github / github/codeql

Python: `FlaskApp` instances do not reliably track subclasses

Offen
#21,854 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Python question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

I was running a set of queries on the [CTFd](https://github.com/CTFd/CTFd) repository, and got suspiciously few results for endpoints. After some experimenting I found out that [they subclass `Flask`](https://github.com/CTFd/CTFd/blob/master/CTFd/__init__.py#L51C1-L91C1), which the current query for `FlaskApp::instance()` does not seem to track.

# Minimal example:
Query:
```plaintext
import python

import semmle.python.frameworks.Flask
import semmle.python.ApiGraphs

from API::Node node
where Flask::FlaskApp::instance() = node
select node
```

Python:
```py
from flask import Flask

class Sub(Flask):
def __init__(self, *args, **kwargs):
Flask.__init__(self, *args, **kwargs)

app = Sub(__name__)

@app.route("/")
def hello():
return "world"
```

CodeQL is not able to identify `Sub` as a Flask app, which means the route setup for `hello` cannot be detected as well.

Adding `.getASubclass*()` to [FlaskApp::instance()](https://github.com/github/codeql/blob/main/python/ql/lib/semmle/python/frameworks/Flask.qll#L76C1-L76C64) would probably fix this. If this can be overridden without changes to the library I am open to suggestions, my knowledge of the QL modules is not that great as of now.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start in python/ql/lib/semmle/python/frameworks/Flask.qll at FlaskApp::instance(), then reproduce the minimal query and Python subclass example from the issue. Confirm that a Flask subclass is recognized as an app and that the route for hello is detected; add or update the relevant library coverage test if one is found nearby.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
55/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.