new capacity bits (#67)

This commit is contained in:
Eli Peter 2026-05-07 01:29:31 -04:00 committed by GitHub
parent afaffc0df6
commit 7d0e7320e2
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
261 changed files with 10591 additions and 231 deletions

View file

@ -0,0 +1,15 @@
// Baseline: tainted body flows through a non-parser XML helper
// (StringBuilder concat). No XML parser entry point, no XXE label
// classification. Used to confirm taint-xxe doesn't fire on stray
// XML-adjacent string operations.
import javax.servlet.http.HttpServletRequest;
public class IrrelevantXmlCall {
public String handle(HttpServletRequest req) {
String body = req.getParameter("xml");
StringBuilder sb = new StringBuilder("<wrap>");
sb.append(body);
sb.append("</wrap>");
return sb.toString();
}
}