mirror of
https://github.com/github/codeql.git
synced 2026-04-30 19:26:02 +02:00
JavaScript: Switch MissingRateLimiting.qll to API graphs.
The added test shows how this helps us avoid false positives.
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
import rateLimit from 'express-rate-limit';
|
||||
|
||||
const rateLimitMiddleware = rateLimit();
|
||||
|
||||
export default rateLimitMiddleware;
|
||||
8
javascript/ql/test/query-tests/Security/CWE-770/tst2.ts
Normal file
8
javascript/ql/test/query-tests/Security/CWE-770/tst2.ts
Normal file
@@ -0,0 +1,8 @@
|
||||
import express from 'express';
|
||||
import rateLimiter from './rateLimit';
|
||||
|
||||
const app = express();
|
||||
app.use(rateLimiter);
|
||||
app.get('/', (req, res) => {
|
||||
res.sendFile('index.html'); // OK
|
||||
});
|
||||
Reference in New Issue
Block a user