Skip to content

Commit ca8ac0c

Browse files
Jami CogswellJami Cogswell
authored andcommitted
Java: add comment about request-forgery sinks
1 parent 9853a66 commit ca8ac0c

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

java/ql/lib/semmle/code/java/security/HttpsUrls.qll

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,7 @@ class HttpStringLiteral extends StringLiteral {
3030
abstract class UrlOpenSink extends DataFlow::Node { }
3131

3232
private class DefaultUrlOpenSink extends UrlOpenSink {
33+
// request-forgery sinks control the URL of a request
3334
DefaultUrlOpenSink() { sinkNode(this, "request-forgery") }
3435
}
3536

0 commit comments

Comments
 (0)