/** * Provides shared predicates for reasoning about improper multi-character sanitization. */ import IncompleteMultiCharacterSanitizationSpecific /** * A prefix that may be dangerous to sanitize explicitly. * * Note that this class exists solely as a (necessary) optimization for this query. */ private class DangerousPrefix extends string { DangerousPrefix() { this = ["/..", "../"] or this = "