XSS: expose extension point for defining barrier sinks

This commit is contained in:
Chris Smowton
2021-06-25 14:40:18 +01:00
parent 10a6089739
commit 3e7ea34054
2 changed files with 8 additions and 0 deletions

View File

@@ -25,6 +25,8 @@ class XSSConfig extends TaintTracking::Configuration {
override predicate isSanitizer(DataFlow::Node node) { node instanceof XssSanitizer }
override predicate isSanitizerOut(DataFlow::Node node) { node instanceof XssSinkBarrier }
override predicate isAdditionalTaintStep(DataFlow::Node node1, DataFlow::Node node2) {
any(XssAdditionalTaintStep s).step(node1, node2)
}