Skip to content

Commit 766d07b

Browse files
committed
Revert "JS: Use an actual sanitizer in test"
This reverts commit 267157b255d9612dc5e8a8c6bb4f4d8138674909.
1 parent 2d08a6e commit 766d07b

File tree

1 file changed

+1
-1
lines changed
  • javascript/ql/test/query-tests/Security/CWE-601/ServerSideUrlRedirect

1 file changed

+1
-1
lines changed

javascript/ql/test/query-tests/Security/CWE-601/ServerSideUrlRedirect/express.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ app.get('/some/other/path2', function(req, res) {
2323

2424
app.get('/some/path', function(req, res) {
2525
var target = req.param("target");
26-
if (target.startsWith("https://example.com/"))
26+
if (isLocalURL(target))
2727
// OK - request parameter is sanitized before incorporating it into the redirect
2828
res.redirect(target);
2929
else

0 commit comments

Comments
 (0)