Skip to content

Allow SecRuleScript without actions and stop parser state bleed into next rule - #3627

Open
fzipi with Copilot wants to merge 4 commits into
v3/masterfrom
copilot/fix-secrulescript-disruptive-actions
Open

fzipi with Copilot wants to merge 4 commits into
v3/masterfrom
copilot/fix-secrulescript-disruptive-actions

Fix parsing of unquoted SecRuleScript actions

195b689
Select commit
Loading
Failed to load commit list.
SonarQubeCloud / SonarCloud Code Analysis succeeded Sep 18, 2026 in 3m 32s

Annotations

Check failure on line 2448 in src/parser/seclang-parser.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Use the "nullptr" literal.

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgZ5Dsf95qEvR2nI&open=AaChpgZ5Dsf95qEvR2nI&pullRequest=3627

Check warning on line 7123 in src/parser/seclang-parser.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this C-style array with "std::vector" (for dynamic size), or "std::array" (for static size)

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgZ5Dsf95qEvR2nK&open=AaChpgZ5Dsf95qEvR2nK&pullRequest=3627

Check warning on line 2452 in src/parser/seclang-parser.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Use "std::make_unique" to construct "std::unique_ptr".

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgZ5Dsf95qEvR2nH&open=AaChpgZ5Dsf95qEvR2nH&pullRequest=3627

Check warning on line 8264 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Remove these redundant parentheses.

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaC1VeaVTRWCblpTEIgt&open=AaC1VeaVTRWCblpTEIgt&pullRequest=3627

Check warning on line 932 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this C-style array with "std::vector" (for dynamic size), or "std::array" (for static size)

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgQSDsf95qEvR2m9&open=AaChpgQSDsf95qEvR2m9&pullRequest=3627

Check warning on line 8157 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Remove these redundant parentheses.

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaC1VeaVTRWCblpTEIgs&open=AaC1VeaVTRWCblpTEIgs&pullRequest=3627

Check warning on line 8308 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

The code of this "case" is a duplicate; join the "case" blocks or refactor so that all "case" blocks are unique.

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgQSDsf95qEvR2nD&open=AaChpgQSDsf95qEvR2nD&pullRequest=3627

Check warning on line 8270 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Remove these redundant parentheses.

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaC1VeaVTRWCblpTEIgu&open=AaC1VeaVTRWCblpTEIgu&pullRequest=3627

Check warning on line 446 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this C-style array with "std::vector" (for dynamic size), or "std::array" (for static size)

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgQSDsf95qEvR2m7&open=AaChpgQSDsf95qEvR2m7&pullRequest=3627

Check warning on line 6985 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Remove these redundant parentheses.

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgQSDsf95qEvR2nF&open=AaChpgQSDsf95qEvR2nF&pullRequest=3627

Check warning on line 3365 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this C-style array with "std::vector" (for dynamic size), or "std::array" (for static size)

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaC1VeaVTRWCblpTEIgp&open=AaC1VeaVTRWCblpTEIgp&pullRequest=3627

Check warning on line 1400 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this C-style array with "std::vector" (for dynamic size), or "std::array" (for static size)

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgQSDsf95qEvR2m-&open=AaChpgQSDsf95qEvR2m-&pullRequest=3627

Check warning on line 919 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this C-style array with "std::vector" (for dynamic size), or "std::array" (for static size)

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgQSDsf95qEvR2m8&open=AaChpgQSDsf95qEvR2m8&pullRequest=3627

Check warning on line 8314 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

The code of this "case" is a duplicate; join the "case" blocks or refactor so that all "case" blocks are unique.

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaC1VeaVTRWCblpTEIgr&open=AaC1VeaVTRWCblpTEIgr&pullRequest=3627

Check warning on line 7988 in src/parser/seclang-parser.hh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this C-style array with "std::vector" (for dynamic size), or "std::array" (for static size)

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgXjDsf95qEvR2nG&open=AaChpgXjDsf95qEvR2nG&pullRequest=3627

Check failure on line 5380 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Refactor this code to not nest more than 3 if|for|do|while|switch statements.

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaC1VeaVTRWCblpTEIgq&open=AaC1VeaVTRWCblpTEIgq&pullRequest=3627

Check failure on line 438 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this macro by "const", "constexpr" or an "enum".

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgQSDsf95qEvR2m6&open=AaChpgQSDsf95qEvR2m6&pullRequest=3627

Check warning on line 6979 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Remove these redundant parentheses.

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgQSDsf95qEvR2nE&open=AaChpgQSDsf95qEvR2nE&pullRequest=3627

Check warning on line 4868 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this C-style array with "std::vector" (for dynamic size), or "std::array" (for static size)

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgQSDsf95qEvR2nB&open=AaChpgQSDsf95qEvR2nB&pullRequest=3627

Check warning on line 1868 in src/parser/seclang-scanner.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this C-style array with "std::vector" (for dynamic size), or "std::array" (for static size)

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgQSDsf95qEvR2m_&open=AaChpgQSDsf95qEvR2m_&pullRequest=3627

Check failure on line 2449 in src/parser/seclang-parser.cc

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Use the "nullptr" literal.

See more on https://sonarcloud.io/project/issues?id=owasp-modsecurity_ModSecurity&issues=AaChpgZ5Dsf95qEvR2nJ&open=AaChpgZ5Dsf95qEvR2nJ&pullRequest=3627