Update TimingAttackAgainstHeaderValue.ql

This commit is contained in:
Ahmed Farid
2023-02-16 01:11:41 +01:00
committed by GitHub
parent 016136a2e3
commit b8f9b2b424

View File

@@ -24,13 +24,7 @@ class ClientSuppliedSecretConfig extends TaintTracking::Configuration {
override predicate isSource(DataFlow::Node source) { source instanceof ClientSuppliedSecret }
override predicate isSink(DataFlow::Node sink) {
exists(Compare cmp, Expr left, Expr right, Cmpop cmpop |
cmpop.getSymbol() = ["==", "in", "is not", "!="] and
cmp.compares(left, cmpop, right) and
sink.asExpr() = [left, right]
)
}
override predicate isSink(DataFlow::Node sink) { sink instanceof CompareSink }
}
from ClientSuppliedSecretConfig config, DataFlow::PathNode source, DataFlow::PathNode sink