Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 7 additions & 4 deletions cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql
Original file line number Diff line number Diff line change
Expand Up @@ -38,19 +38,22 @@ predicate privateHostNameFlowsToExpr(Expr e) {
/**
* A string containing an HTTP URL not in a private domain.
*/
class HttpStringLiteral extends StringLiteral {
HttpStringLiteral() {
private class HttpStringLiteralCandidate extends StringLiteral {
HttpStringLiteralCandidate() {
exists(string s | this.getValue() = s |
s = "http"
or
exists(string tail |
tail = s.regexpCapture("http://(.*)", 1) and not tail instanceof PrivateHostName
)
) and
not privateHostNameFlowsToExpr(this.getParent*())
)
}
}

class HttpStringLiteral extends HttpStringLiteralCandidate {
HttpStringLiteral() { not privateHostNameFlowsToExpr(this.getParent*()) }
}

/**
* Taint tracking configuration for HTTP connections.
*/
Expand Down
Loading