JS: Use HTTP responses as taint sources

This commit is contained in:
Asger F
2024-06-13 09:33:06 +02:00
parent d88c498d49
commit 0751ef5c72

View File

@@ -177,3 +177,12 @@ private class ExternalRemoteFlowSource extends RemoteFlowSource {
override string getSourceType() { result = ap.getSourceType() }
}
/**
* A response from an outgoing network request.
*/
private class ResponseSource extends RemoteFlowSource {
ResponseSource() { this = any(ClientRequest r).getAResponseDataNode() }
override string getSourceType() { result = "a response from a remote server" }
}