Skip to content

Commit 013e7aa

Browse files
committed
Ruby: test whitespace changes
1 parent c1ecd5a commit 013e7aa

File tree

2 files changed

+90
-78
lines changed

2 files changed

+90
-78
lines changed

ruby/ql/test/query-tests/security/cwe-089/ActiveRecordInjection.rb

Lines changed: 17 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -90,9 +90,21 @@ def some_request_handler
9090
# BAD: executes `UPDATE "users" SET #{params[:fields]}`
9191
# where `params[:fields]` is unsanitized
9292
User.update_all(params[:fields])
93-
93+
94+
95+
96+
97+
98+
99+
100+
101+
102+
103+
104+
105+
94106
User.reorder(params[:direction])
95-
107+
96108
User.count_by_sql(params[:custom_sql_query])
97109
end
98110
end
@@ -168,13 +180,13 @@ def index
168180
result = Regression.find_by_sql(query)
169181
end
170182

171-
183+
172184
def permitted_params
173185
params.require(:my_key).permit(:id, :user_id, :my_type)
174186
end
175-
187+
176188
def show
177189
ActiveRecord::Base.connection.execute("SELECT * FROM users WHERE id = #{permitted_params[:user_id]}")
178190
Regression.connection.execute("SELECT * FROM users WHERE id = #{permitted_params[:user_id]}")
179191
end
180-
end
192+
end

0 commit comments

Comments
 (0)