Files
codeql/ruby/ql/lib/change-notes/2023-03-13-sinatra.md
2023-03-13 21:38:45 +13:00

310 B

category
category
minorAnalysis
  • Accesses of params in Sinatra applications are now recognised as HTTP input accesses.
  • Data flow is tracked from Sinatra route handlers to ERB files.
  • Data flow is tracked between basic Sinatra filters (those without URL patterns) and their corresponding route handlers.