v3.0.15
Fix buffer overflow in hex_decode.cc
Harden Base64 error handling and add hash/base64 unit coverage
Added const reported by cppcheck 2.14
Add cppcheck suppressions for false positives
Use default keyword to implement constructor/destructor - Addresses SonarCloud cpp:S3490 issue (Special member function should not be defined unless a non standard behavior is required)
feat: added Lua5.5 support
Remove shadowed variables befor loops
fix: unhandled exception in parser
Change conditions' order; cast isdigit()'s argument
Update remote_user.cc
Merge branch 'v3/master' into v3/master-mbedtl-v4
Apply suggestions from code review
Removed unnecessary usage of heap-allocated VariableValue (m_var) - Removed unused methods
Changes copyright dates on the code
Minor codebase improvements suggested by Sonarcloud - src/modsecurity.cc - Replace the redundant type with "auto". - src/transaction.cc - Avoid this unnecessary copy by using a "const" reference. - test/common/custom_debug_log.cc - Use "=default" instead of the default implementation of this special member functions. - Removed the unnecessary destructor override instead. - Annotate this function with "override" or "final". - Removed the unnecessary destructor override instead. - Remove this "const" qualifier from the return type in all declarations. - test/common/modsecurity_test_context.h - Replace the redundant type with "auto". - test/regression/regression.cc - Use the "nullptr" literal. - Replace this declaration by a structured binding declaration. - Replace "reinterpret_cast" with a safer operation.
Avoid passing RuleMessage by std::shared_ptr and use a reference instead. - Avoids copying std::shared_ptr when lifetime of the RuleMessage is controlled by the caller. - The RuleMessage instance is created in RuleWithActions::evaluate and then used to call the overloaded version of this method that is specialized by subclasses. - Once the call to the overloaded method returns, the std::shared_ptr is destroyed as it's not stored by any of the callers, so it can be replaced with a stack variable and avoid paying the cost of copying the std::shared_ptr (and its control block that is guaranteed to be thread-safe and thus is not a straightforward pointer copy) - Introduced RuleMessage::reset because this is required by RuleWithActions::performLogging when it's not the 'last log', the rule has multimatch and it's to be logged. - The current version is creating allocating another instance of RuleMessage on the heap to copy the Rule & Transaction related state while all the other members in the RuleMessage are set to their default values. - The new version leverages the existent, unused and incomplete function 'clean' (renamed as 'reset') to do this on the current instance. - Notice that the current code preserves the value of m_saveMessage, so 'reset' provides an argument for the caller to control whether this member should be reinitialized.
Eliminate compiler type mismatch warnings
Make function argument const pointer
Make getParserError() to const (cppcheck warnings in rules_set code)
Replace usage of range-checked 'at' method when vector/string has already been size checked
Move variable to inner block (rules_set_properties.cc)
leverage std::make_unique & std::make_shared - Simpler code & more efficient because control block can be allocated with object.
Merge branch 'v3/master' into v3/add-is-interrupted-to-json-log