Skip to content

Commit e13c779

Browse files
Add additional unit tests
1 parent ee651da commit e13c779

File tree

2 files changed

+55
-1
lines changed

2 files changed

+55
-1
lines changed

java/ql/test/library-tests/frameworks/apache-http/B.java

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
import org.apache.hc.core5.http.*;
22
import org.apache.hc.core5.http.protocol.HttpContext;
33
import org.apache.hc.core5.http.io.HttpRequestHandler;
4+
import org.apache.hc.core5.http.io.HttpServerRequestHandler;
45
import org.apache.hc.core5.http.message.*;
56
import org.apache.hc.core5.http.io.entity.*;
67
import org.apache.hc.core5.util.*;
@@ -51,6 +52,7 @@ void test2() {
5152
bbuf.append((byte[]) taint(), 0, 3);
5253
sink(bbuf.array()); //$hasTaintFlow=y
5354
sink(bbuf.toByteArray()); //$hasTaintFlow=y
55+
sink(bbuf.toString()); //SPURIOUS: $hasTaintFlow=y
5456

5557
CharArrayBuffer cbuf = new CharArrayBuffer(42);
5658
cbuf.append(bbuf.toByteArray(), 0, 3);
@@ -63,6 +65,12 @@ void test2() {
6365
sink(Args.notNull(taint(), "x")); //$hasTaintFlow=y
6466
sink(Args.notEmpty((String) taint(), "x")); //$hasTaintFlow=y
6567
sink(Args.notBlank((String) taint(), "x")); //$hasTaintFlow=y
66-
sink(Args.notNull("x", (String) taint())); // Good
68+
sink(Args.notNull("x", (String) taint()));
69+
}
70+
71+
class Test3 implements HttpServerRequestHandler {
72+
public void handle(ClassicHttpRequest req, HttpServerRequestHandler.ResponseTrigger restr, HttpContext ctx) throws HttpException, IOException {
73+
B.sink(req.getEntity()); //$hasTaintFlow=y
74+
}
6775
}
6876
}
Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
/*
2+
* ====================================================================
3+
* Licensed to the Apache Software Foundation (ASF) under one
4+
* or more contributor license agreements. See the NOTICE file
5+
* distributed with this work for additional information
6+
* regarding copyright ownership. The ASF licenses this file
7+
* to you under the Apache License, Version 2.0 (the
8+
* "License"); you may not use this file except in compliance
9+
* with the License. You may obtain a copy of the License at
10+
*
11+
* http://www.apache.org/licenses/LICENSE-2.0
12+
*
13+
* Unless required by applicable law or agreed to in writing,
14+
* software distributed under the License is distributed on an
15+
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
16+
* KIND, either express or implied. See the License for the
17+
* specific language governing permissions and limitations
18+
* under the License.
19+
* ====================================================================
20+
*
21+
* This software consists of voluntary contributions made by many
22+
* individuals on behalf of the Apache Software Foundation. For more
23+
* information on the Apache Software Foundation, please see
24+
* <http://www.apache.org/>.
25+
*
26+
*/
27+
package org.apache.hc.core5.http.io;
28+
import java.io.IOException;
29+
import org.apache.hc.core5.http.ClassicHttpRequest;
30+
import org.apache.hc.core5.http.ClassicHttpResponse;
31+
import org.apache.hc.core5.http.HttpException;
32+
import org.apache.hc.core5.http.protocol.HttpContext;
33+
34+
public interface HttpServerRequestHandler {
35+
interface ResponseTrigger {
36+
void sendInformation(ClassicHttpResponse response) throws HttpException, IOException;
37+
38+
void submitResponse(ClassicHttpResponse response) throws HttpException, IOException;
39+
40+
}
41+
void handle(
42+
ClassicHttpRequest request,
43+
ResponseTrigger responseTrigger,
44+
HttpContext context) throws HttpException, IOException;
45+
46+
}

0 commit comments

Comments
 (0)