Correct string source

This commit is contained in:
luchua-bc
2022-05-11 10:37:22 +00:00
parent 75e7148912
commit f85c01c975

View File

@@ -77,7 +77,7 @@ abstract class JwtTokenSink extends DataFlow::Node { }
* A hardcoded string literal as a source for JWT token signing vulnerabilities.
*/
class HardcodedKeyStringSource extends JwtKeySource {
HardcodedKeyStringSource() { this.asExpr() instanceof CompileTimeConstantExpr }
HardcodedKeyStringSource() { exists(this.asExpr().(CompileTimeConstantExpr).getStringValue()) }
}
/**