We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
encodeURI
1 parent 55eb9fb commit deb715aCopy full SHA for deb715a
javascript/ql/test/query-tests/Security/CWE-918/serverSide.js
@@ -141,4 +141,8 @@ var server2 = http.createServer(function(req, res) {
141
axios.get(target.toString()); // $Alert[js/request-forgery]
142
axios.get(target); // $Alert[js/request-forgery]
143
axios.get(target.href); // $Alert[js/request-forgery]
144
+ const encodedUrl = encodeURI(input);
145
+ axios.get(encodedUrl); // $MISSING:Alert[js/request-forgery]
146
+ const escapedUrl = escape(input);
147
+ axios.get(escapedUrl); // $MISSING:Alert[js/request-forgery]
148
});
0 commit comments