mirror of
https://github.com/github/codeql.git
synced 2026-04-28 10:15:14 +02:00
Django: Model any class used in django route setup as view class
This commit is contained in:
@@ -1,2 +1,3 @@
|
||||
lgtm,codescanning
|
||||
* Improved modeling of `django` to recognize request handlers functions that are decorated (for example with `django.views.decorators.http.require_GET`). This leads to more sources of remote user input (`RemoteFlowSource`), since we correctly identify the first parameter as being passed a django request.
|
||||
* Improved modeling of django View classes. We now consider any class using in a routing setup with `<class>.as_view()` as django view class. This leads to more sources of remote user input (`RemoteFlowSource`), since we correctly identify the first parameter as being passed a django request.
|
||||
Reference in New Issue
Block a user