Sobelow.XSS.Raw (Sobelow v0.16.0)

View Source

XSS in raw

This submodule checks for the use of raw in templates as this can lead to XSS vulnerabilities if taking user input.

Recognized local helpers and explicit imports of unrelated raw functions are excluded. A local helper that returns dynamic {:safe, value} output or calls another raw function retains its caller's finding. Unresolved raw macros and delegates remain possible sinks.

Raw checks can be ignored with the following command:

$ mix sobelow -i XSS.Raw

Summary

Functions

details()

id()

parse_raw_def(fun, file \\ "inline HEEx")

parse_render_def(fun)

rule()

run(fun, meta_file, arg3, controller)