Skip to content

Commit 50cd200

Browse files
paldepindgeoffw0
andauthored
Apply suggestions from code review
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
1 parent 4f9d827 commit 50cd200

File tree

3 files changed

+1
-8
lines changed

3 files changed

+1
-8
lines changed

rust/ql/src/queries/security/CWE-918/RequestForgery.qhelp

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -46,9 +46,6 @@ known fixed string.
4646
<li>
4747
<a href="https://owasp.org/www-community/attacks/Server_Side_Request_Forgery">OWASP SSRF</a>
4848
</li>
49-
<li>
50-
<a href="https://cwe.mitre.org/data/definitions/918.html">CWE-918: Server-Side Request Forgery (SSRF)</a>
51-
</li>
5249
</references>
5350

5451
</qhelp>

rust/ql/src/queries/security/CWE-918/RequestForgery.ql

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,9 +13,6 @@
1313
private import rust
1414
private import codeql.rust.dataflow.TaintTracking
1515
private import codeql.rust.dataflow.DataFlow
16-
private import codeql.rust.dataflow.FlowSink
17-
private import codeql.rust.Concepts
18-
private import codeql.rust.security.CleartextTransmissionExtensions
1916
private import codeql.rust.security.RequestForgeryExtensions
2017

2118
/**
@@ -37,5 +34,5 @@ import RequestForgeryFlow::PathGraph
3734

3835
from RequestForgeryFlow::PathNode source, RequestForgeryFlow::PathNode sink
3936
where RequestForgeryFlow::flowPath(source, sink)
40-
select sink.getNode(), source, sink, "The $@ of this request depends on a $@.", sink, "URL",
37+
select sink.getNode(), source, sink, "The URL of this request depends on a $@.",
4138
source.getNode(), "user-provided value"

rust/ql/test/query-tests/security/CWE-918/options.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,4 +3,3 @@ qltest_dependencies:
33
- reqwest = { version = "0.12.23", features = ["blocking", "json"] }
44
- tokio = { version = "1.0", features = ["full"] }
55
- poem = { version = "3.1.12", features = ["server"] }
6-
- serde = { version = "1.0", features = ["derive"] }

0 commit comments

Comments
 (0)