Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

LGTM.com - false positive (user-provided value) #2532

Open
SpraxDev opened this issue Dec 15, 2019 · 1 comment
Open

LGTM.com - false positive (user-provided value) #2532

SpraxDev opened this issue Dec 15, 2019 · 1 comment

Comments

@SpraxDev
Copy link

Description of the false positive
It is not detecting that I validate that 'user-provided value'. I make a request to my database and its result is stored into the app variable. That contains an array of allowed values and is checked in line 28. I use a function to check if it is inside that array (case insensitive).

URL to the alert on the project page on LGTM.com
https://lgtm.com/projects/g/Mc-Auth-com/Mc-Auth-Web/snapshot/41ec351596d9eaf086d8530beb383734cadebce9/files/routes/oAuth2.js?sort=name&dir=ASC&mode=heatmap#x2ee0a58e9646f1d3:1

@max-schaefer
Copy link
Contributor

Thank you for your report! We will look into improving our query to detect your validation logic.

@max-schaefer max-schaefer self-assigned this Jan 6, 2020
@max-schaefer max-schaefer assigned asgerf and unassigned max-schaefer Jan 23, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants