Skip to content

Commit 9193984

Browse files
committed
delete the experimental query library for cookie queries
1 parent 6858acc commit 9193984

File tree

3 files changed

+3
-56
lines changed

3 files changed

+3
-56
lines changed

javascript/ql/src/Security/CWE-1004/CookieWithoutHttpOnly.ql

Lines changed: 2 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -13,16 +13,11 @@
1313
*/
1414

1515
import javascript
16-
import experimental.semmle.javascript.security.InsecureCookie::Cookie as ExperimentalCookie // TODO: Remove.
1716

1817
from DataFlow::Node node
1918
where
20-
// TODO: Only for sensitive cookies? (e.g. auth cookies)
21-
// TODO: Give all descriptions, qlhelp, qldocs, an overhaul. Consider precisions, severity, cwes.
22-
exists(ExperimentalCookie::CookieWrite cookie | cookie = node |
23-
cookie.isSensitive() and not cookie.isHttpOnly()
24-
)
25-
or
19+
// TODO: Only for sensitive cookies? (e.g. auth cookies)
20+
// TODO: Give all descriptions, qlhelp, qldocs, an overhaul. Consider precisions, severity, cwes.
2621
exists(CookieWrites::CookieWrite cookie | cookie = node |
2722
cookie.isSensitive() and not cookie.isHttpOnly()
2823
)

javascript/ql/src/Security/CWE-614/InsecureCookie.ql

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -11,11 +11,7 @@
1111
*/
1212

1313
import javascript
14-
import experimental.semmle.javascript.security.InsecureCookie::Cookie as ExperimentalCookie // TODO: Remove
1514

1615
from DataFlow::Node node
17-
where
18-
exists(ExperimentalCookie::CookieWrite cookie | cookie = node | not cookie.isSecure())
19-
or
20-
exists(CookieWrites::CookieWrite cookie | cookie = node | not cookie.isSecure())
16+
where exists(CookieWrites::CookieWrite cookie | cookie = node | not cookie.isSecure())
2117
select node, "Cookie is added to response without the 'secure' flag being set to true"

javascript/ql/src/experimental/semmle/javascript/security/InsecureCookie.qll

Lines changed: 0 additions & 44 deletions
This file was deleted.

0 commit comments

Comments
 (0)