Skip to content
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Fix encryption sanitizer
It now discards sensitive exprs (sources) instead of sinks for better precision
  • Loading branch information
atorralba committed Sep 23, 2021
commit d0b9920cac5c762358cda00ba57c24e6c9cf2eb4
Original file line number Diff line number Diff line change
Expand Up @@ -88,7 +88,7 @@ private class EncryptedValueFlowConfig extends DataFlow4::Configuration {
src.asExpr() instanceof EncryptedSensitiveMethodAccess
}

override predicate isSink(DataFlow::Node sink) { sink instanceof CleartextStorageSink }
override predicate isSink(DataFlow::Node sink) { sink.asExpr() instanceof SensitiveExpr }
}

/** A taint step for `EditText.toString` in Android. */
Expand Down