mirror of
https://github.com/github/codeql.git
synced 2026-05-18 21:27:08 +02:00
JS: Use HTTP responses as taint sources
This commit is contained in:
@@ -177,3 +177,12 @@ private class ExternalRemoteFlowSource extends RemoteFlowSource {
|
||||
|
||||
override string getSourceType() { result = ap.getSourceType() }
|
||||
}
|
||||
|
||||
/**
|
||||
* A response from an outgoing network request.
|
||||
*/
|
||||
private class ResponseSource extends RemoteFlowSource {
|
||||
ResponseSource() { this = any(ClientRequest r).getAResponseDataNode() }
|
||||
|
||||
override string getSourceType() { result = "a response from a remote server" }
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user