We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 764eb98 commit 4d7cbe6Copy full SHA for 4d7cbe6
1 file changed
javascript/ql/test/query-tests/Security/CWE-918/serverSide.js
@@ -106,15 +106,15 @@ import * as ws from 'ws';
106
new ws.Server({ port: 8080 }).on('connection', function(socket, request) {
107
socket.on('message', function(message) {
108
const url = request.url;
109
- const socket = new ws(url);
+ const socket = new ws(url); // $ Alert[js/request-forgery]
110
});
111
112
113
new ws.Server({ port: 8080 }).on('connection', function (socket, request) {
114
socket.on('message', function (message) {
115
const url = new URL(request.url, base);
116
const target = new URL(url.pathname, base);
117
118
119
120
0 commit comments