Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 81505fb

Browse files
committed
Normalize tests
1 parent 5123b8f commit 81505fb

18 files changed

Lines changed: 20 additions & 72 deletions

python/ql/test/experimental/query-tests/Security/CWE-943/flask_mongoengine_bad.py

Lines changed: 0 additions & 25 deletions
This file was deleted.

python/ql/test/experimental/query-tests/Security/CWE-943/mongoengine_flask_db_document_subclass_bad.py renamed to python/ql/test/experimental/query-tests/Security/CWE-943/flask_mongoengine_db_document_subclass_bad.py

File renamed without changes.

python/ql/test/experimental/query-tests/Security/CWE-943/mongoengine_flask_db_document_subclass_good.py renamed to python/ql/test/experimental/query-tests/Security/CWE-943/flask_mongoengine_db_document_subclass_good.py

File renamed without changes.

python/ql/test/experimental/query-tests/Security/CWE-943/flask_mongoengine_get_db_bad.py

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@
33
import json
44

55
app = Flask(__name__)
6+
app.config.from_pyfile('the-config.cfg')
67
db = MongoEngine(app)
7-
db.init_app(app)
88

99

1010
class Movie(db.Document):
@@ -16,11 +16,11 @@ class Movie(db.Document):
1616

1717
@app.route("/")
1818
def home_page():
19-
unsanitized_search = request.args['search']
20-
json_search = json.loads(unsanitized_search)
19+
unsafe_search = request.args['search']
20+
json_search = json.loads(unsafe_search)
2121

2222
retrieved_db = db.get_db()
23-
result = retrieved_db["Movie"].find({'name': json_search})
23+
data = retrieved_db["Movie"].find({'name': json_search})
2424

2525
# if __name__ == "__main__":
2626
# app.run(debug=True)

python/ql/test/experimental/query-tests/Security/CWE-943/flask_mongoengine_get_db_good.py

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,8 @@
44
import json
55

66
app = Flask(__name__)
7+
app.config.from_pyfile('the-config.cfg')
78
db = MongoEngine(app)
8-
db.init_app(app)
99

1010

1111
class Movie(db.Document):
@@ -17,12 +17,12 @@ class Movie(db.Document):
1717

1818
@app.route("/")
1919
def home_page():
20-
unsanitized_search = request.args['search']
21-
json_search = json.loads(unsanitized_search)
20+
unsafe_search = request.args['search']
21+
json_search = json.loads(unsafe_search)
2222
safe_search = sanitize(json_search)
2323

2424
retrieved_db = db.get_db()
25-
result = retrieved_db["Movie"].find({'name': safe_search})
25+
data = retrieved_db["Movie"].find({'name': safe_search})
2626

2727
# if __name__ == "__main__":
2828
# app.run(debug=True)

python/ql/test/experimental/query-tests/Security/CWE-943/flask_mongoengine_good.py

Lines changed: 0 additions & 27 deletions
This file was deleted.

python/ql/test/experimental/query-tests/Security/CWE-943/flask_pymongo_bad.py

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -8,10 +8,10 @@
88

99
@app.route("/")
1010
def home_page():
11-
unsanitized_search = request.args['search']
12-
json_search = json.loads(unsanitized_search)
11+
unsafe_search = request.args['search']
12+
json_search = json.loads(unsafe_search)
1313

14-
result = mongo.db.user.find({'name': json_search})
14+
data = mongo.db.user.find({'name': json_search})
1515

1616
# if __name__ == "__main__":
1717
# app.run(debug=True)

python/ql/test/experimental/query-tests/Security/CWE-943/flask_pymongo_good.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ def home_page():
1313
json_search = json.loads(unsafe_search)
1414
safe_search = sanitize(json_search)
1515

16-
result = mongo.db.user.find({'name': safe_search})
16+
data = mongo.db.user.find({'name': safe_search})
1717

1818
# if __name__ == "__main__":
1919
# app.run(debug=True)

python/ql/test/experimental/query-tests/Security/CWE-943/mongoclient_subscript_bad.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ def home_page():
1818
json_search = json.loads(unsafe_search)
1919

2020
db = me.connect('mydb')
21-
data = db['mydb']['movie'].find({'name': json_search})
21+
data = db['movie'].find({'name': json_search})
2222

2323
# if __name__ == "__main__":
2424
# app.run(debug=True)

python/ql/test/experimental/query-tests/Security/CWE-943/mongoclient_subscript_good.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ def home_page():
2020
safe_search = sanitize(json_search)
2121

2222
db = me.connect('mydb')
23-
data = db['mydb']['movie'].find({'name': safe_search})
23+
data = db['movie'].find({'name': safe_search})
2424

2525
# if __name__ == "__main__":
2626
# app.run(debug=True)

0 commit comments

Comments
 (0)