Skip to content

Commit 7536c49

Browse files
committed
JS: Use getAParameter and not getReceiver instead of getASuccessor
1 parent 405f077 commit 7536c49

File tree

1 file changed

+3
-4
lines changed

1 file changed

+3
-4
lines changed

javascript/ql/src/semmle/javascript/security/dataflow/ExternalAPIUsedWithUntrustedDataCustomizations.qll

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -162,10 +162,9 @@ module ExternalAPIUsedWithUntrustedData {
162162
* Gets a parameter of `base` with name `name`, or a property named `name` of a destructuring parameter.
163163
*/
164164
private API::Node getNamedParameter(API::Node base, string name) {
165-
exists(API::Node param, string lbl |
166-
// getParameter(i) requires a bindingset for i, so use the raw label
167-
param = base.getASuccessor("parameter " + lbl) and
168-
lbl != "-1" // ignore receiver
165+
exists(API::Node param |
166+
param = base.getAParameter() and
167+
not param = base.getReceiver()
169168
|
170169
result = param and
171170
name = param.getAnImmediateUse().asExpr().(Parameter).getName()

0 commit comments

Comments
 (0)