Merge pull request #5655 from erik-krogh/cert

Approved by esbena
This commit is contained in:
CodeQL CI
2021-04-12 07:31:04 -07:00
committed by GitHub
4 changed files with 28 additions and 1 deletions

View File

@@ -16,7 +16,7 @@ import javascript
*/
DataFlow::ObjectLiteralNode tlsOptions() {
exists(DataFlow::InvokeNode invk | result.flowsTo(invk.getAnArgument()) |
invk instanceof NodeJSLib::NodeJSClientRequest
invk instanceof ClientRequest
or
invk = DataFlow::moduleMember("https", "Agent").getAnInstantiation()
or

View File

@@ -1,3 +1,4 @@
| tst2.js:8:5:8:29 | rejectU ... : false | Disabling certificate validation is strongly discouraged. |
| tst.js:15:3:15:27 | rejectU ... : false | Disabling certificate validation is strongly discouraged. |
| tst.js:18:1:18:40 | process ... HORIZED | Disabling certificate validation is strongly discouraged. |
| tst.js:21:3:21:27 | rejectU ... : false | Disabling certificate validation is strongly discouraged. |

View File

@@ -0,0 +1,24 @@
const request = require('request');
let requestOptions = {
headers: {
"content-type": "application/json",
"accept": "application/json"
},
rejectUnauthorized: false,
requestCert: true,
agent: false
}
module.exports.post = (url, requestBody, apiContext) => {
Object.assign(requestOptions, {
body: JSON.stringify(requestBody),
headers : Object.assign(requestOptions.headers, apiContext)
})
return request.post(url, requestOptions).then((res) => {
return Promise.resolve(res.body);
}).catch((err) => {
return Promise.resolve(err);
})
}