QL code and tests for C#/C++/JavaScript.

This commit is contained in:
Pavel Avgustinov
2018-08-02 17:53:23 +01:00
commit b55526aa58
10684 changed files with 581163 additions and 0 deletions

View File

@@ -0,0 +1,19 @@
/**
* @name Direct state mutation
* @description Mutating the state of a React component directly may lead to
* lost updates.
* @kind problem
* @problem.severity warning
* @id js/react/direct-state-mutation
* @tags reliability
* frameworks/react
* @precision very-high
*/
import semmle.javascript.frameworks.React
from DataFlow::PropWrite pwn, ReactComponent c
where pwn.getBase() = c.getAStateAccess() and
// writes in constructors are ok
not pwn.getContainer() instanceof Constructor
select pwn, "Use `setState` instead of directly modifying component state."