- 05 4月, 2012 2 次提交
-
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
- 03 4月, 2012 3 次提交
-
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
由 Justin 提交于
Rescanning of templates doesn't pass through the same "filter" as the in...
-
- 31 3月, 2012 2 次提交
-
-
由 Neil Matatall 提交于
/Users/neilm/workspace/brakeman/lib/brakeman/scanner.rb:302:in `process_template': undefined method `[]' for nil:NilClass (NoMethodError) Debated between filtering this in the process_template method, decided to filter BEFORE calling process_template, decided to leave it here to bypass the other login in rescan_template
-
由 Justin Collins 提交于
Add check for Object#send with user input.
-
- 30 3月, 2012 3 次提交
-
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
- 29 3月, 2012 2 次提交
-
-
由 Justin Collins 提交于
during progress. I don't really know why this was there...
-
由 Justin Collins 提交于
because when the get re-processed the module information is lost (just class code is stored)
-
- 28 3月, 2012 1 次提交
-
-
由 Justin Collins 提交于
-
- 27 3月, 2012 1 次提交
-
-
由 Justin Collins 提交于
-
- 24 3月, 2012 1 次提交
-
-
由 Neil Matatall 提交于
Add moar test cases
-
- 23 3月, 2012 6 次提交
-
-
由 Neil Matatall 提交于
-
由 Neil Matatall 提交于
Model.send(params[:method]) == bad
-
由 Justin Collins 提交于
[ci skip]
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
由 Justin 提交于
Use old ruby_parser (2.3.1) for Ruby 1.8 parsing
-
- 22 3月, 2012 6 次提交
-
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
由 Justin 提交于
Fix handling of Erubis templates with xss escaping via rails_xss or Rails 3 (but Rails 3 should not really be affected)
-
由 Justin 提交于
Improved dynamic render check, ignore condition in if statements when looking for user input.
-
- 21 3月, 2012 8 次提交
-
-
由 Justin Collins 提交于
either with rails_xss or Rails 3. This was broken when Brakeman's Erubis output was changed to match what rails_xss does. Unfortunately, that broke the ErubisTemplateProcessor such that NO output was detected. This should fix that. Note that this code detects auto-escaping by the output variable. @output_buffer is used in Brakeman's Erubis classes. _buf will only show up if someone is using Erubis with auto-escaping turned off.
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
由 Justin Collins 提交于
-
- 17 3月, 2012 3 次提交
-
-
由 Justin 提交于
Standardize output of stack trace in 1.8 and 1.9 but only when using debug option
-
由 Justin Collins 提交于
Thanks @PragTob
-
由 Justin Collins 提交于
-
- 14 3月, 2012 2 次提交
-
-
由 Justin 提交于
I was getting a NoMethodError when rescanning a file in the lib directo...
-
由 Neil Matatall 提交于
NoMethodError: undefined method `process_library' for #<Brakeman::Rescanner:0x10a8f5380> /Users/neilm/workspace/brakeman/lib/brakeman/rescanner.rb:77:in `rescan_file' /Users/neilm/workspace/brakeman/lib/brakeman/rescanner.rb:50:in `rescan' /Users/neilm/workspace/brakeman/lib/brakeman/rescanner.rb:47:in `each' /Users/neilm/workspace/brakeman/lib/brakeman/rescanner.rb:47:in `rescan' /Users/neilm/workspace/brakeman/lib/brakeman/rescanner.rb:46:in `each' /Users/neilm/workspace/brakeman/lib/brakeman/rescanner.rb:46:in `rescan' /Users/neilm/workspace/brakeman/lib/brakeman/rescanner.rb:22:in `recheck' /Users/neilm/workspace/brakeman/lib/brakeman.rb:291:in `rescan' /usr/local/rvm/gems/ree-1.8.7-2011.12/gems/guard-brakeman-0.3.1/lib/guard/brakeman.rb:73:in `run_on_change'
-