Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit b20fd3c

Browse files
committed
JS: recognize res.sendfile as alias for res.sendFile in Express
1 parent a3562aa commit b20fd3c

1 file changed

Lines changed: 2 additions & 1 deletion

File tree

  • javascript/ql/src/semmle/javascript/frameworks

javascript/ql/src/semmle/javascript/frameworks/Express.qll

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -785,7 +785,8 @@ module Express {
785785
override MethodCallExpr astNode;
786786

787787
ResponseSendFileAsFileSystemAccess() {
788-
asExpr().(MethodCallExpr).calls(any(ResponseExpr res), "sendFile")
788+
exists (string name | name = "sendFile" or name = "sendfile" |
789+
asExpr().(MethodCallExpr).calls(any(ResponseExpr res), name))
789790
}
790791

791792
override DataFlow::Node getAPathArgument() {

0 commit comments

Comments
 (0)