Skip to content

Commit d814e73

Browse files
committed
update comment position to match alert location for CWE-798
1 parent bcffc97 commit d814e73

File tree

1 file changed

+31
-31
lines changed

1 file changed

+31
-31
lines changed

javascript/ql/test/query-tests/Security/CWE-798/HardcodedCredentials.js

Lines changed: 31 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
const pg = require('pg');
33

44
const client = new pg.Client({
5-
user: 'dbuser',
5+
user: 'dbuser', // NOT OK
66
host: 'database.server.com',
77
database: 'mydb',
8-
password: 'abcdefgh',
8+
password: 'abcdefgh', // NOT OK
99
port: 3211,
10-
}); // NOT OK
10+
});
1111
client.connect();
1212
})();
1313

@@ -26,8 +26,8 @@
2626

2727
basicAuth({users: { 'admin': 'abcdefgh' }}); // NOT OK
2828
var users = {};
29-
users['unknown-admin-name'] = 'abcdefgh';
30-
basicAuth({users: users}) // NOT OK
29+
users['unknown-admin-name'] = 'abcdefgh'; // NOT OK
30+
basicAuth({users: users});
3131
})();
3232

3333
(function() {
@@ -43,37 +43,37 @@
4343
var config = new AWS.Config();
4444
config.update({ accessKeyId: 'username', secretAccessKey: 'abcdefgh'}); // NOT OK
4545
var o = {};
46-
o.secretAccessKey = 'abcdefgh';
47-
config.update(o); // NOT OK
46+
o.secretAccessKey = 'abcdefgh'; // NOT OK
47+
config.update(o);
4848
})();
4949

5050
(function() {
5151
var request = require('request');
5252

5353
request.get(url).auth('username', 'abcdefgh'); // NOT OK
54-
request.get(url, { // NOT OK
54+
request.get(url, {
5555
'auth': {
56-
'user': 'username',
57-
'pass': 'abcdefgh'
56+
'user': 'username', // NOT OK
57+
'pass': 'abcdefgh' // NOT OK
5858
}
5959
});
6060

6161
request.get(url).auth(null, null, _, 'bearerToken'); // NOT OK
6262

63-
request.get(url, { // NOT OK
63+
request.get(url, {
6464
'auth': {
65-
'bearer': 'bearerToken'
65+
'bearer': 'bearerToken' // NOT OK
6666
}
6767
});
6868

6969
request.post(url).auth('username', 'abcdefgh'); // NOT OK
7070
request.head(url).auth('username', 'abcdefgh'); // NOT OK
7171

7272
request(url).auth('username', 'abcdefgh'); // NOT OK
73-
request(url, { // NOT OK
73+
request(url, {
7474
'auth': {
75-
'user': 'username',
76-
'pass': 'abcdefgh'
75+
'user': 'username', // NOT OK
76+
'pass': 'abcdefgh' // NOT OK
7777
}
7878
});
7979
})();
@@ -94,31 +94,31 @@
9494

9595
(function() {
9696
var pkgcloud = require('pkgcloud');
97-
pkgcloud.compute.createClient({ // NOT OK
98-
account: 'x1',
99-
keyId: 'x2',
100-
storageAccount: 'x3',
101-
username: 'x4',
102-
key: 'abcdefgh',
103-
apiKey: 'abcdefgh',
104-
storageAccessKey: 'abcdefgh',
105-
password: 'abcdefgh',
106-
token: 'abcdefgh'
97+
pkgcloud.compute.createClient({
98+
account: 'x1', // NOT OK
99+
keyId: 'x2',// NOT OK
100+
storageAccount: 'x3', // NOT OK
101+
username: 'x4', // NOT OK
102+
key: 'abcdefgh', // NOT OK
103+
apiKey: 'abcdefgh', // NOT OK
104+
storageAccessKey: 'abcdefgh', // NOT OK
105+
password: 'abcdefgh', // NOT OK
106+
token: 'abcdefgh' // NOT OK
107107
});
108108
pkgcloud.compute.createClient({ // OK
109109
INNOCENT_DATA: '42'
110110
});
111-
pkgcloud.providers.SOME_PROVIDER.compute.createClient({ // NOT OK
112-
username: 'x5',
113-
password: 'abcdefgh'
111+
pkgcloud.providers.SOME_PROVIDER.compute.createClient({
112+
username: 'x5', // NOT OK
113+
password: 'abcdefgh' // NOT OK
114114
});
115115
pkgcloud.UNKNOWN_SERVICE.createClient({ // OK
116116
username: 'x6',
117117
password: 'abcdefgh'
118118
});
119-
pkgcloud.providers.SOME_PROVIDER.UNKNOWN_SERVICE.createClient({ // OK
120-
username: 'x7',
121-
password: 'abcdefgh'
119+
pkgcloud.providers.SOME_PROVIDER.UNKNOWN_SERVICE.createClient({
120+
username: 'x7', // OK
121+
password: 'abcdefgh' // OK
122122
});
123123
pkgcloud.compute.createClient({ // OK
124124
username: process.env.USERNAME,

0 commit comments

Comments
 (0)