{"id":2818,"date":"2022-08-24T10:15:01","date_gmt":"2022-08-24T10:15:01","guid":{"rendered":"https:\/\/sdf-docs.clevr.com\/?docs=acr\/custom-code-preview"},"modified":"2023-03-09T09:16:52","modified_gmt":"2023-03-09T09:16:52","slug":"custom-code-preview","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr\/custom-code-preview","title":{"rendered":"Custom code (preview)"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\" id=\"Introduction\"><strong>Introduction<\/strong><\/h1>\n\n\n\n<p>Mendix drastically simplifies the software development lifecycle through abstraction. Software quality is a part of this life cycle. The most significant risk for software quality is human error; by abstracting most of the code away from the developer (through building blocks), Mendix reduces the risk of human error and improves the overall software quality. Of course, connecting these components is still risky, but way less than designing everything from scratch. Now, why is this relevant?\u202f<\/p>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"Custom-code-in-Mendix-and-its-risks\"><strong>Custom code in Mendix and its risks<\/strong>&nbsp;<\/h1>\n\n\n\n<p>Within Mendix, you can also add<em>\u202fcustom code.<\/em>\u202fWhat is custom code? Custom code is every instance where a developer introduces Java or Javascript actions instead of using standard platform capabilities.\u202f&nbsp;<\/p>\n\n\n\n<p>Custom code is a significant risk in every Mendix application. It poses a quality risk because the responsibility of writing proper code falls on the Mendix developer instead of the Mendix platform (which is the case with platform components). Custom code can significantly impact quality, for example, using Java libraries that contain\u202f<a href=\"https:\/\/owasp.org\/Top10\/A06_2021-Vulnerable_and_Outdated_Components\/%22%20\/t%20%22_blank\"><u>security vulnerabilities<\/u><\/a>\u202for not escaping user input resulting in the risk of\u202f<a href=\"https:\/\/owasp.org\/Top10\/A03_2021-Injection\/%22%20\/t%20%22_blank\"><u>malicious injection<\/u><\/a>\u202fduring the runtime.&nbsp;<\/p>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"Custom-Code-feature-in-CDS\"><strong>Custom Code feature in CDS<\/strong><\/h1>\n\n\n\n<p>Inside CDS, we\u2019ve developed the feature <em>Custom code<\/em> that analyzes the customized high-code integrations of the Java and JavaScript actions in your Mendix application so that you get insight into your Java and JavaScript code quality. The evaluation of the code is executed through a well-known open-source code analyzer called <a href=\"https:\/\/pmd.github.io\/latest\/index.html\">PMD<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"How-it-works\">How it works<\/h2>\n\n\n\n<p>The moment you download a model for your revision, the <em>custom code<\/em> <em>feature<\/em> automatically starts analyzing your custom code. In a designated place (which we will show you below), CDS presents the results, providing you insight into its risk severity and coding categories like best practices, code style, and error-prone. To help you understand the potential impact of the vulnerability, we provide a link to PDM\u2019s documentation so that you can examine how to solve the issue. Of course, we present to you the location, the specific file and the line on which the violation occurs.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"Navigation-&amp;-Functionality\">Navigation &amp; Functionality<\/h2>\n\n\n\n<p>After downloading a model, you can access the <em>Custom code feature <\/em>from everywhere in CDS! Just navigate to the main menu and click on the curly brackets (<strong>{ }<\/strong>)<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"527\" height=\"761\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc1.png\" alt=\"\" class=\"wp-image-2821\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc1.png 527w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc1-480x693.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 527px, 100vw\" \/><\/figure><\/div>\n\n\n\n<p>When you open the <em>Custom Code<\/em> page, you see two tabs: one for Java vulneratbilities and one for JavaScript results.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Search-bar\">Search bar<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1006\" height=\"385\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc2.png\" alt=\"\" class=\"wp-image-2822\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc2.png 1006w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc2-980x375.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc2-480x184.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1006px, 100vw\" \/><\/figure>\n\n\n\n<p>Above the results, you find a search bar that is pretty extensive! It helps you filter the results by every data item in the list. These could be the violation\u2019s severity, categories, and keywords within rules (like \u201clocal\u201d, \u201cvariable\u201d or \u201cfoo\u201d), so feel free to play around with it (and let us know what you think!). When you hit enter, you could see your results after opening the file.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"List-of-contaminated-files\">List of contaminated files<\/h3>\n\n\n\n<p>Below the search box, you see a list of files (<em>.java<\/em> or <em>.js<\/em>) that contain potential risks. The file name is presented as the path starting from the <em>javasource<\/em> or <em>javascriptsource<\/em> folder in your Mendix project, so you can easily find the concerning file.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"351\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc3-1024x351.png\" alt=\"\" class=\"wp-image-2823\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc3-980x336.