mirror of
https://github.com/github/codeql.git
synced 2026-05-01 11:45:14 +02:00
apply review comments
This commit is contained in:
@@ -40,11 +40,10 @@ private class PatternQuoteCall extends RegexInjectionSanitizer {
|
||||
*/
|
||||
private class PatternLiteralFlag extends RegexInjectionSanitizer {
|
||||
PatternLiteralFlag() {
|
||||
exists(MethodAccess ma, Method m, Field field | m = ma.getMethod() |
|
||||
exists(MethodAccess ma, Method m, PatternLiteralField field | m = ma.getMethod() |
|
||||
ma.getArgument(0) = this.asExpr() and
|
||||
m.getDeclaringType() instanceof TypeRegexPattern and
|
||||
m.hasName("compile") and
|
||||
field instanceof PatternLiteralField and
|
||||
ma.getArgument(1) = field.getAnAccess()
|
||||
)
|
||||
}
|
||||
|
||||
@@ -2,7 +2,6 @@ import java
|
||||
import TestUtilities.InlineExpectationsTest
|
||||
import semmle.code.java.security.regexp.RegexInjectionQuery
|
||||
|
||||
//import semmle.code.java.security.regexp.PolynomialReDoSQuery
|
||||
class RegexInjectionTest extends InlineExpectationsTest {
|
||||
RegexInjectionTest() { this = "RegexInjectionTest" }
|
||||
|
||||
|
||||
Reference in New Issue
Block a user