Merge pull request #13019 from jcogs33/jcogs33/url-open-stream-updates

Java: switch `url-open-stream` sink models to `experimentalSinkModel`
This commit is contained in:
Jami
2023-05-04 15:07:44 -04:00
committed by GitHub
7 changed files with 28 additions and 16 deletions

View File

@@ -17,6 +17,10 @@ import semmle.code.java.dataflow.FlowSources
import semmle.code.java.dataflow.ExternalFlow
import RemoteUrlToOpenStreamFlow::PathGraph
private class ActivateModels extends ActiveExperimentalModels {
ActivateModels() { this = "openstream-called-on-tainted-url" }
}
class UrlConstructor extends ClassInstanceExpr {
UrlConstructor() { this.getConstructor().getDeclaringType() instanceof TypeUrl }