@@ -185,8 +185,8 @@ private string suspicious() {
185185 result =
186186 [
187187 "%password%" , "%passwd%" , "%pwd%" , "%refresh%token%" , "%secret%token" , "%secret%key" ,
188- "%passcode%" , "%passphrase%" , "%token%" , "%secret%" , "%credential%" , "%userpass%" ,
189- "%digest%" , "% signature%", "%mac%"
188+ "%passcode%" , "%passphrase%" , "%token%" , "%secret%" , "%credential%" , "%userpass%" , "%digest%" ,
189+ "%signature%" , "%mac%"
190190 ]
191191}
192192
@@ -208,7 +208,8 @@ abstract class ClientSuppliedSecret extends API::CallNode { }
208208private class FlaskClientSuppliedSecret extends ClientSuppliedSecret {
209209 FlaskClientSuppliedSecret ( ) {
210210 this = Flask:: request ( ) .getMember ( "headers" ) .getMember ( [ "get" , "get_all" , "getlist" ] ) .getACall ( ) and
211- this .getParameter ( 0 , [ "key" , "name" ] ) .asSink ( ) .asExpr ( ) .( StrConst ) .getText ( ) .toLowerCase ( ) = sensitiveheaders ( )
211+ this .getParameter ( 0 , [ "key" , "name" ] ) .asSink ( ) .asExpr ( ) .( StrConst ) .getText ( ) .toLowerCase ( ) =
212+ sensitiveheaders ( )
212213 }
213214}
214215
@@ -219,7 +220,8 @@ private class DjangoClientSuppliedSecret extends ClientSuppliedSecret {
219220 .getMember ( [ "headers" , "META" ] )
220221 .getMember ( "get" )
221222 .getACall ( ) and
222- this .getParameter ( 0 , "key" ) .asSink ( ) .asExpr ( ) .( StrConst ) .getText ( ) .toLowerCase ( ) = sensitiveheaders ( )
223+ this .getParameter ( 0 , "key" ) .asSink ( ) .asExpr ( ) .( StrConst ) .getText ( ) .toLowerCase ( ) =
224+ sensitiveheaders ( )
223225 }
224226}
225227
@@ -231,7 +233,8 @@ API::Node requesthandler() {
231233private class TornadoClientSuppliedSecret extends ClientSuppliedSecret {
232234 TornadoClientSuppliedSecret ( ) {
233235 this = requesthandler ( ) .getMember ( [ "headers" , "META" ] ) .getMember ( "get" ) .getACall ( ) and
234- this .getParameter ( 0 , "key" ) .asSink ( ) .asExpr ( ) .( StrConst ) .getText ( ) .toLowerCase ( ) = sensitiveheaders ( )
236+ this .getParameter ( 0 , "key" ) .asSink ( ) .asExpr ( ) .( StrConst ) .getText ( ) .toLowerCase ( ) =
237+ sensitiveheaders ( )
235238 }
236239}
237240
@@ -244,7 +247,8 @@ private class WerkzeugClientSuppliedSecret extends ClientSuppliedSecret {
244247 WerkzeugClientSuppliedSecret ( ) {
245248 this =
246249 headers ( ) .getMember ( [ "headers" , "META" ] ) .getMember ( [ "get" , "get_all" , "getlist" ] ) .getACall ( ) and
247- this .getParameter ( 0 , [ "key" , "name" ] ) .asSink ( ) .asExpr ( ) .( StrConst ) .getText ( ) .toLowerCase ( ) = sensitiveheaders ( )
250+ this .getParameter ( 0 , [ "key" , "name" ] ) .asSink ( ) .asExpr ( ) .( StrConst ) .getText ( ) .toLowerCase ( ) =
251+ sensitiveheaders ( )
248252 }
249253}
250254
0 commit comments