class RuboCop::Cop::Lint::DeprecatedOpenSSLConstant

Algorithmic constants for ‘OpenSSL::Cipher` and `OpenSSL::Digest` deprecated since OpenSSL version 2.2.0. Prefer passing a string instead.

@example

# Example for OpenSSL::Cipher instantiation.

# bad
OpenSSL::Cipher::AES.new(128, :GCM)

# good
OpenSSL::Cipher.new('aes-128-gcm')

@example

# Example for OpenSSL::Digest instantiation.

# bad
OpenSSL::Digest::SHA256.new

# good
OpenSSL::Digest.new('SHA256')

@example

# Example for ::Digest inherited class methods.

# bad
OpenSSL::Digest::SHA256.digest('foo')

# good
OpenSSL::Digest.digest('SHA256', 'foo')

Constants

MSG
NO_ARG_ALGORITHM

Public Instance Methods

on_send(node) click to toggle source
# File lib/rubocop/cop/lint/deprecated_open_ssl_constant.rb, line 63
def on_send(node)
  return if node.arguments.any? { |arg| arg.variable? || arg.send_type? || arg.const_type? }
  return if digest_const?(node.receiver)
  return unless algorithm_const(node)

  message = message(node)

  add_offense(node, message: message) { |corrector| autocorrect(corrector, node) }
end

Private Instance Methods

algorithm_name(node) click to toggle source
# File lib/rubocop/cop/lint/deprecated_open_ssl_constant.rb, line 110
def algorithm_name(node)
  name = node.loc.name.source

  if openssl_class(node) == 'OpenSSL::Cipher' && !NO_ARG_ALGORITHM.include?(name)
    name.scan(/.{3}/).join('-')
  else
    name
  end
end
autocorrect(corrector, node) click to toggle source
# File lib/rubocop/cop/lint/deprecated_open_ssl_constant.rb, line 75
def autocorrect(corrector, node)
  algorithm_constant, = algorithm_const(node)

  corrector.remove(algorithm_constant.loc.double_colon)
  corrector.remove(algorithm_constant.loc.name)

  corrector.replace(
    correction_range(node),
    "#{node.loc.selector.source}(#{replacement_args(node)})"
  )
end
build_cipher_arguments(node, algorithm_name, no_arguments) click to toggle source
# File lib/rubocop/cop/lint/deprecated_open_ssl_constant.rb, line 139
def build_cipher_arguments(node, algorithm_name, no_arguments)
  algorithm_parts = algorithm_name.downcase.split('-')
  size_and_mode = sanitize_arguments(node.arguments).map(&:downcase)

  if NO_ARG_ALGORITHM.include?(algorithm_parts.first.upcase) && no_arguments
    "'#{algorithm_parts.first}'"
  else
    mode = 'cbc' unless size_and_mode == ['cbc']

    "'#{(algorithm_parts + size_and_mode + [mode]).compact.take(3).join('-')}'"
  end
end
correction_range(node) click to toggle source
# File lib/rubocop/cop/lint/deprecated_open_ssl_constant.rb, line 102
def correction_range(node)
  range_between(node.loc.dot.end_pos, node.loc.expression.end_pos)
end
message(node) click to toggle source
# File lib/rubocop/cop/lint/deprecated_open_ssl_constant.rb, line 87
def message(node)
  algorithm_constant, = algorithm_const(node)
  parent_constant = openssl_class(algorithm_constant)
  replacement_args = replacement_args(node)
  method = node.loc.selector.source

  format(
    MSG,
    constant: parent_constant,
    method: method,
    replacement_args: replacement_args,
    original: node.source
  )
end
openssl_class(node) click to toggle source
# File lib/rubocop/cop/lint/deprecated_open_ssl_constant.rb, line 106
def openssl_class(node)
  node.children.first.source
end
replacement_args(node) click to toggle source
# File lib/rubocop/cop/lint/deprecated_open_ssl_constant.rb, line 128
def replacement_args(node)
  algorithm_constant, = algorithm_const(node)
  algorithm_name = algorithm_name(algorithm_constant)

  if openssl_class(algorithm_constant) == 'OpenSSL::Cipher'
    build_cipher_arguments(node, algorithm_name, node.arguments.empty?)
  else
    (["'#{algorithm_name}'"] + node.arguments.map(&:source)).join(', ')
  end
end
sanitize_arguments(arguments) click to toggle source
# File lib/rubocop/cop/lint/deprecated_open_ssl_constant.rb, line 120
def sanitize_arguments(arguments)
  arguments.flat_map do |arg|
    argument = arg.str_type? ? arg.value : arg.source

    argument.tr(":'", '').split('-')
  end
end