From a3a4c31911b561bcb9c2ae6ae98e32fc9e0f4135 Mon Sep 17 00:00:00 2001 From: Ed Minnix Date: Fri, 28 Jul 2023 15:48:35 -0400 Subject: [PATCH] Replace servlet source node with RemoteFlowSource --- .../code/java/security/TrustBoundaryViolationQuery.qll | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/java/ql/lib/semmle/code/java/security/TrustBoundaryViolationQuery.qll b/java/ql/lib/semmle/code/java/security/TrustBoundaryViolationQuery.qll index 337c228bc75..d2a1c4c54de 100644 --- a/java/ql/lib/semmle/code/java/security/TrustBoundaryViolationQuery.qll +++ b/java/ql/lib/semmle/code/java/security/TrustBoundaryViolationQuery.qll @@ -12,11 +12,8 @@ private import semmle.code.java.frameworks.owasp.Esapi */ abstract class TrustBoundaryViolationSource extends DataFlow::Node { } -/** - * A node representing a servlet request. - */ -private class ServletRequestSource extends TrustBoundaryViolationSource { - ServletRequestSource() { this.asExpr().getType() instanceof HttpServletRequest } +private class RemoteSource extends TrustBoundaryViolationSource { + RemoteSource() { this instanceof RemoteFlowSource } } /**