Skip to content

Commit 208487f

Browse files
committed
Added middleware test
1 parent 86b64af commit 208487f

File tree

1 file changed

+12
-0
lines changed
  • javascript/ql/test/query-tests/Security/CWE-918/Request

1 file changed

+12
-0
lines changed
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
import { NextRequest, NextResponse } from 'next/server';
2+
3+
export async function middleware(req: NextRequest) {
4+
const target = req.nextUrl // $ MISSING : Source[js/request-forgery]
5+
if (target) {
6+
const res = await fetch(target) // $ MISSING: Alert[js/request-forgery] Sink[js/request-forgery]
7+
const data = await res.text()
8+
return new NextResponse(data)
9+
}
10+
return NextResponse.next()
11+
}
12+

0 commit comments

Comments
 (0)