Skip to content

Commit 730396d

Browse files
committed
JS: add Mongoose createConnection tests
1 parent b7dc26e commit 730396d

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

  • javascript/ql/test/query-tests/Security/CWE-089/untyped

javascript/ql/test/query-tests/Security/CWE-089/untyped/mongoose.js

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -77,4 +77,7 @@ app.post('/documents/find', (req, res) => {
7777
.exec()
7878
;
7979

80+
Mongoose.createConnection(X).count(query); // OK (invalid program)
81+
Mongoose.createConnection(X).model(Y).count(query); // NOT OK
82+
Mongoose.createConnection(X).models[Y].count(query); // NOT OK
8083
});

0 commit comments

Comments
 (0)