CodeQL library for JavaScript/TypeScript
codeql/javascript-all 2.6.3 (changelog, source)
Search

Module CorsMisconfigurationForCredentialsQuery

Provides a dataflow taint tracking configuration for reasoning about CORS misconfiguration for credentials transfer.

Note, for performance reasons: only import this file if CorsMisconfigurationForCredentials::Configuration is needed, otherwise CorsMisconfigurationForCredentialsCustomizations should be imported instead.

Import path

import semmle.javascript.security.dataflow.CorsMisconfigurationForCredentialsQuery

Imports

CorsMisconfigurationForCredentials
javascript

Provides classes for working with JavaScript programs, as well as JSON, YAML and HTML.

Classes

Configuration

DEPRECATED. Use the CorsMisconfigurationFlow module instead.

Modules

CorsMisconfigurationConfig

A data flow configuration for CORS misconfiguration for credentials transfer.

Aliases

CorsMisconfigurationFlow

Data flow for CORS misconfiguration for credentials transfer.