Skip to content

Do not detect HttpDelete or HttpPut

Tomo Masakura requested to merge masakura/semgrep:csharp-csrf-http-methods into main

What does this MR do?

This code is detected as vulnerable by Semgrep C# analyzer.

[HttpPost]
public void Post() {}

However, this code is not detected.

[HttpDelete]
public void Delete() {}

A list of HTTP methods to be detected.

  • HttpPost
  • HttpDelete
  • HttpPatch
  • HttpPut

resources.

What are the relevant issue numbers?

Does this MR meet the acceptance criteria?

Merge request reports