Commit 57cf5f1
authored
Fix compilation error and review issues in Java security queries
- Replace getAValue() with getValue() in InsecureDirectObjectReference.ql
to compile against codeql/java-all@7.1.3 (CI uses CLI 2.21.1)
- Fix getAStringArrayValue -> getAStringValue for PathVariable/RequestParam
annotations (value/name are single String attrs, not arrays)
- Remove setUrls from LdapUrlSink (takes String[], not a single constant)
- Remove LDAP URL literal from alert message to avoid exposing credentials
- Improve InsecureDirectObjectReference alert message clarity1 parent c5361b0 commit 57cf5f1
2 files changed
Lines changed: 5 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
35 | | - | |
| 35 | + | |
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
| |||
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
47 | | - | |
| 47 | + | |
Lines changed: 3 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
| 27 | + | |
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
| |||
64 | 64 | | |
65 | 65 | | |
66 | 66 | | |
67 | | - | |
| 67 | + | |
68 | 68 | | |
69 | 69 | | |
70 | 70 | | |
| |||
121 | 121 | | |
122 | 122 | | |
123 | 123 | | |
124 | | - | |
| 124 | + | |
0 commit comments