forked from aws-cloudformation/cfn-lint
-
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat(conditions) - Add rule W8003 to check if Equals will always be t…
…rue or false (aws-cloudformation#2426) * add rule W8003 to check if Equals will always be true or false
- Loading branch information
Showing
7 changed files
with
111 additions
and
3 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,44 @@ | ||
""" | ||
Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. | ||
SPDX-License-Identifier: MIT-0 | ||
""" | ||
import json | ||
from cfnlint.rules import CloudFormationLintRule | ||
from cfnlint.rules import RuleMatch | ||
|
||
|
||
class EqualsIsUseful(CloudFormationLintRule): | ||
"""Validate that the Equals will return true/false and not always be true or false""" | ||
|
||
id = 'W8003' | ||
shortdesc = 'Fn::Equals will always return true or false' | ||
description = 'Validate Fn::Equals to see if its comparing two strings or two equal items. While this works it may not be intended.' | ||
source_url = 'https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/intrinsic-function-reference-conditions.html#intrinsic-function-reference-conditions-equals' | ||
tags = ['functions', 'equals'] | ||
|
||
function = 'Fn::Equals' | ||
|
||
def _check_equal_values(self, values, path): | ||
matches = [] | ||
|
||
if json.dumps(values[0]) == json.dumps(values[1]): | ||
message = self.function + ' element will alway return true' | ||
matches.append(RuleMatch(path, message)) | ||
elif isinstance(values[0], str) and isinstance(values[1], str): | ||
message = self.function + ' element will alway return false' | ||
matches.append(RuleMatch(path, message)) | ||
return matches | ||
|
||
def match(self, cfn): | ||
matches = [] | ||
# Build the list of functions | ||
trees = cfn.search_deep_keys(self.function) | ||
|
||
for tree in trees: | ||
# Test when in Conditions | ||
if tree[0] == 'Conditions': | ||
value = tree[-1] | ||
if isinstance(value, list) and len(value) == 2: | ||
matches.extend(self._check_equal_values(value, tree[:-1])) | ||
|
||
return matches |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
11 changes: 11 additions & 0 deletions
11
test/fixtures/templates/bad/conditions/equals_not_useful.yaml
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,11 @@ | ||
--- | ||
AWSTemplateFormatVersion: "2010-09-09" | ||
Parameters: | ||
Environment: | ||
Type: String | ||
Default: dev | ||
Conditions: | ||
IsTrue: !Equals ['true', 'true'] | ||
IsFalse: !Equals ['true', 'false'] | ||
IsDevEnvironment: !Equals [!Ref Environment, !Ref Environment] | ||
Resources: {} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,25 @@ | ||
""" | ||
Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. | ||
SPDX-License-Identifier: MIT-0 | ||
""" | ||
from test.unit.rules import BaseRuleTestCase | ||
from cfnlint.rules.conditions.EqualsIsUseful import EqualsIsUseful # pylint: disable=E0401 | ||
|
||
|
||
class TestEqualsIsUseful(BaseRuleTestCase): | ||
"""Test template mapping configurations""" | ||
|
||
def setUp(self): | ||
"""Setup""" | ||
super(TestEqualsIsUseful, self).setUp() | ||
self.collection.register(EqualsIsUseful()) | ||
|
||
success_templates = [] | ||
|
||
def test_file_positive(self): | ||
"""Test Positive""" | ||
self.helper_file_positive() | ||
|
||
def test_file_negative(self): | ||
"""Test failure""" | ||
self.helper_file_negative('test/fixtures/templates/bad/conditions/equals_not_useful.yaml', 3) |