diff --git a/tests/ruby/rails/sql_injection/testdata/injected_params.rb b/tests/ruby/rails/sql_injection/testdata/injected_params.rb index 7a4c67db..56c534a1 100644 --- a/tests/ruby/rails/sql_injection/testdata/injected_params.rb +++ b/tests/ruby/rails/sql_injection/testdata/injected_params.rb @@ -4,8 +4,6 @@ find_by!("oops #{params[:oops]}") # bearer:expected ruby_rails_sql_injection User.joins("INNER JOIN #{params[:oops]}") -# bearer:expected ruby_rails_sql_injection -select("#{params[:oops]} AS oops") # chained case # bearer:expected ruby_rails_sql_injection diff --git a/tests/ruby/rails/sql_injection/testdata/shared_methods.rb b/tests/ruby/rails/sql_injection/testdata/shared_methods.rb index 606484e1..ab1bcdcf 100644 --- a/tests/ruby/rails/sql_injection/testdata/shared_methods.rb +++ b/tests/ruby/rails/sql_injection/testdata/shared_methods.rb @@ -14,3 +14,7 @@ ITEMS.count ITEMS.count(:apple) +# bearer:expected ruby_rails_sql_injection +User.select("#{params[:oops]} AS oops") +# bearer:expected ruby_rails_sql_injection +user.posts.select("#{params[:oops]} AS oops")