returnstrue.Impact
is_doc_file("README.md")truetrue✅is_doc_file("src/org")falsetrue❌ (Go package dir)is_doc_file("tex")falsetrue❌ (binary named tex)is_doc_file("CHANGELOG")falsefalse✅Low real-world probability but logically incorrect.
Fix
Check that the path contains a
.before extracting extension:Related
is_doc_file()