Files
codeql/javascript/ql/test/library-tests/TaintTracking/closure.js
2019-02-25 16:08:47 +00:00

13 lines
237 B
JavaScript

goog.module('test');
let string = goog.require('goog.string');
function test() {
let taint = source();
sink(string.capitalize(taint)); // NOT OK
sink(string.trim(taint)); // NOT OK
sink(string.escapeString(taint)); // OK
}