Skip to content

Enhance Javascript Open Redirect 2 community rule to use taint mode and add sanitizer patterns

Bhavya Kaushal requested to merge open-redirect-js-2 into main

What does this MR do?

This MR enhances the rule - https://gitlab.com/gitlab-org/security-products/sast-rules/-/blob/main/rules/lgpl/javascript/redirect/rule-express_open_redirect2.yml to do multiple things:

  1. Changes rule to use Taint mode
  2. Adds multiple Sanitizer Patterns
  3. Changes description to add remediation text with secure example

It also adds various test cases corresponding to rule patterns for thorough test coverage.

What are the relevant issue numbers?

Addresses issue : gitlab-org/gitlab#440623 (closed)

Does this MR meet the acceptance criteria?

Merge request reports

Loading