mirror of
https://github.com/github/codeql.git
synced 2025-12-21 03:06:31 +01:00
Add property params to RequestInputAccess
This commit is contained in:
@@ -134,7 +134,7 @@ module Hapi {
|
|||||||
kind = "parameter" and
|
kind = "parameter" and
|
||||||
exists(DataFlow::PropRead query |
|
exists(DataFlow::PropRead query |
|
||||||
// `request.query.name`
|
// `request.query.name`
|
||||||
query.accesses(request, "query") and
|
query.accesses(request, ["query", "params"]) and
|
||||||
this.(DataFlow::PropRead).accesses(query, _)
|
this.(DataFlow::PropRead).accesses(query, _)
|
||||||
)
|
)
|
||||||
or
|
or
|
||||||
|
|||||||
Reference in New Issue
Block a user