Skip to content

BSL261 — Unsafe SafeMode method call

Summary

Unsafe SafeMode method call

Identifiers

Field Value
Rule code BSL261
Compatible alias UnsafeSafeModeMethodCall
Severity WARNING
Enabled by default Yes
Implemented Yes
Tags security, correctness

Behavior

  • The public identifier BSL261 and alias UnsafeSafeModeMethodCall are stable.
  • The rule reports the cases documented on this page.
  • Suppressions and project configuration are applied before publication.
  • The rule requires neither an external analyzer nor network access.

Configuration and suppression

BSL### is the primary stable identifier. The compatible alias is accepted in select, ignore, and compatible block suppression comments.

[tool.onec-hbk-bsl]
select = ["BSL261"]
ignore = ["UnsafeSafeModeMethodCall"]

All three suppression families support both a current line and a range. When an opening comment follows code, it affects only that line. Use any one form:

  • noqa:
Value = "example";  // noqa: BSL261
  • bsl-disable:
Value = "example";  // bsl-disable: BSL261
  • compatible BSLLS form:
Value = "example";  // BSLLS:UnsafeSafeModeMethodCall-off

When the same opening comment is on a line by itself, it starts a range. Close it with the matching marker from the same family:

// noqa: BSL261
// code without this diagnostic
// noqa-enable: BSL261

// bsl-disable: BSL261
// code without this diagnostic
// bsl-enable: BSL261

// BSLLS:UnsafeSafeModeMethodCall-off
// code without this diagnostic
// BSLLS:UnsafeSafeModeMethodCall-on

To disable the rule until the end of the file, omit the closing noqa-enable, bsl-enable, or BSLLS:…-on marker.

Opening and closing markers must belong to the same family.

Description

In "1C: Enterprise 8.3" the global context method SafeMode() returns the type String, if safe mode was set with the name of the security profile.

Using the SafeMode() method, in which the result is implicitly converted to a Boolean type is unsafe, must be corrected for the code with an explicit comparison of the result with the value False. Thus, with the installed security profile, the code will be executed in the same way as in the safe mode.

Examples

Incorrect:

If SafeMode() Then
     // some logic in safe mode...
EndIf;

If No SafeMode() Then
     // some logic in unsafe mode...
EndIf;

Correct:

If SafeMode() <> False Then
   // some code
EndIf;
EndIf

Sources