mirror of
https://github.com/nlohmann/json.git
synced 2026-10-03 05:00:30 +00:00
Fix Flawfinder: format the BSON element type without snprintf
Moving the report of an unsupported BSON element type into skip_unsupported_bson_element() moved its snprintf() call, which Flawfinder then reported as a new CWE-134 finding. The two hexadecimal digits are now computed directly; the message is unchanged. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
@@ -401,9 +401,13 @@ class binary_reader
|
||||
*/
|
||||
bool skip_unsupported_bson_element(const char_int_type element_type, const std::size_t element_type_parse_position)
|
||||
{
|
||||
std::array<char, 3> cr{{}};
|
||||
static_cast<void>((std::snprintf)(cr.data(), cr.size(), "%.2hhX", static_cast<unsigned char>(element_type))); // NOLINT(cppcoreguidelines-pro-type-vararg,hicpp-vararg)
|
||||
const std::string cr_str{cr.data()};
|
||||
// the type as two uppercase hexadecimal digits, without a format string
|
||||
const auto type_byte = static_cast<unsigned int>(static_cast<unsigned char>(element_type));
|
||||
const auto hex_digit = [](const unsigned int digit)
|
||||
{
|
||||
return static_cast<char>(digit < 10 ? '0' + digit : 'A' + (digit - 10));
|
||||
};
|
||||
const std::string cr_str{hex_digit(type_byte >> 4u), hex_digit(type_byte & 0x0Fu)};
|
||||
const auto error = parse_error::create(114, element_type_parse_position, concat("Unsupported BSON record type 0x", cr_str), nullptr);
|
||||
|
||||
// the number of bytes to skip, -1 if the value is read differently, or
|
||||
|
||||
@@ -13795,9 +13795,13 @@ class binary_reader
|
||||
*/
|
||||
bool skip_unsupported_bson_element(const char_int_type element_type, const std::size_t element_type_parse_position)
|
||||
{
|
||||
std::array<char, 3> cr{{}};
|
||||
static_cast<void>((std::snprintf)(cr.data(), cr.size(), "%.2hhX", static_cast<unsigned char>(element_type))); // NOLINT(cppcoreguidelines-pro-type-vararg,hicpp-vararg)
|
||||
const std::string cr_str{cr.data()};
|
||||
// the type as two uppercase hexadecimal digits, without a format string
|
||||
const auto type_byte = static_cast<unsigned int>(static_cast<unsigned char>(element_type));
|
||||
const auto hex_digit = [](const unsigned int digit)
|
||||
{
|
||||
return static_cast<char>(digit < 10 ? '0' + digit : 'A' + (digit - 10));
|
||||
};
|
||||
const std::string cr_str{hex_digit(type_byte >> 4u), hex_digit(type_byte & 0x0Fu)};
|
||||
const auto error = parse_error::create(114, element_type_parse_position, concat("Unsupported BSON record type 0x", cr_str), nullptr);
|
||||
|
||||
// the number of bytes to skip, -1 if the value is read differently, or
|
||||
|
||||
Reference in New Issue
Block a user