Skip to content

Commit 6647e5f

Browse files
authored
Merge pull request #22748 from mbaluda/mbaluda/useofhttp-perf
Refactor `CWE-319/UseOfHttp.ql` for performance
2 parents 6013895 + 1c10fca commit 6647e5f

1 file changed

Lines changed: 10 additions & 7 deletions

File tree

‎cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql‎

Lines changed: 10 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -35,22 +35,25 @@ predicate privateHostNameFlowsToExpr(Expr e) {
3535
TaintTracking::localExprTaint(any(StringLiteral p | p.getValue() instanceof PrivateHostName), e)
3636
}
3737

38-
/**
39-
* A string containing an HTTP URL not in a private domain.
40-
*/
41-
class HttpStringLiteral extends StringLiteral {
42-
HttpStringLiteral() {
38+
private class HttpStringLiteralCandidate extends StringLiteral {
39+
HttpStringLiteralCandidate() {
4340
exists(string s | this.getValue() = s |
4441
s = "http"
4542
or
4643
exists(string tail |
4744
tail = s.regexpCapture("http://(.*)", 1) and not tail instanceof PrivateHostName
4845
)
49-
) and
50-
not privateHostNameFlowsToExpr(this.getParent*())
46+
)
5147
}
5248
}
5349

50+
/**
51+
* A string containing an HTTP URL not in a private domain.
52+
*/
53+
class HttpStringLiteral extends HttpStringLiteralCandidate {
54+
HttpStringLiteral() { not privateHostNameFlowsToExpr(this.getParent*()) }
55+
}
56+
5457
/**
5558
* Taint tracking configuration for HTTP connections.
5659
*/

0 commit comments

Comments
 (0)