Skip to content

Commit 91deb4e

Browse files
committed
JS: Move two alerts and add query ID
1 parent 4613280 commit 91deb4e

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

javascript/ql/test/query-tests/Security/CWE-918/serverSide.js

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,8 @@ var server = http.createServer(function(req, res) {
2020
request.get(tainted); // $ Alert[js/request-forgery]
2121

2222
var options = {};
23-
options.url = tainted; // $ Alert
24-
request(options);
23+
options.url = tainted;
24+
request(options); // $ Alert[js/request-forgery]
2525

2626
request("http://" + tainted); // $ Alert[js/request-forgery]
2727

@@ -124,8 +124,8 @@ var server2 = http.createServer(function(req, res) {
124124

125125
axios({
126126
method: 'get',
127-
url: tainted // $ Alert
128-
})
127+
url: tainted
128+
}) // $ Alert[js/request-forgery]
129129

130130
var myUrl = `${something}/bla/${tainted}`;
131131
axios.get(myUrl); // $ Alert[js/request-forgery]

0 commit comments

Comments
 (0)