Analyzer::Elixir::PhoenixChannel
Inherits Analyzer < FileHelper < Reference < Object
Surfaces Phoenix Channels real-time attack surface as ws://
endpoints. A channel module (use Phoenix.Channel / use MyAppWeb, :channel) handles client messages via handle_in/3 clauses; the
socket module maps a topic pattern to the channel with
channel "room:*", RoomChannel. Each handle_in event becomes one
endpoint ws://<topic>/<event> (bare ws://<topic> when a channel has
no handle_in clauses), method "SEND", protocol "ws" — so the existing
WebsocketTagger tags them.
Line-scan analyzer. The topic↔module map lives in the socket module
while handle_in clauses live in the channel module, so channel
declarations are collected across every .ex file first, then joined
onto each channel module.
Constants
channel "room:*", RoomChannel / channel "room:" <> _, MyApp.RoomChannel.
A channel module opts into the behaviour with one of these.
defmodule MyAppWeb.RoomChannel do.
handle_in("new_msg", payload, socket) / handle_in "ping", _p, socket.
A catch-all handle_in(_event, ...) has no string literal, so it is
skipped.
Class methods
Instance methods
Instance-side view of the same declaration. The per-file rescues live on
this base class, which has no way to name the analyzer that is running
inside them, so a skipped file could not be attributed to a tech.
Deriving it from analyzer_for keeps the name written exactly once.