nyx/tests/fixtures/xpath_injection/ruby/baseline_constant_xpath.rb
2026-05-07 01:29:31 -04:00

8 lines
238 B
Ruby

# Baseline: expression is a compile-time constant. No taint reaches
# `doc.xpath` so no XPATH_INJECTION finding fires.
require 'nokogiri'
def lookup
doc = Nokogiri::XML(File.read("users.xml"))
doc.xpath("//user[@role='admin']")
end