forked from github/codeql
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathgraph-ql.js
More file actions
56 lines (51 loc) · 1.17 KB
/
graph-ql.js
File metadata and controls
56 lines (51 loc) · 1.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
const express = require('express');
const { graphql, buildSchema } = require('graphql');
const app = express();
app.use(express.json());
const schema = buildSchema(`
type Query {
greet(name: String!): String
calc(expr: String!): String
}
`);
const root = {
greet: ({ name }) => {
return `Hello, ${name}!`;
},
calc: ({ expr }) => {
try {
return eval(expr).toString(); // $ Alert[js/code-injection]
} catch (e) {
return `Error: ${e.message}`;
}
}
};
app.post('/graphql', async (req, res) => {
const { query, variables } = req.body; // $ Source[js/code-injection]
const result = await graphql({
schema,
source: query,
rootValue: root,
variableValues: variables
});
res.json(result);
const root1 = {
greet: ({ name, title }) => {
return eval(name + title).toString(); // $ Alert[js/code-injection]
}
};
graphql({
schema: buildSchema(`
type Query {
greet(name: String!, title: String): String
}
`),
source: `
query GreetUser($name: String!, $title: String) {
greet(name: $name, title: $title)
}
`,
rootValue: root1,
variableValues: variables
});
});