Skip to content
This repository was archived by the owner on Jan 5, 2023. It is now read-only.
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Fix test
  • Loading branch information
gagliardetto authored and smowton committed Apr 8, 2021
commit 0bb5ef6af2a29d103efb94c62f694252324ac0e0
4 changes: 2 additions & 2 deletions ql/test/experimental/CWE-79/HTMLTemplateEscapingPassthrough.go
100755 → 100644
Original file line number Diff line number Diff line change
Expand Up @@ -71,13 +71,13 @@ func bad(req *http.Request) {
func good(req *http.Request) {
tmpl, _ := template.New("test").Parse(`Hello, {{.}}\n`)
{ // This will be escaped, so it shoud NOT be caught:
var escaped = source(`<a href="example.com">link</a>`)
var escaped = req.UserAgent()
checkError(tmpl.Execute(os.Stdout, escaped))
}
{
// The converted source value does NOT flow to tmpl.Exec,
// so this should NOT be caught.
src := source(`<a href='example.com'>link</a>`)
src := req.UserAgent()
converted := template.HTML(src)
_ = converted
checkError(tmpl.Execute(os.Stdout, src))
Expand Down