From b3bb4cbf541c83eaec474a4599e9fe7a0b406508 Mon Sep 17 00:00:00 2001 From: Remco Vermeulen Date: Thu, 9 Jul 2020 16:14:21 +0200 Subject: [PATCH] Rename and update qldoc of default safe header splitting source --- java/ql/src/semmle/code/java/security/ResponseSplitting.qll | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/java/ql/src/semmle/code/java/security/ResponseSplitting.qll b/java/ql/src/semmle/code/java/security/ResponseSplitting.qll index 02728211e94..b53c90557f5 100644 --- a/java/ql/src/semmle/code/java/security/ResponseSplitting.qll +++ b/java/ql/src/semmle/code/java/security/ResponseSplitting.qll @@ -40,9 +40,9 @@ private class ServletHeaderSplittingSink extends HeaderSplittingSink { } } -/** Servlet sources considered safe regarding header splitting */ -private class ServletSafeHeaderSplittingSource extends SafeHeaderSplittingSource { - ServletSafeHeaderSplittingSource() { +/** Sources of data considered safe to use by header splitting sinks. */ +private class DefaultSafeHeaderSplittingSource extends SafeHeaderSplittingSource { + DefaultSafeHeaderSplittingSource() { this.asExpr().(MethodAccess).getMethod() instanceof HttpServletRequestGetHeaderMethod or this.asExpr().(MethodAccess).getMethod() instanceof CookieGetNameMethod }