From 0bb5ef6af2a29d103efb94c62f694252324ac0e0 Mon Sep 17 00:00:00 2001 From: Slavomir Date: Mon, 8 Mar 2021 19:19:21 +0100 Subject: [PATCH] Fix test --- .../experimental/CWE-79/HTMLTemplateEscapingPassthrough.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) mode change 100755 => 100644 ql/test/experimental/CWE-79/HTMLTemplateEscapingPassthrough.go diff --git a/ql/test/experimental/CWE-79/HTMLTemplateEscapingPassthrough.go b/ql/test/experimental/CWE-79/HTMLTemplateEscapingPassthrough.go old mode 100755 new mode 100644 index b0b5325eb62..e0468e4bfb2 --- a/ql/test/experimental/CWE-79/HTMLTemplateEscapingPassthrough.go +++ b/ql/test/experimental/CWE-79/HTMLTemplateEscapingPassthrough.go @@ -71,13 +71,13 @@ func bad(req *http.Request) { func good(req *http.Request) { tmpl, _ := template.New("test").Parse(`Hello, {{.}}\n`) { // This will be escaped, so it shoud NOT be caught: - var escaped = source(`link`) + var escaped = req.UserAgent() checkError(tmpl.Execute(os.Stdout, escaped)) } { // The converted source value does NOT flow to tmpl.Exec, // so this should NOT be caught. - src := source(`link`) + src := req.UserAgent() converted := template.HTML(src) _ = converted checkError(tmpl.Execute(os.Stdout, src))