MCPcopy Create free account
hub / github.com/AnukarOP/claude-code-leaked / transformStatement

Function transformStatement

source code/utils/powershell/parser.ts:1004–1105  ·  view source on GitHub ↗
(raw: RawStatement)

Source from the content-addressed store, hash-verified

1002/** Transform a raw statement into ParsedStatement */
1003// exported for testing
1004export function transformStatement(raw: RawStatement): ParsedStatement {
1005 const statementType = mapStatementType(raw.type)
1006 const commands: ParsedCommandElement[] = []
1007 const redirections: ParsedRedirection[] = []
1008
1009 if (raw.elements) {
1010 // PipelineAst: walk pipeline elements
1011 for (const elem of ensureArray(raw.elements)) {
1012 if (elem.type === 'CommandAst') {
1013 commands.push(transformCommandAst(elem))
1014 for (const redir of ensureArray(elem.redirections)) {
1015 redirections.push(transformRedirection(redir))
1016 }
1017 } else {
1018 commands.push(transformExpressionElement(elem))
1019 // SECURITY: CommandExpressionAst also carries .Redirections (inherited
1020 // from CommandBaseAst). `1 > /tmp/evil.txt` is a CommandExpressionAst
1021 // with a FileRedirectionAst. Must extract here or getFileRedirections()
1022 // misses it and compound commands like `Get-ChildItem; 1 > /tmp/x`
1023 // auto-allow at step 5 (only Get-ChildItem is checked).
1024 for (const redir of ensureArray(elem.redirections)) {
1025 redirections.push(transformRedirection(redir))
1026 }
1027 }
1028 }
1029 // SECURITY: The PS1 PipelineAst branch does a deep FindAll for
1030 // FileRedirectionAst to catch redirections hidden inside:
1031 // - colon-bound ParenExpressionAst args: -Name:('payload' > file)
1032 // - hashtable value statements: @{k='payload' > ~/.bashrc}
1033 // Both are invisible at the element level — the redirection's parent
1034 // is a child of CommandParameterAst / CommandExpressionAst, not a
1035 // separate pipeline element. Merge into statement-level redirections.
1036 //
1037 // The FindAll ALSO re-discovers direct-element redirections already
1038 // captured in the per-element loop above. Dedupe by (operator, target)
1039 // so tests and consumers see the real count.
1040 const seen = new Set(redirections.map(r => `${r.operator}\0${r.target}`))
1041 for (const redir of ensureArray(raw.redirections)) {
1042 const r = transformRedirection(redir)
1043 const key = `${r.operator}\0${r.target}`
1044 if (!seen.has(key)) {
1045 seen.add(key)
1046 redirections.push(r)
1047 }
1048 }
1049 } else {
1050 // Non-pipeline statement: add synthetic command entry with full text
1051 commands.push({
1052 name: raw.text,
1053 nameType: 'unknown',
1054 elementType: 'CommandExpressionAst',
1055 args: [],
1056 text: raw.text,
1057 })
1058 // SECURITY: The PS1 else-branch does a direct recursive FindAll on
1059 // FileRedirectionAst to catch expression redirections inside control flow
1060 // (if/for/foreach/while/switch/try/trap/&& and ||). The CommandAst FindAll
1061 // above CANNOT see these: in if ($x) { 1 > /tmp/evil }, the literal 1 with

Callers

nothing calls this directly

Calls 7

mapStatementTypeFunction · 0.85
ensureArrayFunction · 0.85
transformCommandAstFunction · 0.85
transformRedirectionFunction · 0.85
hasMethod · 0.45
addMethod · 0.45

Tested by

no test coverage detected