Error Handling with SecItemCopyMatching and Veracode












0















I use Veracode to scan my application and have the error about
Unchecked Error Condition. Here is my code:



    let status = withUnsafeMutablePointer(to: &queryResult) {
SecItemCopyMatching(query as CFDictionary, UnsafeMutablePointer($0))
}

// Check the return status and throw an error if appropriate.
guard status != errSecItemNotFound else {
throw KeychainError.noKeychain
}
guard status == noErr else {
throw KeychainError.unhandledError(status: status)
}


Error is at this line: SecItemCopyMatching(query as CFDictionary, UnsafeMutablePointer($0))




Error handling problems occur when an application does not properly handle errors that occur during processing. If a function does not generate the correct return/status codes, or if the product does not handle all possible return/status codes that could be generated by a function, then security issues may result. Similarly, failing to catch an exception thrown by a function can potentially cause the program to crash or to behave in an unexpected manner.











share|improve this question





























    0















    I use Veracode to scan my application and have the error about
    Unchecked Error Condition. Here is my code:



        let status = withUnsafeMutablePointer(to: &queryResult) {
    SecItemCopyMatching(query as CFDictionary, UnsafeMutablePointer($0))
    }

    // Check the return status and throw an error if appropriate.
    guard status != errSecItemNotFound else {
    throw KeychainError.noKeychain
    }
    guard status == noErr else {
    throw KeychainError.unhandledError(status: status)
    }


    Error is at this line: SecItemCopyMatching(query as CFDictionary, UnsafeMutablePointer($0))




    Error handling problems occur when an application does not properly handle errors that occur during processing. If a function does not generate the correct return/status codes, or if the product does not handle all possible return/status codes that could be generated by a function, then security issues may result. Similarly, failing to catch an exception thrown by a function can potentially cause the program to crash or to behave in an unexpected manner.











    share|improve this question



























      0












      0








      0








      I use Veracode to scan my application and have the error about
      Unchecked Error Condition. Here is my code:



          let status = withUnsafeMutablePointer(to: &queryResult) {
      SecItemCopyMatching(query as CFDictionary, UnsafeMutablePointer($0))
      }

      // Check the return status and throw an error if appropriate.
      guard status != errSecItemNotFound else {
      throw KeychainError.noKeychain
      }
      guard status == noErr else {
      throw KeychainError.unhandledError(status: status)
      }


      Error is at this line: SecItemCopyMatching(query as CFDictionary, UnsafeMutablePointer($0))




      Error handling problems occur when an application does not properly handle errors that occur during processing. If a function does not generate the correct return/status codes, or if the product does not handle all possible return/status codes that could be generated by a function, then security issues may result. Similarly, failing to catch an exception thrown by a function can potentially cause the program to crash or to behave in an unexpected manner.











      share|improve this question
















      I use Veracode to scan my application and have the error about
      Unchecked Error Condition. Here is my code:



          let status = withUnsafeMutablePointer(to: &queryResult) {
      SecItemCopyMatching(query as CFDictionary, UnsafeMutablePointer($0))
      }

      // Check the return status and throw an error if appropriate.
      guard status != errSecItemNotFound else {
      throw KeychainError.noKeychain
      }
      guard status == noErr else {
      throw KeychainError.unhandledError(status: status)
      }


      Error is at this line: SecItemCopyMatching(query as CFDictionary, UnsafeMutablePointer($0))




      Error handling problems occur when an application does not properly handle errors that occur during processing. If a function does not generate the correct return/status codes, or if the product does not handle all possible return/status codes that could be generated by a function, then security issues may result. Similarly, failing to catch an exception thrown by a function can potentially cause the program to crash or to behave in an unexpected manner.








      ios swift






      share|improve this question















      share|improve this question













      share|improve this question




      share|improve this question








      edited Nov 15 '18 at 21:08







      YodaVN

















      asked Nov 15 '18 at 19:28









      YodaVNYodaVN

      264




      264
























          1 Answer
          1






          active

          oldest

          votes


















          0














          According to documentation of withUnsafeMutablePointer, the argument in closure is already of UnsafeMutablePointer type. So basically you're passing UnsafeMutablePointer<UnsafeMutablePointer> to SecItemCopyMatching, where (if you want to stick with UnsafeMutablePointer) you should be passing UnsafeMutablePointer<CFTypeRef>. So try



          SecItemCopyMatching(query as CFDictionary, $0)





          share|improve this answer
























          • Thank you, I just edit my question. The problem is about return checking so I'm not sure about your answer. I will run the veracode check again and let you know.

