Skip to content

BSL006 — Using hardcode file paths in code

Summary

Using hardcode file paths in code

Identifiers

Field Value
Rule code BSL006
Compatible alias UsingHardcodePath
Severity WARNING
Enabled by default Yes
Implemented Yes
Tags security, hardware-related

Behavior

  • The public identifier BSL006 and alias UsingHardcodePath are stable.
  • The rule reports the cases documented on this page.
  • Suppressions and project configuration are applied before publication.
  • The rule requires neither an external analyzer nor network access.

Configuration and suppression

BSL### is the primary stable identifier. The compatible alias is accepted in select, ignore, and compatible block suppression comments.

[tool.onec-hbk-bsl]
select = ["BSL006"]
ignore = ["UsingHardcodePath"]

All three suppression families support both a current line and a range. When an opening comment follows code, it affects only that line. Use any one form:

  • noqa:
Value = "example";  // noqa: BSL006
  • bsl-disable:
Value = "example";  // bsl-disable: BSL006
  • compatible BSLLS form:
Value = "example";  // BSLLS:UsingHardcodePath-off

When the same opening comment is on a line by itself, it starts a range. Close it with the matching marker from the same family:

// noqa: BSL006
// code without this diagnostic
// noqa-enable: BSL006

// bsl-disable: BSL006
// code without this diagnostic
// bsl-enable: BSL006

// BSLLS:UsingHardcodePath-off
// code without this diagnostic
// BSLLS:UsingHardcodePath-on

To disable the rule until the end of the file, omit the closing noqa-enable, bsl-enable, or BSLLS:…-on marker.

Opening and closing markers must belong to the same family.

Description

It's forbidden to store in code:

  • Paths to files and folders (Windows, Unix)

There are several ways to correctly store this information:

  • Store in Constants.
  • Store in Information registers.
  • Store in separate module, where this diagnostic is disabled (not recommended).
  • Store in Catalog, Exchange plan node and etc.

Nuances

When search for Windows / Unix paths, also check for URL in a string. URL search keywords: * http * https * ftp

Examples

Incorrect:

EchangeFolder = "c:/exchange/dataexchange";

Correct:

ExchangeFolder = Constants.ExchangeFolder.Get();

or

ExchangeFolder = DataExchangeReuse.ExchangeFolder();