Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss/jwt.js
2025-02-28 13:27:28 +01:00

8 lines
234 B
JavaScript

import jwt_decode from "jwt-decode";
import $ from "jquery"
$.post(loginUrl(), {data: "foo"}, (data, xhr) => {
var decoded = jwt_decode(data);
$.jGrowl(decoded); // $ MISSING: Alert - only flagged with additional sources
});