JS: recognize tiny-csrf

This commit is contained in:
Asger F
2022-12-14 12:25:25 +01:00
parent 162419138d
commit b63c658e3b

View File

@@ -57,7 +57,7 @@ predicate hasCookieMiddleware(Routing::Node route, Http::CookieMiddlewareInstanc
*/
DataFlow::SourceNode csrfMiddlewareCreation() {
exists(DataFlow::SourceNode callee | result = callee.getACall() |
callee = DataFlow::moduleImport("csurf")
callee = DataFlow::moduleImport(["csurf", "tiny-csrf"])
or
callee = DataFlow::moduleImport("lusca") and
exists(result.(DataFlow::CallNode).getOptionArgument(0, "csrf"))