CodeQL library for Ruby
codeql/ruby-all 0.8.15-dev (changelog, source)
Search

Module ServerSideRequestForgery

Provides default sources, sinks and sanitizers for reasoning about server side request forgery, as well as extension points for adding your own.

Import path

import codeql.ruby.security.ServerSideRequestForgeryCustomizations

Classes

HttpRequestAsSink

The URL of an HTTP request, considered as a sink.

RemoteFlowSourceAsSource

A source of remote user input, considered as a flow source for server side request forgery.

Sanitizer

A sanitizer for server side request forgery vulnerabilities.

Sink

A data flow sink for server side request forgery vulnerabilities.

Source

A data flow source for server side request forgery vulnerabilities.

StringInterpolationAsSanitizer

A string interpolation with a fixed prefix, considered as a flow sanitizer.