Skip to content

Commit 68b2a6c

Browse files
dellaliberaesbena
andauthored
Update javascript/ql/src/experimental/Security/CWE-020/PostMessageNoOriginCheck.ql
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
1 parent 8843522 commit 68b2a6c

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

javascript/ql/src/experimental/Security/CWE-020/PostMessageNoOriginCheck.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,5 +65,5 @@ class PostMessageEvent extends DataFlow::SourceNode {
6565
}
6666

6767
from PostMessageEvent event
68-
where not event.hasOriginChecked()
68+
where not event.hasOriginChecked() or event.hasOriginInsufficientlyChecked()
6969
select event, "Missing or unsafe origin verification"

0 commit comments

Comments
 (0)