Identify your sanitizer's FQN
How to identify the fully qualified name (FQN) of a sanitizer function for a Snyk Code Rule Extension
When creating a custom sanitizer, you must provide its Fully Qualified Name (FQN). The FQN is how Snyk Code's security engine identifies your function across your codebase. This guide walks you through identifying the correct FQN format for your sanitizer function.
Why FQNs matter
Snyk Code traces data flow through your application to identify security issues. To recognize your custom sanitizer, the engine must resolve the function's name to its exact definition. The name you see in your IDE may differ from how the engine resolves it, especially when imports, namespaces, or module systems are involved.
Critical rule: Snyk Code requires Fully Qualified Names (FQNs). Partially Qualified Names (PQNs) are not supported.
Step-by-step identification process
Follow these steps to identify your sanitizer's FQN:
Step 1: Identify your programming language
Select your language to see the specific FQN format:
C# FQN format
Format: Namespace.Class.Method
Important: C# FQNs must include the global:: prefix.
Pattern: global::Namespace.Class.Method
How to identify your FQN
Find the namespace declaration in your sanitizer's file.
Find the class name containing your sanitizer method.
Find the method name.
Combine them with dots:
global::Namespace.Class.Method
Example
namespace MyCorp.Security {
public static class InputSanitizer {
public static string Clean(string input) {
return input.Trim();
}
}
}FQN: global::MyCorp.Security.InputSanitizer.Clean
Common pitfalls
Using
usingdirectives: If your sanitizer is imported via ausingdirective (especially wildcard imports), the engine may not resolve the FQN correctly. Use explicit namespace references at the call site.Missing
global::prefix: Always includeglobal::at the start of your FQN.
Instance methods
For instance methods, use the class name followed by the method name:
FQN: global::MyCorp.Web.RequestHelper.FilterParams
Java FQN format
Format: package.name.ClassName.methodName
How to identify your FQN
Find the
packagedeclaration at the top of your file.Find the class name containing your sanitizer method.
Find the method name.
Combine them with dots:
package.ClassName.methodName
Example
FQN: com.bank.security.XSSFilter.stripTags
Common pitfalls
Wildcard imports: Avoid
import com.example.security.*;. The engine struggles to trace functions imported this way. Use explicit imports:import com.example.security.Sanitizer;Static vs instance: Both static and instance methods are supported, but ensure the class is explicitly typed at the call site.
Instance methods
FQN: com.bank.utils.StringUtils.makeSafe
Kotlin FQN format
Format: package.name.ClassName.methodName or package.name.FileNameKt.functionName (for top-level functions)
How to identify your FQN
For class methods:
Find the
packagedeclaration.Find the class name.
Find the method name.
Combine:
package.ClassName.methodName
For top-level functions:
Find the
packagedeclaration.Find the file name (without extension).
Find the function name.
Combine:
package.FileNameKt.functionName
Example: Top-level function
FQN: com.app.helpers.UtilsKt.sanitizeInput
(Note: Kotlin compiles top-level functions into a class named FileName + Kt)
Example: Class method
FQN: com.app.security.Validator.clean
Common pitfalls
Implicit typing: Avoid
val x = Validator(). Use explicit types:val v: Validator = Validator()Wildcard imports: Same as Java—avoid wildcard imports for sanitizer classes.
Python FQN format
Format: module.submodule.function_name or module.ClassName.method_name
How to identify your FQN
Determine the module path from your project root.
Replace directory separators (
/) with dots (.).Add the function or class name.
For class methods, add the class name before the method:
module.ClassName.method_name
Example: Module function
FQN: project.security.text.remove_bad_chars
Example: Class method
FQN: project.utils.cleaner.InputScrubber.scrub
Common pitfalls
Decorators: You cannot define a sanitizer that is applied as a decorator (e.g.,
@my_sanitizer).
JavaScript/TypeScript FQN format
Format: module_name.export_name
How to identify your FQN
For named exports:
Identify the module path from your project root or npm package name.
Add the exported function name.
For npm packages:
Use the package name as it appears in
package.json.Add the exported function name.
Example: Named export
FQN: security.index.escapeSql
Example: NPM package
FQN: awesome-sanitizer.sanitizeHtml
Common pitfalls
Relative imports: The engine does not reliably resolve FQNs for functions imported using relative paths (e.g.,
import { clean } from '../../utils'). Use absolute module paths or npm package names instead.Default exports: Default exports are supported. Append
.defaultto the module path (e.g.,security.index.default).
Go FQN format
Format: host.com/user/project/package.Function
How to identify your FQN
Find the import path (e.g.,
github.com/myuser/utils).Find the function name (must be exported—starts with capital letter).
Combine: Use the full import path followed by
.FunctionName.
Example: Public function
Import Path: github.com/org/repo/pkg/input
FQN: github.com/org/repo/pkg/input.SanitizeString
(Note the dots replacing slashes)
Example: Struct method
FQN: github.com/org/repo/pkg/security.XSSBlocker.Block
Common pitfalls
Factory returns: Methods called on structs returned by interface factories often fail resolution. Use direct struct instantiation when possible.
