Skip to content

Commit 35abc3f

Browse files
ahmed-farid-devsmowton
authored andcommitted
Update and rename ComparingValueOfSensetiveHeader.java to Test.java
1 parent 0912279 commit 35abc3f

File tree

2 files changed

+20
-17
lines changed

2 files changed

+20
-17
lines changed

java/ql/src/experimental/Security/CWE/CWE-208/ComparingValueOfSensetiveHeader.java

Lines changed: 0 additions & 17 deletions
This file was deleted.
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
import javax.servlet.http.HttpServletRequest;
2+
import java.nio.charset.StandardCharsets;
3+
import java.security.MessageDigest;
4+
import java.lang.String;
5+
6+
7+
public class Test {
8+
private boolean UnsafeComparison(HttpServletRequest request) {
9+
String Key = "secret";
10+
return Key.equals(request.getHeader("X-Auth-Token"));
11+
}
12+
13+
private boolean safeComparison(HttpServletRequest request) {
14+
String token = request.getHeader("X-Auth-Token");
15+
String Key = "secret";
16+
return MessageDigest.isEqual(Key.getBytes(StandardCharsets.UTF_8), token.getBytes(StandardCharsets.UTF_8));
17+
}
18+
19+
}
20+

0 commit comments

Comments
 (0)