Skip to content

Commit a50c226

Browse files
Autoformat
1 parent 0fd684c commit a50c226

File tree

1 file changed

+10
-6
lines changed

1 file changed

+10
-6
lines changed

python/ql/src/experimental/semmle/python/security/TimingAttack.qll

Lines changed: 10 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -185,8 +185,8 @@ private string suspicious() {
185185
result =
186186
[
187187
"%password%", "%passwd%", "%pwd%", "%refresh%token%", "%secret%token", "%secret%key",
188-
"%passcode%", "%passphrase%", "%token%", "%secret%", "%credential%", "%userpass%",
189-
"%digest%", "%signature%", "%mac%"
188+
"%passcode%", "%passphrase%", "%token%", "%secret%", "%credential%", "%userpass%", "%digest%",
189+
"%signature%", "%mac%"
190190
]
191191
}
192192

@@ -208,7 +208,8 @@ abstract class ClientSuppliedSecret extends API::CallNode { }
208208
private class FlaskClientSuppliedSecret extends ClientSuppliedSecret {
209209
FlaskClientSuppliedSecret() {
210210
this = Flask::request().getMember("headers").getMember(["get", "get_all", "getlist"]).getACall() and
211-
this.getParameter(0, ["key", "name"]).asSink().asExpr().(StrConst).getText().toLowerCase() = sensitiveheaders()
211+
this.getParameter(0, ["key", "name"]).asSink().asExpr().(StrConst).getText().toLowerCase() =
212+
sensitiveheaders()
212213
}
213214
}
214215

@@ -219,7 +220,8 @@ private class DjangoClientSuppliedSecret extends ClientSuppliedSecret {
219220
.getMember(["headers", "META"])
220221
.getMember("get")
221222
.getACall() and
222-
this.getParameter(0, "key").asSink().asExpr().(StrConst).getText().toLowerCase() = sensitiveheaders()
223+
this.getParameter(0, "key").asSink().asExpr().(StrConst).getText().toLowerCase() =
224+
sensitiveheaders()
223225
}
224226
}
225227

@@ -231,7 +233,8 @@ API::Node requesthandler() {
231233
private class TornadoClientSuppliedSecret extends ClientSuppliedSecret {
232234
TornadoClientSuppliedSecret() {
233235
this = requesthandler().getMember(["headers", "META"]).getMember("get").getACall() and
234-
this.getParameter(0, "key").asSink().asExpr().(StrConst).getText().toLowerCase() = sensitiveheaders()
236+
this.getParameter(0, "key").asSink().asExpr().(StrConst).getText().toLowerCase() =
237+
sensitiveheaders()
235238
}
236239
}
237240

@@ -244,7 +247,8 @@ private class WerkzeugClientSuppliedSecret extends ClientSuppliedSecret {
244247
WerkzeugClientSuppliedSecret() {
245248
this =
246249
headers().getMember(["headers", "META"]).getMember(["get", "get_all", "getlist"]).getACall() and
247-
this.getParameter(0, ["key", "name"]).asSink().asExpr().(StrConst).getText().toLowerCase() = sensitiveheaders()
250+
this.getParameter(0, ["key", "name"]).asSink().asExpr().(StrConst).getText().toLowerCase() =
251+
sensitiveheaders()
248252
}
249253
}
250254

0 commit comments

Comments
 (0)