mirror of
https://github.com/github/codeql.git
synced 2026-04-30 19:26:02 +02:00
Stop considering usernames sensitive info
Require variables to be static to be considered constants
This commit is contained in:
@@ -5,12 +5,18 @@ class Test {
|
||||
Logger logger = null;
|
||||
|
||||
logger.info("User's password is: " + password); // $ hasTaintFlow
|
||||
}
|
||||
}
|
||||
|
||||
void test2(String authToken) {
|
||||
Logger logger = null;
|
||||
|
||||
logger.error("Auth failed for: " + authToken); // $ hasTaintFlow
|
||||
logger.error("Auth failed for: " + authToken); // $ hasTaintFlow
|
||||
}
|
||||
|
||||
}
|
||||
void test3(String username) {
|
||||
Logger logger = null;
|
||||
|
||||
logger.error("Auth failed for: " + username); // Safe
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user