Skip to content

Commit d11cb91

Browse files
committed
Use of CGI.escapeHTML() in test samples
1 parent 7cd1fd4 commit d11cb91

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

ruby/ql/test/query-tests/experimental/cwe-176/unicode_normalization.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ def unicodeNormalize
1818
class UnicodeNormalizationHtMLSafeController < ActionController::Base
1919
def unicodeNormalize
2020
unicode_input = params[:unicode_input]
21-
unicode_html_safe = unicode_input.html_safe
21+
unicode_html_safe = CGI.escapeHTML(unicode_input).html_safe
2222
normalized_nfkc = unicode_html_safe.unicode_normalize(:nfkc) # $result=BAD
2323
normalized_nfc = unicode_html_safe.unicode_normalize(:nfc) # $result=BAD
2424
end

0 commit comments

Comments
 (0)