Skip to content

Commit 081765c

Browse files
Apply suggestions from code review
Co-authored-by: Asger F <[email protected]>
1 parent a616059 commit 081765c

File tree

2 files changed

+4
-2
lines changed

2 files changed

+4
-2
lines changed

javascript/ql/src/Security/CWE-843/examples/TypeConfusionThroughParameterTampering.js

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,8 @@ var app = require("express")(),
44
app.get("/user-files", function(req, res) {
55
var file = req.param("file");
66
if (file.indexOf("..") !== -1) {
7-
// BAD: we forbid relative paths that contain ..
7+
// BAD
8+
// we forbid relative paths that contain ..
89
// as these could leave the public directory
910
res.status(400).send("Bad request");
1011
} else {

javascript/ql/src/Security/CWE-843/examples/TypeConfusionThroughParameterTampering_fixed.js

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,8 @@ var app = require("express")(),
44
app.get("/user-files", function(req, res) {
55
var file = req.param("file");
66
if (typeof file !== 'string' || file.indexOf("..") !== -1) {
7-
// BAD: we forbid relative paths that contain ..
7+
// GOOD
8+
// we forbid relative paths that contain ..
89
// as these could leave the public directory
910
res.status(400).send("Bad request");
1011
} else {

0 commit comments

Comments
 (0)