Merge pull request #9351 from RasmusWL/django-file-read

Python: Support `read` on Django file
This commit is contained in:
Rasmus Wriedt Larsen
2022-06-01 10:45:26 +02:00
committed by GitHub
2 changed files with 10 additions and 1 deletions

View File

@@ -71,6 +71,7 @@ def test_taint(request: HttpRequest, foo, bar, baz=None): # $requestHandler rou
request.FILES["key"].name, # $ tainted
request.FILES["key"].file, # $ tainted
request.FILES["key"].file.read(), # $ tainted
request.FILES["key"].read(), # $ tainted
request.FILES.get("key"), # $ tainted
request.FILES.get("key").name, # $ tainted