Skip to content

Commit 3dc07ce

Browse files
committed
Allow MaD sanitizers for java/unvalidated-url-redirection
1 parent 03a43b8 commit 3dc07ce

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

java/ql/lib/semmle/code/java/security/UrlRedirect.qll

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,5 +50,9 @@ private class ApacheUrlRedirectSink extends UrlRedirectSink {
5050
}
5151
}
5252

53-
private class DefaultUrlRedirectSanitizer extends UrlRedirectSanitizer instanceof RequestForgerySanitizer
53+
private class RequestForgeryUrlRedirectSanitizer extends UrlRedirectSanitizer instanceof RequestForgerySanitizer
5454
{ }
55+
56+
private class ExternalUrlRedirectSanitizer extends UrlRedirectSanitizer {
57+
ExternalUrlRedirectSanitizer() { barrierNode(this, "url-redirection") }
58+
}

0 commit comments

Comments
 (0)