From 3734a544bc9fc12593bc892a0be34166cf413b60 Mon Sep 17 00:00:00 2001 From: Harry Maclean Date: Mon, 13 Mar 2023 21:38:45 +1300 Subject: [PATCH] Ruby: Add change note --- ruby/ql/lib/change-notes/2023-03-13-sinatra.md | 6 ++++++ 1 file changed, 6 insertions(+) create mode 100644 ruby/ql/lib/change-notes/2023-03-13-sinatra.md diff --git a/ruby/ql/lib/change-notes/2023-03-13-sinatra.md b/ruby/ql/lib/change-notes/2023-03-13-sinatra.md new file mode 100644 index 00000000000..3d888416fb9 --- /dev/null +++ b/ruby/ql/lib/change-notes/2023-03-13-sinatra.md @@ -0,0 +1,6 @@ +--- + category: minorAnalysis +--- +* Accesses of `params` in Sinatra applications are now recognised as HTTP input accesses. +* Data flow is tracked from Sinatra route handlers to ERB files. +* Data flow is tracked between basic Sinatra filters (those without URL patterns) and their corresponding route handlers.