Django: Model any class used in django route setup as view class

This commit is contained in:
Rasmus Wriedt Larsen
2021-02-10 16:26:25 +01:00
parent b428945bc2
commit ca0d345987
3 changed files with 38 additions and 16 deletions

View File

@@ -1,2 +1,3 @@
lgtm,codescanning
* Improved modeling of `django` to recognize request handlers functions that are decorated (for example with `django.views.decorators.http.require_GET`). This leads to more sources of remote user input (`RemoteFlowSource`), since we correctly identify the first parameter as being passed a django request.
* Improved modeling of django View classes. We now consider any class using in a routing setup with `<class>.as_view()` as django view class. This leads to more sources of remote user input (`RemoteFlowSource`), since we correctly identify the first parameter as being passed a django request.