CodeQL library for Python
codeql/python-all 0.6.4 (changelog, source)
Search

Module UrlRedirect

Provides default sources, sinks and sanitizers for detecting “URL redirection” vulnerabilities, as well as extension points for adding your own.

Import path

import semmle.python.security.dataflow.UrlRedirectCustomizations

Classes

RedirectLocationAsSink

A HTTP redirect response, considered as a flow sink.

RemoteFlowSourceAsSource

A source of remote user input, considered as a flow source.

Sanitizer

A sanitizer for “URL redirection” vulnerabilities.

SanitizerGuard

DEPRECATED: Use Sanitizer instead.

Sink

A data flow sink for “URL redirection” vulnerabilities.

Source

A data flow source for “URL redirection” vulnerabilities.

StringConcatAsSanitizer

The right side of a string-concat, considered as a sanitizer.

StringConstCompareAsSanitizerGuard

A comparison with a constant string, considered as a sanitizer-guard.