如何修复遗留代码中SQL查询来自外部时的CA2100安全警告?
解决CA2100冗余安全警告的方案
方案1:重构Read方法接收OleDbCommand对象
把Read方法的参数从string sqlQuery改为OleDbCommand,让外部代码负责构建命令对象,这样代码分析工具会认为命令的构建是受控的,不会触发注入警告,同时也没有把查询逻辑移到Read内部。
修改后的完整代码:
class Program { static void Main () { string connectionString = @"Provider=Microsoft.Jet.OLEDB.4.0;Data Source=D:\Newfolder\database1.mdb"; using (OleDbConnection connection = new OleDbConnection(connectionString)) { try { connection.Open(); string strsql = "SELECT * FROM Table1"; // 外部构建OleDbCommand OleDbCommand queryCmd = new OleDbCommand(strsql, connection); Read(queryCmd); } catch(Exception ex) { Console.WriteLine(ex.Message); } } } static void Read (OleDbCommand command) { OleDbDataReader reader = command.ExecuteReader(); while (reader.Read()) { Console.WriteLine(reader["PName"]); } } }
方案2:添加安全分析属性(仅确认所有传入SQL绝对安全时使用)
如果能保证所有调用Read方法的sqlQuery都是硬编码、无用户输入的安全语句,可以在Read方法上添加SuppressMessage属性,明确标记该警告为冗余:
[System.Diagnostics.CodeAnalysis.SuppressMessage("Microsoft.Security", "CA2100:Review SQL queries for security vulnerabilities", Justification = "所有传入的SQL均为硬编码的安全查询,无任何用户输入参与")] static void Read (OleDbConnection connection,string sqlQuery) { OleDbCommand command = new OleDbCommand(); command.Connection = connection; command.CommandText = sqlQuery; OleDbDataReader reader = command.ExecuteReader(); while (reader.Read()) { Console.WriteLine(reader["PName"]); } }
注意:此方法仅限完全可控的场景,若后续有调用传入用户生成的SQL,会直接引入注入风险。
内容的提问来源于stack exchange,提问作者Tahir Abbas
相关产品推荐
相关产品推荐

