mirror of
https://github.com/github/codeql.git
synced 2025-12-18 01:33:15 +01:00
Python: Model routed parameter flow to *args and **kwargs in Django + rest framework
This commit is contained in:
@@ -174,11 +174,11 @@ class ClassView(View):
|
||||
)
|
||||
|
||||
|
||||
def kwargs_param(request, **kwargs): # $ requestHandler
|
||||
def kwargs_param(request, **kwargs): # $ requestHandler routedParameter=kwargs
|
||||
ensure_tainted(
|
||||
kwargs, # $ MISSING: tainted
|
||||
kwargs["foo"], # $ MISSING: tainted
|
||||
kwargs["bar"] # $ MISSING: tainted
|
||||
kwargs, # $ tainted
|
||||
kwargs["foo"], # $ tainted
|
||||
kwargs["bar"] # $ tainted
|
||||
)
|
||||
|
||||
ensure_tainted(request) # $ tainted
|
||||
|
||||
Reference in New Issue
Block a user