Skip to content

Commit b91b314

Browse files
committed
Ruby: add missing qldoc comments for SQL injection query
1 parent 511fb97 commit b91b314

File tree

2 files changed

+6
-0
lines changed

2 files changed

+6
-0
lines changed

ruby/ql/lib/codeql/ruby/security/SqlInjectionCustomizations.qll

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,10 +13,13 @@ private import codeql.ruby.dataflow.RemoteFlowSources
1313
* vulnerabilities, as well as extension points for adding your own.
1414
*/
1515
module SqlInjection {
16+
/** A data flow source for SQL injection vulnerabilities. */
1617
abstract class Source extends DataFlow::Node { }
1718

19+
/** A data flow sink for SQL injection vulnerabilities. */
1820
abstract class Sink extends DataFlow::Node { }
1921

22+
/** A sanitizer for SQL injection vulnerabilities. */
2023
abstract class Sanitizer extends DataFlow::Node { }
2124

2225
/**

ruby/ql/lib/codeql/ruby/security/SqlInjectionQuery.qll

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,9 @@ private import codeql.ruby.DataFlow
77
private import codeql.ruby.TaintTracking
88
import SqlInjectionCustomizations::SqlInjection
99

10+
/**
11+
* A taint-tracking configuration for detecting SQL injection vulnerabilities.
12+
*/
1013
class Configuration extends TaintTracking::Configuration {
1114
Configuration() { this = "SqlInjectionConfiguration" }
1215

0 commit comments

Comments
 (0)