Skip to content

Commit cc1d2c4

Browse files
committed
JS: add extra test case with }
1 parent 953bd90 commit cc1d2c4

File tree

2 files changed

+2
-0
lines changed

2 files changed

+2
-0
lines changed

javascript/ql/test/query-tests/Security/CWE-116/IncompleteSanitization/IncompleteSanitization.expected

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,3 +35,4 @@
3535
| tst.js:353:9:353:17 | s.replace | This does not escape backslash characters in the input. | tst.js:353:19:353:50 | new Reg ... lags()) | |
3636
| tst.js:362:2:362:10 | x.replace | This replaces only the first occurrence of $@. | tst.js:362:12:362:27 | new RegExp("\\n") | this node |
3737
| tst.js:363:2:363:24 | x.repla ... replace | This replaces only the first occurrence of $@. | tst.js:363:26:363:41 | new RegExp("\\n") | this node |
38+
| tst.js:367:2:367:24 | x.repla ... replace | This replaces only the first occurrence of $@. | tst.js:367:26:367:28 | '}' | '}' |

javascript/ql/test/query-tests/Security/CWE-116/IncompleteSanitization/tst.js

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -364,4 +364,5 @@ function newlinesNewReGexp(s) {
364364

365365
x.replace(new RegExp("\n", unknownFlags()), "").replace(x, y);
366366
x.replace(x, y).replace(new RegExp("\n", unknownFlags()), "");
367+
x.replace(x, y).replace('}', ""); // $ Alert[js/incomplete-sanitization]
367368
}

0 commit comments

Comments
 (0)