Skip to content
This repository was archived by the owner on Jan 5, 2023. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
  • Loading branch information
gagliardetto and smowton committed Apr 8, 2021
commit dc95902e56b4917417fdc2eca03b8cb1a9b2a168
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
that allow values to be rendered as-is in the template, avoiding the escaping that all the other strings go
through.
</p>
<p>Using them on user-provided values will result in an XSS.</p>
<p>Using them on user-provided values will result in an opportunity for XSS.</p>
</overview>
<recommendation>
<p>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -42,10 +42,9 @@ class PassthroughTypeName extends string {
* output of the templates.
*/
class FlowConfFromUntrustedToPassthroughTypeConversion extends TaintTracking::Configuration {
string dstTypeName;
PassthroughTypeName dstTypeName;

FlowConfFromUntrustedToPassthroughTypeConversion() {
dstTypeName instanceof PassthroughTypeName and
this = "UntrustedToConversion" + dstTypeName
}

Expand Down Expand Up @@ -105,11 +104,10 @@ class FlowConfPassthroughTypeConversionToTemplateExecutionCall extends TaintTrac
isSourceConversionToPassthroughType(source, _)
}

private predicate isSourceConversionToPassthroughType(DataFlow::TypeCastNode source, string name) {
private predicate isSourceConversionToPassthroughType(DataFlow::TypeCastNode source, PassthroughTypeName name) {
exists(Type typ |
typ = source.getResultType() and
typ.getUnderlyingType*().hasQualifiedName("html/template", name) and
name instanceof PassthroughTypeName
typ.getUnderlyingType*().hasQualifiedName("html/template", name)
)
}

Expand Down