Comments (2)
Hi Dave,
The reason the first section of code warns and the second does not is because name
is not determined to be user input.
But that's not the real issue. I agree that the #find_or_create_by_<attr>
methods should not be checked for SQLi. This is apparently just an oversight on my part!
from brakeman.
I take part of that back...in find...
methods, Brakeman is only checking the last argument (I assume because I thought this would be a conditions hash).
from brakeman.
Related Issues (20)
- Segmentation Fault in ruby 3.2.0 ( EDIT: fixed in 3.2.2 ) HOT 14
- False Positive 'Unescaped model attribute' when using safe '_html' i18n key
- Broken link to Unmaintained Dependency HOT 2
- Add "obsolete" entries to comparison results HOT 1
- CircleCI - running with format `junit` can't be parsed by CircleCI HOT 3
- Parse error on Ruby 3.2 anonymous keyword spread HOT 5
- False positive for send_file HOT 1
- Is there a flag to show all warnings including the ignored ones? HOT 5
- Brakeman Is Not Catching SQL Injections in Arel.sql(raw_sql) HOT 3
- Check for signed_id/Global ID usage without specified purpose HOT 1
- False Negative: warning on CSRF in Rails 5.2+ with defaults HOT 5
- Relax Rails app structure constraints HOT 2
- content_tag no longer considered dangerous HOT 1
- False positive Send where `send` is inside conditional that prevents arbitrary user input. HOT 2
- False positive for `protect_from_forgery` when defaults for rails 7 are used HOT 1
- Unscoped find not alerted for `find_by!`
- Unscoped find does not traverse concerns HOT 1
- Error: undefined method `node_type' for nil:NilClass case value.node_type HOT 4
- False positive - loofah gem 2.19.1 is already beyond suggested upgrade of 2.2.1 HOT 2
- Config in environment files generated by external services are not detected HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from brakeman.