From f77d46f29697a0253fc7c30a257ccb3f38192cbc Mon Sep 17 00:00:00 2001 From: Sauyon Lee Date: Wed, 25 Mar 2020 03:27:30 -0700 Subject: [PATCH] Address review comments. --- ql/src/semmle/go/security/OpenUrlRedirect.qll | 9 --------- 1 file changed, 9 deletions(-) diff --git a/ql/src/semmle/go/security/OpenUrlRedirect.qll b/ql/src/semmle/go/security/OpenUrlRedirect.qll index d2ced212267..fb3efd2006f 100644 --- a/ql/src/semmle/go/security/OpenUrlRedirect.qll +++ b/ql/src/semmle/go/security/OpenUrlRedirect.qll @@ -30,15 +30,6 @@ module OpenUrlRedirect { override predicate isBarrier(DataFlow::Node node) { node instanceof Barrier } override predicate isAdditionalFlowStep(DataFlow::Node pred, DataFlow::Node succ) { - // A write to URL.Host - exists(Write write, Field f, DataFlow::SsaNode var | - write.writesField(var.getAUse(), f, pred) and - succ = var.getAUse() and - write.getASuccessor+() = succ.asInstruction() and - f.getName() = "Host" and - var.getType().hasQualifiedName("net/url", "URL") - ) - or // taint steps that do not include flow through fields TaintTracking::localTaintStep(pred, succ) and not TaintTracking::fieldReadStep(pred, succ) or