BSL184 — Executing of external code in a common module on the server¶
Summary¶
Executing of external code in a common module on the server
Identifiers¶
| Field | Value |
|---|---|
| Rule code | BSL184 |
| Compatible alias | ExecuteExternalCodeInCommonModule |
| Severity | WARNING |
| Enabled by default | Yes |
| Implemented | Yes |
| Tags | security, module |
Behavior¶
- The public identifier
BSL184and aliasExecuteExternalCodeInCommonModuleare stable. - The rule reports the cases documented on this page.
- Suppressions and project configuration are applied before publication.
- The rule requires neither an external analyzer nor network access.
Configuration and suppression¶
BSL### is the primary stable identifier. The compatible alias is accepted
in select, ignore, and compatible block suppression comments.
All three suppression families support both a current line and a range. When an opening comment follows code, it affects only that line. Use any one form:
noqa:
bsl-disable:
- compatible
BSLLSform:
When the same opening comment is on a line by itself, it starts a range. Close it with the matching marker from the same family:
// noqa: BSL184
// code without this diagnostic
// noqa-enable: BSL184
// bsl-disable: BSL184
// code without this diagnostic
// bsl-enable: BSL184
// BSLLS:ExecuteExternalCodeInCommonModule-off
// code without this diagnostic
// BSLLS:ExecuteExternalCodeInCommonModule-on
To disable the rule until the end of the file, omit the closing
noqa-enable, bsl-enable, or BSLLS:…-on marker.
Opening and closing markers must belong to the same family.
Description¶
When you develop applications, note that not only execution of a code written in the Enterprise mode is unsafe, but also places, where the Execute or Eval methods are used to execute the code created based on parameters passed to server functions and procedures.
If the execution of arbitrary code Is necessary then it has to be preliminarily checked.
This restriction is not applicable to the code being executed on the client.