Skip to content

Commit a8afa05

Browse files
authored
Correct ReplaceAll params
ReplaceAll doesn't take a count argument
1 parent 11218f7 commit a8afa05

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

go/ql/src/Security/CWE-117/LogInjectionGood.go

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ import (
99
// GOOD: The user-provided value is escaped before being written to the log.
1010
func handlerGood(req *http.Request) {
1111
username := req.URL.Query()["username"][0]
12-
escapedUsername := strings.ReplaceAll(username, "\n", "", -1)
13-
escapedUsername = strings.ReplaceAll(escapedUsername, "\r", "", -1)
12+
escapedUsername := strings.ReplaceAll(username, "\n", "")
13+
escapedUsername = strings.ReplaceAll(escapedUsername, "\r", "")
1414
log.Printf("user %s logged in.\n", escapedUsername)
1515
}

0 commit comments

Comments
 (0)