subham-deepsource / x-demo-go

Reflected cross-site scripting GO-S1006
Security
Major
2 years ago2 years old
Request parameter is incorporated without validation into the response: username
213		r.ParseForm()
214		username := r.Form.Get("username")
215		if !isValidUsername(username) {
216			fmt.Fprintf(w, "%q is an unknown user", username)217		}
218	})
219	http.ListenAndServe(":8080", nil)