From 84c335ae50ea09e45e2c898a8f4084dc0688d65b Mon Sep 17 00:00:00 2001 From: Subarno Banerjee <98043512+awsubarno@users.noreply.github.com> Date: Wed, 9 Mar 2022 14:02:53 -0800 Subject: [PATCH] Revert "Use isalnum (#43)" This reverts commit b9a178ea8b21b436b6931b11785a81288e9af89a. --- src/python/detectors/log_injection/log_injection.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/python/detectors/log_injection/log_injection.py b/src/python/detectors/log_injection/log_injection.py index 320f158..1440fc3 100644 --- a/src/python/detectors/log_injection/log_injection.py +++ b/src/python/detectors/log_injection/log_injection.py @@ -16,7 +16,7 @@ def logging_noncompliant(): # {fact rule=log-injection@v1.0 defects=0} def logging_compliant(): filename = input("Enter a filename: ") - if filename.isalnum(): + if re.match(r'^[\w_ -\.]+$', filename): # Compliant: input is validated before logging. logger.info("Processing %s", filename) # {/fact}