Skip to content

Commit 83937b9

Browse files
committed
StackTraceExposureQuery documentation
1 parent 546a39f commit 83937b9

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

java/ql/lib/semmle/code/java/security/StackTraceExposureQuery.qll

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,7 @@ private module StackTraceStringToHttpResponseSinkFlow =
7575
TaintTracking::Global<StackTraceStringToHttpResponseSinkFlowConfig>;
7676

7777
/**
78-
* A write of stack trace data to an external stream.
78+
* Holds if `call` writes the data of `stackTrace` to an external stream.
7979
*/
8080
predicate printsStackExternally(MethodAccess call, Expr stackTrace) {
8181
printsStackToWriter(call) and
@@ -84,7 +84,7 @@ predicate printsStackExternally(MethodAccess call, Expr stackTrace) {
8484
}
8585

8686
/**
87-
* A stringified stack trace flows to an external sink.
87+
* Holds if `stackTrace` is a stringified stack trace which flows to an external sink.
8888
*/
8989
predicate stringifiedStackFlowsExternally(DataFlow::Node externalExpr, Expr stackTrace) {
9090
exists(MethodAccess stackTraceString |
@@ -113,7 +113,7 @@ private module GetMessageFlowSourceToHttpResponseSinkFlow =
113113
TaintTracking::Global<GetMessageFlowSourceToHttpResponseSinkFlowConfig>;
114114

115115
/**
116-
* A call to `getMessage()` that then flows to a servlet response.
116+
* Holds if there is a call to `getMessage()` that then flows to a servlet response.
117117
*/
118118
predicate getMessageFlowsExternally(DataFlow::Node externalExpr, GetMessageFlowSource getMessage) {
119119
GetMessageFlowSourceToHttpResponseSinkFlow::flow(getMessage, externalExpr)

0 commit comments

Comments
 (0)