diff options
author | Carlos Antonio da Silva <carlosantoniodasilva@gmail.com> | 2013-11-15 01:03:07 -0200 |
---|---|---|
committer | Carlos Antonio da Silva <carlosantoniodasilva@gmail.com> | 2013-11-15 01:04:57 -0200 |
commit | 374d465f2894dc5b120cc6a5f28619a6e60407be (patch) | |
tree | 79e81551ea2fa8da205aa155bb87657bee1a3abe /activemodel | |
parent | 9014a79436c8585ac17c8c27d14f7467cddd3562 (diff) | |
download | rails-374d465f2894dc5b120cc6a5f28619a6e60407be.tar.gz rails-374d465f2894dc5b120cc6a5f28619a6e60407be.tar.bz2 rails-374d465f2894dc5b120cc6a5f28619a6e60407be.zip |
Invert conditional to avoid double checking for Regexp
Diffstat (limited to 'activemodel')
-rw-r--r-- | activemodel/lib/active_model/validations/format.rb | 23 |
1 files changed, 12 insertions, 11 deletions
diff --git a/activemodel/lib/active_model/validations/format.rb b/activemodel/lib/active_model/validations/format.rb index 488a498a41..f0fe22438f 100644 --- a/activemodel/lib/active_model/validations/format.rb +++ b/activemodel/lib/active_model/validations/format.rb @@ -32,23 +32,24 @@ module ActiveModel record.errors.add(attribute, :invalid, options.except(name).merge!(value: value)) end - def regexp_using_multiline_anchors?(regexp) - source = regexp.source - source.start_with?("^") || (source.end_with?("$") && !source.end_with?("\\$")) - end - def check_options_validity(name) if option = options[name] - if !option.is_a?(Regexp) && !option.respond_to?(:call) + if option.is_a?(Regexp) + if options[:multiline] != true && regexp_using_multiline_anchors?(option) + raise ArgumentError, "The provided regular expression is using multiline anchors (^ or $), " \ + "which may present a security risk. Did you mean to use \\A and \\z, or forgot to add the " \ + ":multiline => true option?" + end + elsif !option.respond_to?(:call) raise ArgumentError, "A regular expression or a proc or lambda must be supplied as :#{name}" - elsif option.is_a?(Regexp) && - regexp_using_multiline_anchors?(option) && options[:multiline] != true - raise ArgumentError, "The provided regular expression is using multiline anchors (^ or $), " \ - "which may present a security risk. Did you mean to use \\A and \\z, or forgot to add the " \ - ":multiline => true option?" end end end + + def regexp_using_multiline_anchors?(regexp) + source = regexp.source + source.start_with?("^") || (source.end_with?("$") && !source.end_with?("\\$")) + end end module HelperMethods |