Skip to content

Commit 23fdc35

Browse files
committed
Added test case @apollo/server with SSRF.
1 parent 179bae8 commit 23fdc35

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
import { ApolloServer } from '@apollo/server';
2+
import { get } from 'https';
3+
4+
function createApolloServer(typeDefs) {
5+
const resolvers = {
6+
Mutation: {
7+
downloadFiles: async (_, { files }) => { // $ MISSING: Source[js/request-forgery]
8+
files.forEach((file) => { get(file.url, (res) => {}); }); // $ MISSING: Alert[js/request-forgery] Sink[js/request-forgery]
9+
return true;
10+
},
11+
},
12+
};
13+
const server = new ApolloServer({typeDefs, resolvers});
14+
}

0 commit comments

Comments
 (0)