final class SinkFinder
Restricted visibility: declared "@visibility root". Code outside that scope must not name this declaration.

Finds every call that is written the way a database call is written.

Reading a statement and finding the call that carries it are separate jobs. A call whose statement cannot be reconstructed is still a place the program talks to a database, and a call nothing could be read from is a gap in the analysis rather than an absence in the program. This pass answers the second question on its own, so neither can be lost to a failure of the first.

Methods§

public function __construct()

Builds a finder over the node search.

Calls 1
public function find(ParsedFile $file, list<SinkSpec> $sinks): list<CallLike>
public function findAll(ParsedFile $file, list<SinkSpec> $sinks): list<CallLike>

The calls in a file written the way any database call is written, including those that only bind values.

Calls that compose a statement are left out: they hand the statement back rather than sending it, so they are read as part of whatever call does.

Parameters

$fileParsedFile
$sinkslist<SinkSpec>

Returns

list<CallLike>
Test cases 3
Called from 1
Calls 4
public function findIn(
    array<array-key, Node> $nodes,
    array<string, true> $names,
): list<CallLike>

The calls among the given nodes that are written the way a statement-carrying call is written.

Parameters

$nodesarray<array-key, Node>
$namesarray<string, true>

Returns

list<CallLike>
Test cases 1
Called from 2
Calls 4
public function namesOf(list<SinkSpec> $sinks): array<string, true>

The names the statement-carrying calls are written with.

Parameters

$sinkslist<SinkSpec>

Returns

array<string, true>
Test cases 2
Called from 1
Calls 5
public function enclosingBody(Node $node): ?FunctionLike

The function body a node is written inside, or null when it is written outside any.

Parameters

$nodeNode

Returns

?FunctionLike
Test cases 1
Calls 1
  • method-call Node::getAttribute() line 132

Private surface 1§

Implementation details, listed for orientation only.

private NodeFinder $finder

Test cases 35§

Test cases that cover or call this symbol, from the coverage report and from the analyzed test sources.

Dedicated tests 11
Other tests reaching this symbol 24

Relations§

Instantiated in 2
Method calls 4
Type declarations 1