            – YodaVN
            Nov 15 '18 at 21:10











          Your Answer






          StackExchange.ifUsing("editor", function () {
          StackExchange.using("externalEditor", function () {
          StackExchange.using("snippets", function () {
          StackExchange.snippets.init();
          });
          });
          }, "code-snippets");

          StackExchange.ready(function() {
          var channelOptions = {
          tags: "".split(" "),
          id: "1"
          };
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function() {
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled) {
          StackExchange.using("snippets", function() {
          createEditor();
          });
          }
          else {
          createEditor();
          }
          });

          function createEditor() {
          StackExchange.prepareEditor({
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader: {
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          },
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          });


          }
          });














          draft saved

          draft discarded


















          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53326673%2ferror-handling-with-secitemcopymatching-and-veracode%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown

























          1 Answer
          1






          active

          oldest

          votes








          1 Answer
          1






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes









          0














          According to documentation of withUnsafeMutablePointer, the argument in closure is already of UnsafeMutablePointer type. So basically you're passing UnsafeMutablePointer<UnsafeMutablePointer> to SecItemCopyMatching, where (if you want to stick with UnsafeMutablePointer) you should be passing UnsafeMutablePointer<CFTypeRef>. So try



          SecItemCopyMatching(query as CFDictionary, $0)





          share|improve this answer
























          • Thank you, I just edit my question. The problem is about return checking so I'm not sure about your answer. I will run the veracode check again and let you know.

            – YodaVN
            Nov 15 '18 at 21:10
















          0














          According to documentation of withUnsafeMutablePointer, the argument in closure is already of UnsafeMutablePointer type. So basically you're passing UnsafeMutablePointer<UnsafeMutablePointer> to SecItemCopyMatching, where (if you want to stick with UnsafeMutablePointer) you should be passing UnsafeMutablePointer<CFTypeRef>. So try



          SecItemCopyMatching(query as CFDictionary, $0)





          share|improve this answer
























          • Thank you, I just edit my question. The problem is about return checking so I'm not sure about your answer. I will run the veracode check again and let you know.

            – YodaVN
            Nov 15 '18 at 21:10














          0












          0








          0







          According to documentation of withUnsafeMutablePointer, the argument in closure is already of UnsafeMutablePointer type. So basically you're passing UnsafeMutablePointer<UnsafeMutablePointer> to SecItemCopyMatching, where (if you want to stick with UnsafeMutablePointer) you should be passing UnsafeMutablePointer<CFTypeRef>. So try



          SecItemCopyMatching(query as CFDictionary, $0)





          share|improve this answer













          According to documentation of withUnsafeMutablePointer, the argument in closure is already of UnsafeMutablePointer type. So basically you're passing UnsafeMutablePointer<UnsafeMutablePointer> to SecItemCopyMatching, where (if you want to stick with UnsafeMutablePointer) you should be passing UnsafeMutablePointer<CFTypeRef>. So try



          SecItemCopyMatching(query as CFDictionary, $0)






          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered Nov 15 '18 at 20:55









          mag_zbcmag_zbc

          4,10383048




          4,10383048













          • Thank you, I just edit my question. The problem is about return checking so I'm not sure about your answer. I will run the veracode check again and let you know.

            – YodaVN
            Nov 15 '18 at 21:10



















          • Thank you, I just edit my question. The problem is about return checking so I'm not sure about your answer. I will run the veracode check again and let you know.

            – YodaVN
            Nov 15 '18 at 21:10

















          Thank you, I just edit my question. The problem is about return checking so I'm not sure about your answer. I will run the veracode check again and let you know.

          – YodaVN
          Nov 15 '18 at 21:10





          Thank you, I just edit my question. The problem is about return checking so I'm not sure about your answer. I will run the veracode check again and let you know.

          – YodaVN
          Nov 15 '18 at 21:10




















          draft saved

          draft discarded




















































          Thanks for contributing an answer to Stack Overflow!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid



          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.


          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53326673%2ferror-handling-with-secitemcopymatching-and-veracode%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          List item for chat from Array inside array React Native

          Thiostrepton

          Caerphilly