Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

General issue Go. Why isn't the following code recognized as a source in a global data stream?

Aberta
#19,807 4 comentários 0 reações 0 responsáveis Ver no GitHub

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
5/5
Tempo estimado
Mais de uma semana
Facilidade para iniciantes
25/100
Tipo de issue
Bug
Clareza
Razoavelmente clara
Status de atividade
Estagnada
Stack de tecnologia
go
Domínio
devtools, security

Direção de pesquisa

Comece comparando o fluxo da fonte em router.go, controller.go, validator.go e param.go com a ActiveThreatModelSource padrão em TainterPath.ql. Reproduza a diferença entre Quick Evaluation e TaintTracking::Global e, em seguida, inspecione a consulta personalizada GinContextGetSource e suas referências a val.Get, req e c. O trabalho estará concluído quando a fonte pretendida for reconhecida no fluxo de dados global.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

question

Why isn't the following code recognized as a source in a global data stream? If I want to identify this source in the global data stream, how should I write my QL?

Here's the code context:

//router.go
func RegisterServers(group *gin.RouterGroup) {
	group.POST("/abc/test", val.Validate[*param.TestParam], controller.TestReadFile)
}
//controller.go
func TestReadFile(c *gin.Context) {
	req := val.Get[*param.TestParam](c)
	cleanPath := req.Path
	file, err := os.Open(cleanPath)
	if err != nil {
		if os.IsNotExist(err) {
			c.JSON(http.StatusNotFound, gin.H{"error": "file not found"})
		} else {
			c.JSON(http.StatusInternalServerError, gin.H{"error": "failed to open file"})
		}
		return
	}
......
}
//validator.go
package val
func Validate[T any](ctx *gin.Context) {
	var req T
	if err := ctx.ShouldBindJSON(&req); err != nil {
		ctx.JSON(http.StatusBadRequest, gin.H{"code": constant.UnknownErrorCode, "msg": util.GetErrorText(constant.UnknownErrorCode)})
		ctx.Abort()
		return
	}
	ctx.Set("params", req)
	ctx.Next()
}

func Get[T any](ctx *gin.Context) T {
	return ctx.MustGet("params").(T)
}
//param.go
package param

type TestParam struct {
	Path string `json:"filepath"`
}

I found that the default "ActiveThreatModelSource" in the official rule "TainterPath.ql" is not recognizable as a source by the above code.
Here's the code I wrote to try to add a new class about this kind of source, and I use "req" from "req.Path" as the source, although the result can be recognized when "Quick Evaluation" is used, but when it is run in the whole "TaintTracking::Global", it cannot be recognized that there is a problem with this "controller.go".
Image

class GinContextGetSource extends DataFlow::Node {
  GinContextGetSource() {
    exists(Function asmGet, CallExpr call |
    asmGet.hasQualifiedName("project/router/val", "Get")
    and call.getTarget() =  asmGet
    and call.getEnclosingFunction() = this.asExpr().getEnclosingFunction()
    and this.asExpr().toString() = "req"
    and this.asExpr().getEnclosingFunction().getAParameter().toString() = "c"
    )
  }
}

I need to address this issue urgently. Because the routing and controller parts of the entire Gin project that I am currently responsible for are developed in this form, the global data flow in each of my official rules cannot be identified in any of the sources
Thank you so much!

Linguagem predominante
CodeQL
Estrelas
10.1k
Forks
2.1k
Merge médio
2d 17h
PRs com merge (30d)
145

Guia de contribuição

Abrir o guia de contribuição

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de github/codeql

Todas as issues de github/codeql

Issues semelhantes

Mais issues de DevTools

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.