Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/ExceptionXss/ajv.js
2021-03-02 12:39:04 +00:00

14 lines
325 B
JavaScript

import express from 'express';
import Ajv from 'ajv';
let app = express();
let ajv = new Ajv();
ajv.addSchema({type: 'object', additionalProperties: {type: 'number'}}, 'pollData');
app.post('/polldata', (req, res) => {
if (!ajv.validate('pollData', req.body)) {
res.send(ajv.errorsText()); // NOT OK
}
});