We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 880fb2b commit 977e8a8Copy full SHA for 977e8a8
ruby/ql/test/query-tests/security/cwe-598/app/controllers/users_controller.rb
@@ -10,6 +10,11 @@ def login_post
10
authenticate_user(params[:username], password)
11
end
12
13
+ def login_get_cookies
14
+ password = cookies[:password]
15
+ authenticate_user(params[:username], password)
16
+ end
17
+
18
private
19
def authenticate_user(username, password)
20
# ... authenticate the user here
ruby/ql/test/query-tests/security/cwe-598/config/routes.rb
@@ -2,4 +2,5 @@
2
match "users/login1", to: "users#login_get", via: :get
3
get "users/login2", to: "users#login_get"
4
post "users/login3", to: "users#login_post"
5
+ get "users/login3", to: "users#login_get_cookies"
6
0 commit comments