github / github/codeql

False negatives of `py/flask-debug`

Aperta
#21,616 1 commento 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
CodeQL
Stelle
10.1k
Fork
2.1k
Merge medio
2g 15h
PR unite (30g)
141

Descrizione

`py/flask-debug` misses some common ways to enable debug mode in Flask.

For example:
```python
app = Flask(__name__)
app.config['DEBUG'] = True # Enables debug mode
app.run()

---
class Settings:
DEBUG = True

settings = Settings()
app.run(debug=settings.DEBUG)
```

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start by locating the py/flask-debug query and reproducing the two examples in the issue. Compare the query's behavior with both configuration-based and argument-based debug activation; done means these common Flask patterns are detected without regressing existing cases.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
flask, python
Ambito
security
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
58/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.