Skip to content

Commit 8effbff

Browse files
committed
Remove unused code and update qldoc
1 parent e33d786 commit 8effbff

File tree

2 files changed

+4
-10
lines changed

2 files changed

+4
-10
lines changed

java/ql/src/experimental/Security/CWE/CWE-552/UnsafeUrlForward.qll

Lines changed: 3 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,7 @@ private class GetResourceSink extends UnsafeUrlForwardSink {
102102
}
103103
}
104104

105-
/** Sink of Spring resource loading. */
105+
/** A sink for methods that load Spring resources. */
106106
private class SpringResourceSink extends UnsafeUrlForwardSink {
107107
SpringResourceSink() {
108108
exists(MethodAccess ma |
@@ -189,7 +189,7 @@ private class FilePathFlowStep extends SummaryModelCsv {
189189
}
190190
}
191191

192-
/** Taint model related to resource loading in Spring. */
192+
/** Taint models related to resource loading in Spring. */
193193
private class LoadSpringResourceFlowStep extends SummaryModelCsv {
194194
override predicate row(string row) {
195195
row =
@@ -201,20 +201,14 @@ private class LoadSpringResourceFlowStep extends SummaryModelCsv {
201201
}
202202
}
203203

204-
/** Sink related to spring resource. */
204+
/** Sink models for methods that load Spring resources. */
205205
private class SpringResourceCsvSink extends SinkModelCsv {
206206
override predicate row(string row) {
207207
row =
208208
[
209209
// Get spring resource
210210
"org.springframework.core.io;ClassPathResource;true;" +
211211
["getFilename", "getPath", "getURL", "resolveURL"] + ";;;Argument[-1];get-resource;manual",
212-
// "org.springframework.core.io;Resource;true;" +
213-
// ["getFile", "getFilename", "getURI", "getURL"] +
214-
// ";;;Argument[-1];get-resource;manual",
215-
// "org.springframework.core.io;InputStreamSource;true;" +
216-
// ["getInputStream"] +
217-
// ";;;Argument[-1];get-resource;manual"
218212
]
219213
}
220214
}

java/ql/src/experimental/semmle/code/java/frameworks/SpringResource.qll

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ class ResourceUtils extends Class {
1212
}
1313

1414
/**
15-
* Resource loading method declared in Spring `ResourceUtils`.
15+
* A method declared in `org.springframework.util.ResourceUtils` that loads Spring resources.
1616
*/
1717
class GetResourceUtilsMethod extends Method {
1818
GetResourceUtilsMethod() {

0 commit comments

Comments
 (0)