Documentation
¶
Overview ¶
Package analyzers holds every detector behind `gofastr verify`.
The rules themselves, IDs, severities, the Why and the Fix, live in github.com/DonaldMurillo/gofastr/framework/contracts. This package only finds the code. That split is deliberate: the catalog has to be readable and serveable (over MCP, in docs) without dragging in a Go parser, and an analyzer has to be replaceable without touching the documentation contract it satisfies.
Analyzers here are AST-based rather than type-checked. The trade is explicit: a type-checked pass would be more precise and would need a full `go/packages` load of the module, which costs seconds and fails outright on a project that does not compile. Verify has to be useful mid-edit, so precision is bought back with narrow patterns and suppression rather than with types.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func AuthWiring ¶
AuthWiring reports whether the module configures auth and whether anything reads it.
Types ¶
type EntityDecl ¶
EntityDecl is one `app.Entity(...)` / `GroupEntity(...)` call.
type EntityInfo ¶
type EntityInfo struct {
Name string
Fields []string
// FieldsResolved is false when Fields came from a helper call rather
// than a literal slice. The scoping rules stay quiet in that case:
// they cannot see the columns, and guessing would mean either false
// findings or a false all-clear.
FieldsResolved bool
CRUDDisabled bool
MCP bool
Public bool
HasAccess bool
OwnerField string
MultiTenant bool
// AccessPermissions are the permission strings the entity's Access
// block names. These are the permissions least likely to be exercised
// by accident: nothing in the app calls them by name, so only a real
// request through the CRUD layer can prove them.
AccessPermissions []string
File string
Line int
Pos token.Pos
}
EntityInfo is what the static pass can recover from an entity registration. It is a subset of framework/entity.EntityConfig, only the fields that decide exposure and scoping, read straight off the composite literal.
func Entities ¶
func Entities(p *contracts.Pass) []EntityInfo
Entities returns every statically readable entity registration.
func (EntityInfo) Exposed ¶
func (e EntityInfo) Exposed() bool
Exposed reports whether the entity has a generated surface at all. CRUD defaults to on, so only an explicit false turns it off.
func (EntityInfo) Scoped ¶
func (e EntityInfo) Scoped() bool
Scoped reports whether the entity limits which rows a caller can reach.
type EventSub ¶
type EventSub struct {
// Type is the event type string the handler listens for.
Type string
File string
Line int
Pos token.Pos
}
EventSub is one statically discovered event subscription.
type HookDecl ¶
type HookDecl struct {
// Entity is the entity name the hook is attached to.
Entity string
// Type is the lifecycle point, lower-cased to match the manifest
// ("beforecreate", "afterupdate", …).
Type string
File string
Line int
Pos token.Pos
}
HookDecl is one statically discovered lifecycle-hook registration.
type RoleGrant ¶
type RoleGrant struct {
// Role is the role name granted permissions.
Role string
File string
Line int
Pos token.Pos
}
RoleGrant is one statically discovered role definition.
type Route ¶
type Route struct {
// Method is the HTTP verb exactly as written, case included, since a
// lowercase one is a finding rather than something to normalise away.
Method string
// Pattern is the full path with any resolvable group prefix applied.
Pattern string
// RawPattern is the literal passed at the call site, before prefixing.
RawPattern string
// Group is the receiver identifier, "" for a direct router call.
Group string
// Guarded is true when the route was registered on a group carrying
// access or middleware, which is the framework's guarding seam.
Guarded bool
// Handler is the handler expression, for evidence.
Handler string
// Screen marks a route declared through `app.NewScreen`. Screens are
// matched by core-ui's own router, NOT by ServeMux, and that router
// takes `:id` parameters natively. It even rewrites `{id}` into
// `:id`. Every rule about ServeMux pattern syntax must therefore skip
// them, or it reports the correct spelling as a bug.
Screen bool
// Package is the import path of the registering package. Duplicate
// detection is scoped by it: two example apps in one repository both
// serving "/healthz" are not a conflict, they are two programs.
Package string
File string
Line int
Col int
Pos token.Pos
}
Route is one statically discovered registration.
type RouteTable ¶
type RouteTable struct {
Routes []Route
Entities []EntityDecl
// Registered is true when at least one registration was found,
// distinguishing "no routes" from "this project does not register
// routes in a way the static pass can see". Analyzers stay quiet in
// the second case rather than reporting an empty app.
Registered bool
}
RouteTable is everything the static pass could learn about the app's surface. It is memoized on the pass, so the routing, permissions, testing, and guidance analyzers all read one traversal.
func Routes ¶
func Routes(p *contracts.Pass) *RouteTable
Routes returns the pass's route table, computing it at most once.