Package path format: If the standard format fails, try replacing
/with.in the package path.
Apex FQN format
Format: ClassName.methodName or Namespace.ClassName.methodName
How to identify your FQN
Find the Apex class name containing your sanitizer method.
Find the method name.
If the class is in a managed package namespace, prepend the namespace.
Combine with a dot:
ClassName.methodNameorNamespace.ClassName.methodName
Example: Global class method
FQN: InputSanitizer.clean
Example: Managed package class method
FQN: MyCorp.SecurityUtils.escapeHtml
Common pitfalls
Inner classes: Include the outer class name:
OuterClass.InnerClass.methodNameValidation: Use the Impact Testing API to confirm the FQN resolves correctly in your org.
C/C++ FQN format
Format: namespace::functionName or namespace::ClassName::methodName
How to identify your FQN
Find the namespace declaration (if any).
Find the function or class method name.
Combine with
::separators.
Example: Namespace function
FQN: mycorp::security::sanitizeInput
Example: Class method
FQN: mycorp::security::InputSanitizer::clean
Common pitfalls
Missing namespace: If your function is in the global namespace, use
functionNameorClassName::methodNameonly.Header vs implementation: Use the namespace and name from the declaration the engine resolves at the call site.
Dart FQN format
Format: package_name/path/file.dart.functionName or package_name/path/file.dart.ClassName.methodName
How to identify your FQN
Find the package name from
pubspec.yaml.Find the library file path relative to the
lib/directory.Add the function or class method name.
Example: Top-level function
FQN: my_app/security/sanitizer.dart.removeBadChars
Example: Class method
FQN: my_app/security/sanitizer.dart.InputScrubber.scrub
Common pitfalls
Barrel exports: Prefer the file that defines the sanitizer, not a re-export file.
Private methods: Sanitizers must be public (no leading
_).
Groovy FQN format
Format: package.ClassName.methodName
Groovy follows the same FQN pattern as Java.
How to identify your FQN
Find the
packagedeclaration at the top of your file.Find the class name containing your sanitizer method.
Find the method name.
Combine them with dots:
package.ClassName.methodName
Example
FQN: com.example.security.XSSFilter.stripTags
Common pitfalls
Dynamic dispatch: Prefer explicit class references at the call site (for example,
XSSFilter.stripTags(input)).Scripts without packages: Use
ScriptClassName.methodNamewhereScriptClassNameis the compiled script class name.
PHP FQN format
Format: Namespace\ClassName\methodName or methodName
How to identify your FQN
Find the
namespacedeclaration in your sanitizer's file.Find the class name containing your sanitizer method.
Find the method name.
Combine with backslashes:
Namespace\ClassName\methodName
For some call patterns—especially chained instance method calls—the engine may resolve the sanitizer to the method name alone. Validate the FQN with the Impact Testing API.
Example 1: Static call on a namespaced class
FQN: App\Security\Sanitizer\sanitizeInput
Example 2: Chained instance method call
FQN: escape
Common pitfalls
Abstract or parent classes: Static calls on abstract classes resolve to the declaring class namespace path, not the concrete subclass.
Chained calls: When a sanitizer is invoked through a chain (for example,
$object->escape($input)), the FQN may be the method name only. Always confirm with an impact test.Global functions: Functions defined outside a namespace use the function name only (for example,
htmlspecialchars).
Ruby FQN format
Format: Module::Class.method_name or Module.method_name
How to identify your FQN
Find the module or class path to your sanitizer.
Find the method name.
Combine modules with
::and separate the method with.:Module::Class.method_name
Example: Class method
FQN: MyApp::Security::InputSanitizer.clean
Example: Module function
FQN: MyApp::Security::Sanitizer.escape_html
Common pitfalls
Mixins and
include: Prefer the module or class where the method is defined, not where it is mixed in.Unique method names: If the method name is unique in your project, the engine may resolve to the method name alone. Confirm with an impact test.
Rust FQN format
Format: crate::module::function_name or crate::module::StructName::method_name
How to identify your FQN
Find the crate name from
Cargo.toml.Find the module path to your sanitizer.
Add the function name, or the struct and method name for
implmethods.
Example: Public function
FQN: my_app::security::sanitize::sanitize_string
Example: Struct method
FQN: my_app::security::sanitize::InputSanitizer::clean
Common pitfalls
Re-exports: Prefer the module where the function is defined.
Private functions: Sanitizers must be
pub.
Scala FQN format
Format: package.ClassName.methodName or package.ObjectName.methodName
Scala follows the same FQN pattern as Java.
How to identify your FQN
Find the
packagedeclaration at the top of your file.Find the class or object name containing your sanitizer method.
Find the method name.
Combine them with dots:
package.ClassName.methodName
Example: Class method
FQN: com.bank.security.XSSFilter.stripTags
Example: Object method
FQN: com.bank.security.SecurityUtils.escapeHtml
Common pitfalls
Companion objects: Use the object name directly:
package.MyClass$.methodNameonly if the standard object name fails.Wildcard imports: Avoid wildcard imports for sanitizer classes.
