Skip to content

Commit d8c4d6d

Browse files
committed
Rename cors-misconfiguration to cors-origin.
1 parent e6eacca commit d8c4d6d

File tree

4 files changed

+4
-4
lines changed

4 files changed

+4
-4
lines changed

javascript/ql/lib/ext/apollo-server.model.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ extensions:
1010
extensible: sinkModel
1111
data:
1212
- ["@apollo/server", "Member[gql].Argument[0]", "sql-injection"]
13-
- ["@apollo/server", "Member[ApolloServer,ApolloServerBase].Argument[0].Member[cors].Member[origin]", "cors-misconfiguration"]
13+
- ["@apollo/server", "Member[ApolloServer,ApolloServerBase].Argument[0].Member[cors].Member[origin]", "cors-origin"]
1414

1515
- addsTo:
1616
pack: codeql/javascript-all

javascript/ql/lib/ext/cors.model.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,4 +3,4 @@ extensions:
33
pack: codeql/javascript-all
44
extensible: sinkModel
55
data:
6-
- ["cors", "Argument[0].Member[origin]", "cors-misconfiguration"]
6+
- ["cors", "Argument[0].Member[origin]", "cors-origin"]

javascript/ql/lib/semmle/javascript/security/CorsPermissiveConfigurationCustomizations.qll

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,7 @@ module CorsPermissiveConfiguration {
6666
* The value of cors origin when initializing the application.
6767
*/
6868
class CorsOriginSink extends Sink, DataFlow::ValueNode {
69-
CorsOriginSink() { this = ModelOutput::getASinkNode("cors-misconfiguration").asSink() }
69+
CorsOriginSink() { this = ModelOutput::getASinkNode("cors-origin").asSink() }
7070
}
7171

7272
/**

shared/mad/codeql/mad/ModelValidation.qll

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ module KindValidation<KindValidationConfigSig Config> {
3939
"response-splitting", "trust-boundary-violation", "template-injection", "url-forward",
4040
"xslt-injection",
4141
// JavaScript-only currently, but may be shared in the future
42-
"cors-misconfiguration", "mongodb.sink",
42+
"cors-origin", "mongodb.sink",
4343
// Swift-only currently, but may be shared in the future
4444
"database-store", "format-string", "hash-iteration-count", "predicate-injection",
4545
"preferences-store", "tls-protocol-version", "transmission", "webview-fetch", "xxe",

0 commit comments

Comments
 (0)