Thanks to visit codestin.com Credit goes to github.com
We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent d940085 commit b47939cCopy full SHA for b47939c
1 file changed
java/ql/test/query-tests/security/CWE-079/semmle/tests/SpringXSS.java
@@ -139,12 +139,12 @@ public String testDirectReturn(String userControlled) {
139
140
@GetMapping(value = "/xyz", produces = {"application/json"})
141
public ResponseEntity<String> overridesWithSafe(String userControlled) {
142
- return ResponseEntity.ok(userControlled); // $SPURIOUS: xss
+ return ResponseEntity.ok(userControlled);
143
}
144
145
@GetMapping(value = "/abc")
146
public ResponseEntity<String> overridesWithSafe2(String userControlled) {
147
- return ResponseEntity.ok().contentType(MediaType.APPLICATION_JSON).body(userControlled); // $SPURIOUS: xss
+ return ResponseEntity.ok().contentType(MediaType.APPLICATION_JSON).body(userControlled);
148
149
150
0 commit comments