Skip to content

Commit 6282c34

Browse files
Update formatting
1 parent a25861d commit 6282c34

File tree

4 files changed

+20
-20
lines changed

4 files changed

+20
-20
lines changed

go/ql/src/Security/CWE-1004/examples/CookieWithoutHttpOnly.go

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,8 @@ import (
66

77
func handlerBad(w http.ResponseWriter, r *http.Request) {
88
c := http.Cookie{
9-
Name: "session",
10-
Value: "secret",
9+
Name: "session",
10+
Value: "secret",
1111
}
1212
http.SetCookie(w, &c) // BAD: The HttpOnly flag is set to false by default.
1313
}
@@ -19,4 +19,4 @@ func handlerGood(w http.ResponseWriter, r *http.Request) {
1919
HttpOnly: true,
2020
}
2121
http.SetCookie(w, &c) // GOOD: The HttpOnly flag is set to true.
22-
}
22+
}

go/ql/src/Security/CWE-614/examples/CookieWithoutSecure.go

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,17 +6,17 @@ import (
66

77
func handlerBad(w http.ResponseWriter, r *http.Request) {
88
c := http.Cookie{
9-
Name: "session",
10-
Value: "secret",
9+
Name: "session",
10+
Value: "secret",
1111
}
1212
http.SetCookie(w, &c) // BAD: The Secure flag is set to false by default.
1313
}
1414

1515
func handlerGood(w http.ResponseWriter, r *http.Request) {
1616
c := http.Cookie{
17-
Name: "session",
18-
Value: "secret",
17+
Name: "session",
18+
Value: "secret",
1919
Secure: true,
2020
}
2121
http.SetCookie(w, &c) // GOOD: The Secure flag is set to true.
22-
}
22+
}

go/ql/test/query-tests/Security/CWE-1004/CookieWithoutHttpOnly.go

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ func handler2(w http.ResponseWriter, r *http.Request) {
2525

2626
func handler3(w http.ResponseWriter, r *http.Request) {
2727
c := http.Cookie{
28-
Name: "session",
28+
Name: "session",
2929
Value: "secret",
3030
HttpOnly: true,
3131
}
@@ -63,7 +63,7 @@ func handler6(w http.ResponseWriter, r *http.Request) {
6363
func handler7(w http.ResponseWriter, r *http.Request) {
6464
val := true
6565
c := http.Cookie{
66-
Name: "session",
66+
Name: "session",
6767
Value: "secret",
6868
HttpOnly: val,
6969
}
@@ -125,7 +125,7 @@ func main() {
125125

126126
router.GET("/cookie", func(c *gin.Context) {
127127

128-
_, err := c.Cookie("session")
128+
_, err := c.Cookie("session")
129129

130130
if err != nil {
131131
c.SetCookie("session", "test", 3600, "/", "localhost", false, false) // $ Alert // BAD: httpOnly set to false

go/ql/test/query-tests/Security/CWE-614/CookieWithoutSecure.go

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -16,17 +16,17 @@ func handler1(w http.ResponseWriter, r *http.Request) {
1616

1717
func handler2(w http.ResponseWriter, r *http.Request) {
1818
c := http.Cookie{
19-
Name: "session", // $ Source
20-
Value: "secret",
19+
Name: "session", // $ Source
20+
Value: "secret",
2121
Secure: false,
2222
}
2323
http.SetCookie(w, &c) // $ Alert // BAD: Secure explicitly set to false
2424
}
2525

2626
func handler3(w http.ResponseWriter, r *http.Request) {
2727
c := http.Cookie{
28-
Name: "session",
29-
Value: "secret",
28+
Name: "session",
29+
Value: "secret",
3030
Secure: true,
3131
}
3232
http.SetCookie(w, &c) // GOOD: Secure explicitly set to true
@@ -53,8 +53,8 @@ func handler5(w http.ResponseWriter, r *http.Request) {
5353
func handler6(w http.ResponseWriter, r *http.Request) {
5454
val := false
5555
c := http.Cookie{
56-
Name: "session", // $ Source
57-
Value: "secret",
56+
Name: "session", // $ Source
57+
Value: "secret",
5858
Secure: val,
5959
}
6060
http.SetCookie(w, &c) // $ Alert // BAD: Secure explicitly set to false
@@ -63,8 +63,8 @@ func handler6(w http.ResponseWriter, r *http.Request) {
6363
func handler7(w http.ResponseWriter, r *http.Request) {
6464
val := true
6565
c := http.Cookie{
66-
Name: "session",
67-
Value: "secret",
66+
Name: "session",
67+
Value: "secret",
6868
Secure: val,
6969
}
7070
http.SetCookie(w, &c) // GOOD: Secure explicitly set to true
@@ -96,7 +96,7 @@ func main() {
9696

9797
router.GET("/cookie", func(c *gin.Context) {
9898

99-
_, err := c.Cookie("session")
99+
_, err := c.Cookie("session")
100100

101101
if err != nil {
102102
c.SetCookie("session", "test", 3600, "/", "localhost", false, false) // $ Alert // BAD: Secure set to false

0 commit comments

Comments
 (0)