Files
codeql/python/ql/test/experimental/query-tests/Security/CWE-614/flask_bad.py
2021-07-25 04:06:02 +02:00

35 lines
706 B
Python

from flask import Flask, request, make_response, Response
app = Flask(__name__)
@app.route("/false")
def false():
resp = make_response()
resp.set_cookie("name", value="value", secure=False)
return resp
@app.route("/none")
def none():
resp = make_response()
resp.set_cookie("name", value="value", secure=None)
return resp
@app.route("/flask_Response")
def flask_Response():
resp = Response()
resp.headers['Set-Cookie'] = "name=value;"
return resp
@app.route("/flask_make_response")
def flask_make_response():
resp = make_response("hello")
resp.headers['Set-Cookie'] = "name=value;"
return resp
# if __name__ == "__main__":
# app.run(debug=True)