Skip to content

Commit 2302c8d

Browse files
committed
Python: Model new alias method on django QuerySets
1 parent 1ed11b2 commit 2302c8d

File tree

2 files changed

+30
-3
lines changed

2 files changed

+30
-3
lines changed

python/ql/src/semmle/python/frameworks/Django.qll

Lines changed: 25 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -366,7 +366,7 @@ private module PrivateDjango {
366366
"none", "all", "filter", "exclude", "complex_filter", "union", "intersection",
367367
"difference", "select_for_update", "select_related", "prefetch_related", "order_by",
368368
"distinct", "reverse", "defer", "only", "using", "annotate", "extra", "raw",
369-
"datetimes", "dates", "values", "values_list"
369+
"datetimes", "dates", "values", "values_list", "alias"
370370
] and
371371
result = [manager(), querySet()].getMember(name)
372372
}
@@ -386,7 +386,8 @@ private module PrivateDjango {
386386
/** Provides models for the `django.db.models.expressions.RawSQL` class. */
387387
module RawSQL {
388388
/**
389-
* Gets a reference to the `django.db.models.expressions.RawSQL` class.
389+
* Gets an instance of the `django.db.models.expressions.RawSQL` class,
390+
* that was initiated with the SQL represented by `sql`.
390391
*/
391392
API::Node classRef() {
392393
result = expressions().getMember("RawSQL")
@@ -406,7 +407,10 @@ private module PrivateDjango {
406407
exists(DataFlow::TypeTracker t2 | result = instance(t2, sql).track(t2, t))
407408
}
408409

409-
/** Gets an instance of the `django.db.models.expressions.RawSQL` class. */
410+
/**
411+
* Gets an instance of the `django.db.models.expressions.RawSQL` class,
412+
* that was initiated with the SQL represented by `sql`.
413+
*/
410414
DataFlow::Node instance(ControlFlowNode sql) {
411415
instance(DataFlow::TypeTracker::end(), sql).flowsTo(result)
412416
}
@@ -435,6 +439,24 @@ private module PrivateDjango {
435439
override DataFlow::Node getSql() { result.asCfgNode() = sql }
436440
}
437441

442+
/**
443+
* A call to the `alias` function on a model using a `RawSQL` argument.
444+
*
445+
* See https://docs.djangoproject.com/en/3.2/ref/models/querysets/#alias
446+
*/
447+
private class ObjectsAlias extends SqlExecution::Range, DataFlow::CallCfgNode {
448+
ControlFlowNode sql;
449+
450+
ObjectsAlias() {
451+
this = django::db::models::querySetReturningMethod("alias").getACall() and
452+
django::db::models::expressions::RawSQL::instance(sql) in [
453+
this.getArg(_), this.getArgByName(_)
454+
]
455+
}
456+
457+
override DataFlow::Node getSql() { result.asCfgNode() = sql }
458+
}
459+
438460
/**
439461
* A call to the `raw` function on a model.
440462
*

python/ql/test/library-tests/frameworks/django/SqlExecution.py

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,9 +19,14 @@ class User(models.Model):
1919

2020
def test_model():
2121
User.objects.raw("some sql") # $getSql="some sql"
22+
2223
User.objects.annotate(RawSQL("some sql")) # $getSql="some sql"
2324
User.objects.annotate(RawSQL("foo"), RawSQL("bar")) # $getSql="foo" getSql="bar"
2425
User.objects.annotate(val=RawSQL("some sql")) # $getSql="some sql"
26+
27+
User.objects.alias(RawSQL("foo"), RawSQL("bar")) # $getSql="foo" getSql="bar"
28+
User.objects.alias(val=RawSQL("some sql")) # $getSql="some sql"
29+
2530
User.objects.extra("some sql") # $getSql="some sql"
2631
User.objects.extra(select="select", where="where", tables="tables", order_by="order_by") # $getSql="select" getSql="where" getSql="tables" getSql="order_by"
2732

0 commit comments

Comments
 (0)