Skip to content

Commit 1208195

Browse files
Align alert messages across languages.
1 parent 2cffb21 commit 1208195

File tree

3 files changed

+5
-5
lines changed

3 files changed

+5
-5
lines changed

python/ql/src/Security/CWE-1004/NonHttpOnlyCookie.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/**
2-
* @name Cookie missing `HttpOnly` attribute.
2+
* @name Sensitive cookie missing `HttpOnly` attribute.
33
* @description Cookies without the `HttpOnly` attribute set can be accessed by JS scripts, making them more vulnerable to XSS attacks.
44
* @kind problem
55
* @problem.severity warning
@@ -18,4 +18,4 @@ from Http::Server::CookieWrite cookie
1818
where
1919
cookie.hasHttpOnlyFlag(false) and
2020
cookie.isSensitive()
21-
select cookie, "Cookie is added without the HttpOnly attribute properly set."
21+
select cookie, "Sensitive cookie is set without HttpOnly flag."

python/ql/src/Security/CWE-1275/SameSiteNoneCookie.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/**
2-
* @name Cookie with `SameSite` attribute set to `None`.
2+
* @name Sensitive cookie with `SameSite` attribute set to `None`.
33
* @description Cookies with `SameSite` set to `None` can allow for Cross-Site Request Forgery (CSRF) attacks.
44
* @kind problem
55
* @problem.severity warning
@@ -18,4 +18,4 @@ from Http::Server::CookieWrite cookie
1818
where
1919
cookie.hasSameSiteAttribute(any(Http::Server::CookieWrite::SameSiteNone v)) and
2020
cookie.isSensitive()
21-
select cookie, "Cookie is added with the SameSite attribute set to None."
21+
select cookie, "Sensitive cookie with SameSite set to 'None'."

python/ql/src/Security/CWE-614/InsecureCookie.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,4 +19,4 @@ from Http::Server::CookieWrite cookie
1919
where
2020
cookie.hasSecureFlag(false) and
2121
cookie.isSensitive()
22-
select cookie, "Cookie is added without the Secure attribute properly set."
22+
select cookie, "Cookie is added to response without the 'secure' flag being set."

0 commit comments

Comments
 (0)