We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent e290802 commit d4b231bCopy full SHA for d4b231b
javascript/ql/src/experimental/Security/CWE-614/InsecureCookie.qll
@@ -112,7 +112,7 @@ module InsecureCookie {
112
// A cookie is insecure if the 'secure' flag is not specified in the cookie definition.
113
not exists(string s |
114
getCookieOptionsArgument().mayHaveStringValue(s) and
115
- s.matches("%; secure%")
+ s.regexpMatch("(.*;)?\\s*secure.*")
116
)
117
}
118
0 commit comments