Files
codeql/ruby/ql/test/query-tests/security/cwe-352/CSRFProtectionNotEnabled.qlref
Harry Maclean 49d826f667 Ruby: Add a query for CSRF protection not enabled
Specifically in Rails apps, we look for root ActionController classes
without a call to `protect_from_forgery`.
2024-02-23 11:13:14 +00:00

1 line
52 B
Plaintext

queries/security/cwe-352/CSRFProtectionNotEnabled.ql