mirror of
https://github.com/github/codeql.git
synced 2026-03-05 07:06:47 +01:00
Java: add comment about request-forgery sinks
This commit is contained in:
@@ -30,6 +30,7 @@ class HttpStringLiteral extends StringLiteral {
|
||||
abstract class UrlOpenSink extends DataFlow::Node { }
|
||||
|
||||
private class DefaultUrlOpenSink extends UrlOpenSink {
|
||||
// request-forgery sinks control the URL of a request
|
||||
DefaultUrlOpenSink() { sinkNode(this, "request-forgery") }
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user