WIP: Ruby: Add context query for retrieving XSS sanitisers

This commit is contained in:
Aditya Sharad
2025-04-17 15:05:56 -07:00
parent 6176202d50
commit 4a1b988f39

12
ruby/ql/src/Sanitizers.ql Normal file
View File

@@ -0,0 +1,12 @@
/**
* @name Sanitizers
* @id rb/meta/sanitizers
* @kind problem
* @severity info
*/
import codeql.ruby.DataFlow
import codeql.ruby.security.XSS
from StoredXss::Sanitizer s
where s instanceof DataFlow::CallNode
select s, "XSS sanitizer"