(code: string)
| 41 | * @returns Detection result with list of found functions and their locations |
| 42 | */ |
| 43 | export function detectSensitiveFunctions(code: string): SensitiveDataDetection { |
| 44 | const detectedFunctions: string[] = []; |
| 45 | const lineNumbers: Record<string, number[]> = {}; |
| 46 | |
| 47 | if (!code || typeof code !== 'string') { |
| 48 | return { |
| 49 | hasSensitiveData: false, |
| 50 | detectedFunctions: [], |
| 51 | lineNumbers: {} |
| 52 | }; |
| 53 | } |
| 54 | |
| 55 | // Split code into lines for line number tracking |
| 56 | const lines = code.split('\n'); |
| 57 | |
| 58 | // Check each sensitive function |
| 59 | for (const funcName of SENSITIVE_FUNCTIONS) { |
| 60 | // Create regex to match function calls |
| 61 | // Matches: funcName( with optional whitespace |
| 62 | const regex = new RegExp(`\\b${funcName}\\s*\\(`, 'g'); |
| 63 | |
| 64 | // Track line numbers where this function appears |
| 65 | const foundLines: number[] = []; |
| 66 | |
| 67 | lines.forEach((line, index) => { |
| 68 | if (regex.test(line)) { |
| 69 | foundLines.push(index + 1); // Line numbers start at 1 |
| 70 | } |
| 71 | }); |
| 72 | |
| 73 | if (foundLines.length > 0) { |
| 74 | detectedFunctions.push(funcName); |
| 75 | lineNumbers[funcName] = foundLines; |
| 76 | } |
| 77 | } |
| 78 | |
| 79 | return { |
| 80 | hasSensitiveData: detectedFunctions.length > 0, |
| 81 | detectedFunctions, |
| 82 | lineNumbers |
| 83 | }; |
| 84 | } |
| 85 | |
| 86 | /** |
| 87 | * Get human-readable description of what data type a function may contain |
no test coverage detected