We have just learned that ColdFusion 2021 Update 1...
# cfml-general
p
We have just learned that ColdFusion 2021 Update 13 introduced variable scope changes. We have a lot of un-scoped variables, so we will be using the searchimplicitscopes=true flag as a temporary solution, but will need to fix this before next major upgrade. Does anyone know if there is a tool that we could use to find all un-scoped variables in our ColdFusion codebase?
f
Likely something I will be adding to https://fixinator.app in the near future, but it is not in the current version
👍 5
🤘 3
j
See a larger discussion in another channel here: https://cfml.slack.com/archives/C06TABBT8/p1710270949513319
The above is not an answer to your question directly, simply more information around the change.
s
Hands up if (like a doofus) you patched PROD and discovered this the hard way... 😐
😢 1
p
Thanks for the information. I will take a look at the bigger discussion and the blog. 🙂 We are just patching dev at this point.
g
https://github.com/cfmleditor/CFLint will have an implicit scope checker soon ( not in the current release ), its not perfect but it'll pick up a lot
p
Thanks Gareth!
g
https://github.com/cfmleditor/CFLint/releases/tag/1.5.3-SNAPSHOT if you're running CFLint somewhere already this is compiled against JDK 11 and isn't compatible with older JRE's, also the implicit scope checker is a bit slow...
hopefully some of you find it of some use
like I said, its not perfect
but I'm using it and its already improving code its identified
👍 1
p
Thanks Gareth, we will give it a try!
g
I'm a bit limited in how much time I can spend on this, but I'm still quite interested in any feedback
p
Gareth, the tool works good. It gives me a lot of false positives, but I can see why it might "think" those are unscopped, so I think that's okay. Here is example of false positive. In this code, it reports duplicate(cfcatch) as possibly unscopped. <cfcatch type="any"> <cfscript> structAppend(local.excptInfo, duplicate(cfcatch));
And an example of a good result. Line below was missing quotes around the ZeroSize: addError(GetProfileString(Application.ErrorIniPath, "docMgmt", ZeroSize));
Gareth, my colleague also tried the below. Looks like CFLint is not marking that code as possible implicit use. Is this something you could add to CFLint? I dropped in a basic example to test behavior: <cfset cookie.test=1> <cfoutput>#test#</cfoutput> Neither varscoper nor CFLint flagged this unscoped variable, although I am getting an (expected) error from ColdFusion.
g
I was having some trouble with new files in some projects and can't quite get to the bottom of it, but I tried this in a file I know was being scanned correctly
p
Interesting, looks like you're using it in the VS Code, I will need to try that. I was testing it with the actual jar file, running it manually in the command line.
Copy code
java -jar CFLint-1.5.3-all.jar -file <fullPathToFile>
Gareth, apologies. Looks like my colleague was testing it with 1.5.0 version and not the latest 1.5.3-SNAPSHOP version of the jar file. I just tried the same code as my colleague's (and yours) and CFLint correctly marks it as possible error.
I tried CFLint in VS Code and I think it works well for me. Thanks for providing it!