Python: `FlaskApp` instances do not reliably track subclasses
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 141
Mô tả
I was running a set of queries on the [CTFd](https://github.com/CTFd/CTFd) repository, and got suspiciously few results for endpoints. After some experimenting I found out that [they subclass `Flask`](https://github.com/CTFd/CTFd/blob/master/CTFd/__init__.py#L51C1-L91C1), which the current query for `FlaskApp::instance()` does not seem to track.
# Minimal example:
Query:
```plaintext
import python
import semmle.python.frameworks.Flask
import semmle.python.ApiGraphs
from API::Node node
where Flask::FlaskApp::instance() = node
select node
```
Python:
```py
from flask import Flask
class Sub(Flask):
def __init__(self, *args, **kwargs):
Flask.__init__(self, *args, **kwargs)
app = Sub(__name__)
@app.route("/")
def hello():
return "world"
```
CodeQL is not able to identify `Sub` as a Flask app, which means the route setup for `hello` cannot be detected as well.
Adding `.getASubclass*()` to [FlaskApp::instance()](https://github.com/github/codeql/blob/main/python/ql/lib/semmle/python/frameworks/Flask.qll#L76C1-L76C64) would probably fix this. If this can be overridden without changes to the library I am open to suggestions, my knowledge of the QL modules is not that great as of now.
Hướng dẫn đóng góp
Hướng nghiên cứu
Bắt đầu trong python/ql/lib/semmle/python/frameworks/Flask.qll tại FlaskApp::instance(), sau đó tái hiện truy vấn tối thiểu và ví dụ lớp con Python từ issue. Xác nhận rằng một lớp con Flask được nhận diện là app và route cho hello được phát hiện; thêm hoặc cập nhật bài kiểm thử coverage của thư viện liên quan nếu tìm thấy một bài ở gần đó.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- python
- Lĩnh vực
- security
- Loại issue
- Lỗi
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức độ hoạt động
- Ít trao đổi
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 55/100