Files
codeql/javascript/ql/test/query-tests/Security/CWE-352/MissingCsrfMiddleware.qlref
Asger F cd2c4d5e3a JS: Use post-processed inline test in MissingCsrfMiddleware
This query flags the cookie-parsing middleware in order to consolidate huge numbers of alerts into a single alert, which is more manageable. But simply annotating the cookie-parsing middleware with 'Alert' isn't a very useful, we want to annotate which middlewares are vulnerable.
2025-02-21 14:44:46 +01:00

3 lines
104 B
Plaintext

query: Security/CWE-352/MissingCsrfMiddleware.ql
postprocess: utils/test/InlineExpectationsTestQuery.ql