Update javascript/ql/src/experimental/Security/CWE-020/PostMessageNoOriginCheck.ql

Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
This commit is contained in:
Alessio Della Libera
2020-06-16 18:22:55 +02:00
committed by GitHub
parent e8b05b70c4
commit 72dc6510b2

View File

@@ -33,7 +33,7 @@ class InsufficientOriginChecks extends DataFlow::MethodCallNode {
* A function handler for the `MessageEvent`.
*/
class PostMessageHandler extends DataFlow::FunctionNode {
PostMessageHandler() { exists(PostMessageEventHandler handler | this.getFunction() = handler) }
PostMessageHandler() { this.getFunction() instanceof PostMessageEventHandler }
}
/**