nyx/tests/fixtures/xpath_injection/cpp/baseline_constant_xpath.cpp
2026-05-07 01:29:31 -04:00

7 lines
292 B
C++

// Baseline: expression is a compile-time constant. No taint reaches
// xmlXPathEvalExpression so no XPATH_INJECTION finding fires.
#include <libxml/xpath.h>
xmlXPathObjectPtr do_lookup(xmlXPathContextPtr ctx) {
return xmlXPathEvalExpression((xmlChar *)"//user[@role='admin']", ctx);
}