Swift FQN format
Format: ModuleName.ClassName.methodName or ModuleName.functionName
How to identify your FQN
Find the module name (typically your target or framework name).
Find the type or function name.
Combine with dots.
Example: Struct method
FQN: MyApp.InputSanitizer.clean
Example: Top-level function
FQN: MyApp.sanitizeInput
Common pitfalls
Extensions: Prefer the type that owns the method at the call site.
Framework modules: For sanitizers in a framework target, use that target's module name as the prefix.
VB.NET FQN format
Format: global::Namespace.Class.Method
VB.NET follows the same FQN pattern as C#.
Important: VB.NET FQNs must include the global:: prefix.
How to identify your FQN
Find the namespace declaration in your sanitizer's file.
Find the class name containing your sanitizer method.
Find the method name.
Combine them with dots:
global::Namespace.Class.Method
Example
FQN: global::MyCorp.Security.InputSanitizer.Clean
Common pitfalls
Missing
global::prefix: Always includeglobal::at the start of your FQN.Modules: For methods in a VB module, use
global::Namespace.ModuleName.Method.
Step 2: Verify your function meets requirements
Before proceeding, ensure your sanitizer function:
✅ Is publicly accessible (public/exported)
✅ Has a unique name within your codebase
✅ Is not imported via wildcard (where applicable)
✅ Uses explicit types at call sites (for languages that support type inference)
Step 3: Check your call site
The way your sanitizer is called affects FQN resolution:
Supported patterns:
Static methods called with explicit class names
Instance methods on explicitly typed objects
Functions imported with absolute paths (not relative)
Problematic patterns:
Functions imported via wildcard imports (
import pkg.*)Functions called via relative imports (
import { func } from './utils')Implicitly typed variables (for languages with type inference)
Step 4: Test your FQN
After identifying your FQN:
Create a draft Rule Extension with your identified FQN.
Run an Impact Testing API test on a project that uses your sanitizer. This is the recommended way to confirm the FQN resolves correctly and to check the expected reduction in findings before you publish the Rule Extension.
Verify that false positives are reduced in the impact test results.
If issues persist, review the troubleshooting section below.
For more information on permissions and usage, see FAQ & troubleshooting.
Quick reference: FQN formats by language
Apex
ClassName.methodName or Namespace.ClassName.methodName
InputSanitizer.clean
C/C++
namespace::functionName or namespace::ClassName::methodName
mycorp::security::sanitizeInput
C#
global::Namespace.Class.Method
global::MyCorp.Security.InputSanitizer.Clean
Dart
package/path/file.dart.functionName
my_app/security/sanitizer.dart.removeBadChars
Go
host.com/user/project/package.Function
github.com/org/repo/pkg/input.SanitizeString
Groovy
package.ClassName.methodName
com.example.security.XSSFilter.stripTags
Java
package.ClassName.methodName
com.bank.security.XSSFilter.stripTags
JavaScript/TypeScript
module_name.export_name
security.index.escapeSql
Kotlin
package.ClassName.methodName or package.FileNameKt.functionName
com.app.security.Validator.clean
PHP
Namespace\ClassName\methodName or methodName
App\Security\Sanitizer\sanitizeInput
Python
module.function_name or module.ClassName.method_name
project.security.text.remove_bad_chars
Ruby
Module::Class.method_name
MyApp::Security::InputSanitizer.clean
Rust
crate::module::function_name or crate::module::StructName::method_name
my_app::security::sanitize::sanitize_string
Scala
package.ClassName.methodName
com.bank.security.XSSFilter.stripTags
Swift
ModuleName.ClassName.methodName
MyApp.InputSanitizer.clean
VB.NET
global::Namespace.Class.Method
global::MyCorp.Security.InputSanitizer.Clean
Troubleshooting FQN issues
My sanitizer isn't being recognized
Check these common issues:
Missing
global::prefix (C# and VB.NET): Ensure C# and VB.NET FQNs start withglobal::Wildcard imports: Replace wildcard imports with explicit imports
Relative imports (JS/TS): Use absolute module paths or npm package names
Case sensitivity: FQNs are case-sensitive—verify exact capitalization
PHP namespace separators: Use backslashes (
\), not dots, in PHP FQNsChained or dynamic calls (PHP, Ruby): The engine may resolve to the method name only—validate with the Impact Testing API
Still having issues?
If your sanitizer meets all requirements but still isn't recognized:
Verify the function is exported/public
Check that the function name matches exactly (case-sensitive)
Ensure the function is called with explicit types (where applicable)
Review the language-specific limitations in the tabs above
Run an Impact Testing API test to confirm the FQN and sanitization type
Contact your Snyk account team or Snyk support for assistance
Next steps
Once you've identified your FQN:
Read about sanitization types to determine which type matches your function's behavior
Review the supported rules to select which rules your sanitizer applies to
Follow the configuration guide to create your Rule Extension
Last updated
Was this helpful?

