Commit 459b9ff
Address CCR: don't claim guaranteed downstream encoding
Copilot Code Review correctly pointed out that bracketing between
BeginWriteTagHelperAttribute()/EndWriteTagHelperAttribute() only proves
the value is captured into a buffer rather than written directly to the
response; it does not, by itself, guarantee that every tag helper later
HTML-attribute-encodes that buffer. Reworded the doc comments and the
change note to justify the exclusion on "not a direct write to the
response" rather than on assumed downstream encoding.
No logic change; XSS.ql compiles and the CWE-079/XSS test still passes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>1 parent 6a272fb commit 459b9ff
2 files changed
Lines changed: 7 additions & 7 deletions
File tree
- csharp/ql/lib
- change-notes
- semmle/code/csharp/security/dataflow/flowsinks
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
Lines changed: 6 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
184 | 184 | | |
185 | 185 | | |
186 | 186 | | |
187 | | - | |
188 | | - | |
189 | | - | |
190 | | - | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
191 | 191 | | |
192 | 192 | | |
193 | 193 | | |
| |||
244 | 244 | | |
245 | 245 | | |
246 | 246 | | |
247 | | - | |
248 | | - | |
| 247 | + | |
| 248 | + | |
249 | 249 | | |
250 | 250 | | |
251 | 251 | | |
| |||
0 commit comments