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc3-480x164.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Custom-Code-Violations\">Custom Code Violations<\/h3>\n\n\n\n<p>To open a file in the list, click anywhere on the item to expand it. It will show you violations in each of the files (Java\/JavaScript actions).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"313\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc4-1024x313.png\" alt=\"\" class=\"wp-image-2824\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc4-980x299.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc4-480x147.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n\n\n\n<p>As you can see in this example, the <code>ConvertGrantsToCommaSepString.java<\/code> file has 5 violations. Each violation is presented in a list of items with information about the violation\u2019s priority, rule, and category.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Violation-Details\">Violation Details<\/h3>\n\n\n\n<p>To see the details of a violation, simply click on them.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"331\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc5-1024x331.png\" alt=\"\" class=\"wp-image-2825\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc5-980x317.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/08\/cc5-480x155.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n\n\n\n<p>In the details section, the violation is shown in detail. Details of a violation include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Priority<\/strong>: The level of importance of the violation<\/li><li><strong>Rule<\/strong>: A brief description of the violation<\/li><li><strong>Category<\/strong>: The category of the violation provided by PMD:<ul><li><img decoding=\"async\" alt=\"\" src=\"blob:https:\/\/clevr.atlassian.net\/b3236018-0c2d-4c14-a40c-82ede76ad9b6#media-blob-url=true&amp;id=0e1fa647-574e-44fd-a0a9-60ee25a0f21e&amp;collection=contentId-3281846287&amp;contextId=3281846287&amp;mimeType=image%2Fpng&amp;name=image-20220819-143407.png&amp;size=4753&amp;height=180&amp;width=207&amp;alt=\">For more information about the rules and existing categories, see <a href=\"https:\/\/pmd.github.io\/latest\/pmd_rules_java.html\">Java<\/a> and <a href=\"https:\/\/pmd.github.io\/latest\/pmd_rules_ecmascript.html\">JavaScript<\/a><\/li><\/ul><\/li><li><strong>Description<\/strong>: Description of the specific rule<\/li><li><strong>Documentation<\/strong>: a reference to the rule\u2019s category in the code analyzer\u2019s (PMD) documentation<\/li><li><strong>Code snippet box<\/strong>: the place where you can see the code and its location in the file<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"Allowing-violations-via-annotations\">Allowing violations via annotations<\/h2>\n\n\n\n<p>Like every violation in CDS, custom code violations can also be annotated. However, this is done a bit differently. To read the full documentation on how to suppress warnings, go to <a href=\"https:\/\/pmd.github.io\/latest\/pmd_userdocs_suppressing_warnings.html\">Suppressing warnings | PMD Source Code Analyzer<\/a><\/p>\n\n\n\n<p>To provide a short overview:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Class-annotation\">Class annotation<\/h3>\n\n\n\n<p><code>\/\/ This will suppress all the PMD warnings in this class <\/code><\/p>\n\n\n\n<p><code>@SuppressWarnings(\"PMD\") <\/code><\/p>\n\n\n\n<p><code>public class Bar { <\/code><\/p>\n\n\n\n<p><code> void bar() { <\/code><\/p>\n\n\n\n<p><code> int foo; <\/code><\/p>\n\n\n\n<p><code> } <\/code><\/p>\n\n\n\n<p><code>}<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Annotate-a-single-rule-in-a-class\">Annotate a single rule in a class<\/h3>\n\n\n\n<p><code>\/\/ This will suppress UnusedLocalVariable warnings in this class @SuppressWarnings(\"PMD.UnusedLocalVariable\") <\/code><\/p>\n\n\n\n<p><code>public class Bar { <\/code><\/p>\n\n\n\n<p><code> void bar() { <\/code><\/p>\n\n\n\n<p><code> int foo; <\/code><\/p>\n\n\n\n<p><code> } <\/code><\/p>\n\n\n\n<p><code>}<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Annotate-multiple-rules-in-a-class\">Annotate multiple rules in a class<\/h3>\n\n\n\n<p><code>@SuppressWarnings({\"PMD.UnusedLocalVariable\", \"PMD.UnusedPrivateMethod\"})<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Annotate-a-line\">Annotate a line<\/h3>\n\n\n\n<p><code>public class Bar { <\/code><\/p>\n\n\n\n<p><code> \/\/ 'bar' is accessed by a native method, so we want to suppress warnings for it <\/code><\/p>\n\n\n\n<p><code> private int bar; \/\/NOPMD <\/code><\/p>\n\n\n\n<p><code>}<\/code><\/p>\n","protected":false},"featured_media":0,"parent":43,"menu_order":10,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-2818","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2818"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2818"}],"version-history":[{"count":2,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2818\/revisions"}],"predecessor-version":[{"id":2826,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2818\/revisions\/2826"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/43"}],"next":[{"title":"Revisions","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr\/revisions","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/86"}],"prev":[{"title":"[View details] to see more articles ...","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr\/more-articles","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2942"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2818"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=2818"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}