Skip to content

Commit ad7d40f

Browse files
committed
Add missing QLDoc
1 parent 2a30898 commit ad7d40f

File tree

2 files changed

+11
-0
lines changed

2 files changed

+11
-0
lines changed

go/ql/lib/semmle/go/security/MissingJwtSignatureCheck.qll

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ import go
1111
module MissingJwtSignatureCheck {
1212
import MissingJwtSignatureCheckCustomizations::MissingJwtSignatureCheck
1313

14+
/** Config for reasoning about JWT vulnerabilities. */
1415
module Config implements DataFlow::ConfigSig {
1516
predicate isSource(DataFlow::Node source) {
1617
source instanceof Source and
@@ -24,6 +25,7 @@ module MissingJwtSignatureCheck {
2425
}
2526
}
2627

28+
/** Tracks taint flow for reasoning about JWT vulnerabilities. */
2729
module Flow = TaintTracking::Global<Config>;
2830

2931
private module SafeParseConfig implements DataFlow::ConfigSig {

go/ql/lib/semmle/go/security/MissingJwtSignatureCheckCustomizations.qll

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,16 @@
1+
/**
2+
* Provides default sources, sinks, and sanitizers for reasoning about
3+
* JWT vulnerabilities, as well as extension points for adding your own.
4+
*/
5+
16
import go
27
private import semmle.go.dataflow.ExternalFlow
38
private import codeql.util.Unit
49

10+
/**
11+
* Provides extension points for customizing the data-flow tracking configuration for reasoning
12+
* about JWT vulnerabilities.
13+
*/
514
module MissingJwtSignatureCheck {
615
/**
716
* A data flow source for JWT vulnerabilities.

0 commit comments

Comments
 (0)