{"id":675,"date":"2020-01-08T12:59:07","date_gmt":"2020-01-08T12:59:07","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/reliability\/only-non-empty-objects-should-be-dereferenced\/"},"modified":"2020-03-20T08:44:58","modified_gmt":"2020-03-20T08:44:58","slug":"emptyobjectdereference","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/reliability\/emptyobjectdereference","title":{"rendered":"Only non-empty objects should be dereferenced"},"content":{"rendered":"\n<p style=\"text-align:center\">Introduced in version: 1.3 (29 Jan 2020)<\/p>\n\n\n\n<p>Dereferencing an empty object will result in an error. At best, such an exception will cause abrupt termination of the running microflow and an automatic rollback. At worst, it could allow an attacker to bypass security measures. This rule can be fixed by removing the dereference.<\/p>\n\n\n\n<p>It is safe to dereference objects if:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>they are used in equality comparisons  e.g.  <code>$Entity\/Attribute = empty<\/code> (but not in combination with <code>not<\/code> )<\/li><li>they are used in XPath constraint during retrieve e.g.<code>[Module.Associaiton &lt; $Entity\/Attribute]<\/code><\/li><li>there is an additional safeguard for empty in the microflow expression e.g. <code>if $Entity\/Attribute != empty then $Entity\/Attribute+' years' else 'no data'<\/code><\/li><\/ul>\n\n\n\n<p>Non-compliant example:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"238\" height=\"246\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-6.png\" alt=\"\" class=\"wp-image-677\"\/><\/figure>\n\n\n\n<p>Compliant example:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"415\" height=\"144\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-7.png\" alt=\"\" class=\"wp-image-678\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-7.png 415w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-7-300x104.png 300w\" sizes=\"(max-width: 415px) 100vw, 415px\" \/><\/figure>\n","protected":false},"featured_media":0,"parent":97,"menu_order":18,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-675","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/675"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=675"}],"version-history":[{"count":2,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/675\/revisions"}],"predecessor-version":[{"id":680,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/675\/revisions\/680"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/97"}],"next":[{"title":"Only variables that are not empty should be returned or assigned","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/reliability\/emptyvariablereturned","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/789"}],"prev":[{"title":"Objects should not be dereferenced after failing an empty check","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/reliability\/emptycheckdereference","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/837"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=675"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=675"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}