Merge pull request #6162 from smowton/smowton/feature/jax-rs-content-type-sensitivity-fixes

Jax-RS: implement content-type tracking
This commit is contained in:
Chris Smowton
2021-08-03 14:53:31 +01:00
committed by GitHub
8 changed files with 228 additions and 37 deletions

View File

@@ -25,6 +25,8 @@ class XSSConfig extends TaintTracking::Configuration {
override predicate isSanitizer(DataFlow::Node node) { node instanceof XssSanitizer }
override predicate isSanitizerOut(DataFlow::Node node) { node instanceof XssSinkBarrier }
override predicate isAdditionalTaintStep(DataFlow::Node node1, DataFlow::Node node2) {
any(XssAdditionalTaintStep s).step(node1, node2)
}