Skip to content

Commit 084efe0

Browse files
committed
Ruby: limit rb/sensitive-get-query to data from query params
1 parent 977e8a8 commit 084efe0

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

ruby/ql/lib/codeql/ruby/security/SensitiveGetQueryCustomizations.qll

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,8 @@ module SensitiveGetQuery {
3232

3333
RequestInputAccessSource() {
3434
handler = this.asExpr().getExpr().getEnclosingMethod() and
35-
handler.getAnHttpMethod() = "get"
35+
handler.getAnHttpMethod() = "get" and
36+
this.getSourceType().matches(["%params%", "%parameters%"])
3637
}
3738

3839
override Http::Server::RequestHandler getHandler() { result = handler }

0 commit comments

Comments
 (0)