Skip to content

Commit c5e020c

Browse files
committed
Work around problem with comments in heredocs
1 parent 5e606b7 commit c5e020c

4 files changed

Lines changed: 229 additions & 227 deletions

File tree

ruby/ql/test/query-tests/security/cwe-089/ActiveRecordInjection.rb

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,8 @@ def some_request_handler
6666
# BAD: executes `SELECT "users".* FROM "users" WHERE id BETWEEN '#{params[:min_id]}' AND 100000`
6767
# where `params[:min_id]` is unsanitized
6868
User.where(<<-SQL, MAX_USER_ID) # $ Alert
69-
id BETWEEN '#{params[:min_id]}' AND ? # $ Source
69+
id BETWEEN '#{params[:min_id]}' AND ? #{# $ Source
70+
}
7071
SQL
7172

7273
# BAD: chained method case

0 commit comments

Comments
 (0)