CodeQL library for Java/Kotlin
codeql/java-all 0.9.2-dev (changelog, source)
Search

Module XssConfig

A taint-tracking configuration for cross site scripting vulnerabilities.

Import path

import semmle.code.java.security.XssQuery

Predicates

isAdditionalFlowStep

Holds if data may flow from node1 to node2 in addition to the normal data-flow steps.

isBarrier

Holds if data flow through node is prohibited. This completely removes node from the data flow graph.

isBarrierOut

Holds if data flow out of node is prohibited.

isSink

Holds if sink is a relevant data flow sink.

isSource

Holds if source is a relevant data flow source.