Skip to content

String.tainted() overrides prior taint values #257

@leeN

Description

@leeN

If we manually mark a String as tainted, e.g., by calling String.tainted(location.href, "manual"); it overrides the existing taint.

However, in some cases, it would be desirable to add an additional source operation to the taint flow instead of throwing the taint away.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions