|
36 | 36 | * options nest again (`headers`, `cookieDomainRewrite`), and `configure` |
37 | 37 | * takes a function whose body carries braces of its own. A `host` written |
38 | 38 | * below one of those is a miss, and the audit is what covers it. |
| 39 | + * - A positional port may wrap one call (`Number(process.env.PORT || 0)`); |
| 40 | + * a port expression nesting parentheses deeper hides the bind. |
39 | 41 | * - Outside `ws`, it matches only an explicit loopback host. A listener that |
40 | 42 | * binds every interface (`.listen(port)` with no host) is a different and |
41 | 43 | * larger problem, and `relay/` does it deliberately from config, so |
@@ -127,7 +129,7 @@ const NESTED_KEYS = '(?:[^{}]|\\{(?:[^{}]|\\{[^{}]*\\})*\\})*?'; |
127 | 129 | * exercises is a claim, not a check. |
128 | 130 | */ |
129 | 131 | const BIND_FORMS = [ |
130 | | - { label: 'node, positional', re: `\\.listen\\(\\s*[^,)]+,\\s*${LOOPBACK}` }, |
| 132 | + { label: 'node, positional', re: `\\.listen\\(\\s*(?:[^,()]|\\([^()]*\\))+,\\s*${LOOPBACK}` }, |
131 | 133 | { label: 'node, options object', re: `\\.listen\\(\\s*\\{[^}]*?host\\s*:\\s*${LOOPBACK}` }, |
132 | 134 | { label: '@hono/node-server', re: `\\bserve\\(\\s*\\{[^}]*?hostname\\s*:\\s*${LOOPBACK}` }, |
133 | 135 | { label: 'ws, explicit loopback host', re: `${WS_NEW}host\\s*:\\s*${LOOPBACK}` }, |
|
0 commit comments