JS: Port Routing test

This commit is contained in:
Asger F
2023-10-06 10:41:29 +02:00
parent 2364bd84e0
commit 771519bbc5
2 changed files with 23 additions and 5 deletions

View File

@@ -0,0 +1,2 @@
legacyDataFlowDifference
consistencyIssue

View File

@@ -3,18 +3,34 @@ import testUtilities.ConsistencyChecking
API::Node testInstance() { result = API::moduleImport("@example/test").getInstance() }
class Taint extends TaintTracking::Configuration {
Taint() { this = "Taint" }
override predicate isSource(DataFlow::Node node) {
module TestConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node node) {
node.(DataFlow::CallNode).getCalleeName() = "source"
or
node = testInstance().getMember("getSource").getReturn().asSource()
}
override predicate isSink(DataFlow::Node node) {
predicate isSink(DataFlow::Node node) {
node = any(DataFlow::CallNode call | call.getCalleeName() = "sink").getAnArgument()
or
node = testInstance().getMember("getSink").getAParameter().asSink()
}
}
module TestFlow = TaintTracking::Global<TestConfig>;
class Consistency extends ConsistencyConfiguration {
Consistency() { this = "Consistency" }
override DataFlow::Node getAnAlert() { TestFlow::flowTo(result) }
}
class LegacyConfig extends TaintTracking::Configuration {
LegacyConfig() { this = "LegacyConfig" }
override predicate isSource(DataFlow::Node source) { TestConfig::isSource(source) }
override predicate isSink(DataFlow::Node sink) { TestConfig::isSink(sink) }
}
import testUtilities.LegacyDataFlowDiff::DataFlowDiff<TestFlow, LegacyConfig>