You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The above code is for an analytical purposes and just logs event names with metadata. There is a chance that user input could be used to enter arbitrary data but that is of little concern to us. There are no SQL counts going on, count is probably badly named but what it does is increase the account of an event name happening.
The text was updated successfully, but these errors were encountered:
Hi @thijsnado - thank you for reporting. Looking at the Brakeman code, this shouldn't be happening... which scares me a little bit 😆 I will take a deeper look.
Background
Brakeman version: 5.2.0
Rails version: 6.1.4.4
Ruby version: 2.7.5p203
Link to Rails application code: ?
False Positive
Full warning from Brakeman:
Relevant code:
Why might this be a false positive?
The above code is for an analytical purposes and just logs event names with metadata. There is a chance that user input could be used to enter arbitrary data but that is of little concern to us. There are no SQL counts going on, count is probably badly named but what it does is increase the account of an event name happening.
The text was updated successfully, but these errors were encountered: