Esben Sparre Andreasen
|
5f1317fa2d
|
JS: model path.parse and its ponyfill package: "path-parse"
|
2020-01-30 21:26:18 +01:00 |
|
semmle-qlci
|
3158b8401a
|
Merge pull request #2705 from erik-krogh/CVE75
Approved by asgerf
|
2020-01-30 13:07:05 +00:00 |
|
semmle-qlci
|
120b50f497
|
Merge pull request #2708 from asger-semmle/js/react-flow-through-imports
Approved by esbena
|
2020-01-30 13:05:07 +00:00 |
|
Erik Krogh Kristensen
|
162c19c348
|
changes based on review
|
2020-01-30 14:04:04 +01:00 |
|
Erik Krogh Kristensen
|
7637ebcc03
|
Merge remote-tracking branch 'upstream/master' into exceptionFPs
|
2020-01-30 10:56:41 +01:00 |
|
Esben Sparre Andreasen
|
a6d3afd817
|
JS: support additional Koa request sources
|
2020-01-29 14:49:01 +01:00 |
|
Esben Sparre Andreasen
|
d4d910b681
|
JS: add koa test
|
2020-01-29 14:41:23 +01:00 |
|
Erik Krogh Kristensen
|
b8834ffcad
|
add support for private fields in classes
|
2020-01-29 13:10:45 +01:00 |
|
semmle-qlci
|
fb90c2ba52
|
Merge pull request #2681 from asger-semmle/csrf-only-session-cookie-access
Approved by erik-krogh, max-schaefer
|
2020-01-29 10:46:48 +00:00 |
|
Erik Krogh Kristensen
|
cb16116b4d
|
adjust type-tracking on custom EventEmitters
|
2020-01-28 14:00:26 +01:00 |
|
Asger Feldthaus
|
b306571d52
|
JS: Type-track react component factories
|
2020-01-28 10:22:04 +00:00 |
|
Asger Feldthaus
|
b98db62e82
|
JS: Recognize req.user a cookie access
|
2020-01-24 09:44:20 +00:00 |
|
Asger Feldthaus
|
a68bb9ffd1
|
JS: Ignore calls and csrf/captcha access
|
2020-01-23 15:32:05 +00:00 |
|
Asger Feldthaus
|
b1ec3e1bf2
|
JS: Add test and dont check predecessors
|
2020-01-23 14:59:03 +00:00 |
|
Erik Krogh Kristensen
|
b526a2ea0f
|
implement a model of WebSocket and ws based on the EventEmitter model
|
2020-01-22 14:46:53 +01:00 |
|
semmle-qlci
|
007b0795ec
|
Merge pull request #2636 from erik-krogh/NewSocketIO
Approved by esbena
|
2020-01-22 13:46:11 +00:00 |
|
Erik Krogh Kristensen
|
5063e3820d
|
update expected output
|
2020-01-22 11:18:47 +01:00 |
|
Erik Krogh Kristensen
|
8370699344
|
add support for creating a promise with another resolved promise, e.g: Promise.resolve(otherPromise)
|
2020-01-21 20:11:27 +01:00 |
|
Erik Krogh Kristensen
|
fe0b6a86d7
|
add data-flow steps for when Promise handlers return other promises
|
2020-01-21 16:15:18 +01:00 |
|
Erik Krogh Kristensen
|
d8b25ef5a2
|
add data-flow steps for resolved promises using pseudo-properties
|
2020-01-21 15:52:50 +01:00 |
|
Erik Krogh Kristensen
|
6648e2751f
|
remove use of .getAlocalSource() i custom load/store test
|
2020-01-21 15:49:42 +01:00 |
|
Erik Krogh Kristensen
|
569ee8fc8d
|
add support for subclasses of EventEmitter
|
2020-01-21 12:08:50 +01:00 |
|
Erik Krogh Kristensen
|
026092559c
|
changes based on review
|
2020-01-20 15:53:58 +01:00 |
|
Erik Krogh Kristensen
|
6494649125
|
fix a number of FPs in js/exception-xss
|
2020-01-20 15:11:57 +01:00 |
|
Erik Krogh Kristensen
|
ad813ef86c
|
add flowsTo to the use of isAdditionalLoadStep
|
2020-01-20 14:16:29 +01:00 |
|
Erik Krogh Kristensen
|
ffbd0f6632
|
update expected test output
|
2020-01-20 09:56:40 +01:00 |
|
Erik Krogh Kristensen
|
b3b132c66d
|
Merge remote-tracking branch 'upstream/master' into ExceptionalPromise
|
2020-01-20 09:20:09 +01:00 |
|
Erik Krogh Kristensen
|
6ad62e32e0
|
copyPropertyStep works interprocedurally
|
2020-01-17 12:24:29 +01:00 |
|
Erik Krogh Kristensen
|
06e898f53b
|
only use .getALocalSource in copyPropertyStep
|
2020-01-16 16:04:45 +01:00 |
|
semmle-qlci
|
4efc418e2c
|
Merge pull request #2617 from asger-semmle/prototype-pollution-utility
Approved by esbena, mchammer01
|
2020-01-16 13:02:07 +00:00 |
|
Erik Krogh Kristensen
|
4e880e2f96
|
implement SocketIO on top of the EventEmitter model
|
2020-01-16 11:02:36 +01:00 |
|
semmle-qlci
|
8128d23b6e
|
Merge pull request #2505 from erik-krogh/EventEmitter
Approved by esbena, max-schaefer
|
2020-01-16 08:47:38 +00:00 |
|
Erik Krogh Kristensen
|
a76ab39a39
|
no longer need for .getALocalSource() in custom load/store
|
2020-01-15 16:00:57 +01:00 |
|
Erik Krogh Kristensen
|
830100d2ed
|
support interprocedural flow with custom load/store steps
|
2020-01-15 14:23:17 +01:00 |
|
Asger Feldthaus
|
6d9306366c
|
JS: ignore useless-expr in first stmt in try block
|
2020-01-15 11:49:23 +00:00 |
|
Erik Krogh Kristensen
|
d09bce5cd7
|
custom load/store steps to implement promise flow
|
2020-01-14 21:37:55 +01:00 |
|
semmle-qlci
|
3c4749be88
|
Merge pull request #2624 from asger-semmle/js-duplicate-alert-strict-mode
Approved by max-schaefer
|
2020-01-14 11:59:45 +00:00 |
|
Asger F
|
2c05ee8ab8
|
JS: Add regression test
|
2020-01-14 10:53:00 +00:00 |
|
Asger F
|
9bd3c4a11c
|
JS: Add sanitizer for "in" exprs
|
2020-01-14 10:53:00 +00:00 |
|
Asger Feldthaus
|
7ac30e2289
|
JS: Add test for rephinement nodes
|
2020-01-14 10:53:00 +00:00 |
|
Asger F
|
a447645c10
|
JS: Add test with typeof on value
|
2020-01-14 10:52:59 +00:00 |
|
Asger F
|
bd9405ab84
|
JS: Guard against more FPs
|
2020-01-14 10:52:59 +00:00 |
|
Asger F
|
f7543aec95
|
JS: Support Reflect.ownKeys
|
2020-01-14 10:52:59 +00:00 |
|
Asger F
|
8af233307a
|
JS: Support enumeration through Object.entries
|
2020-01-14 10:52:59 +00:00 |
|
Asger F
|
96bf9db200
|
JS: Add another test and more barriers
|
2020-01-14 10:52:59 +00:00 |
|
Asger F
|
bc7871078a
|
JS: Fix FPs from Object.create(null)
|
2020-01-14 10:52:59 +00:00 |
|
Asger F
|
c889420dd3
|
JS: Add qhelp samples to test suite
|
2020-01-14 10:52:59 +00:00 |
|
Asger F
|
654f145772
|
JS: Add PrototypePollutionUtility query
|
2020-01-14 10:52:59 +00:00 |
|
Asger Feldthaus
|
73e60a7400
|
JS: Ignore strict-mode-call-stack-introspection for expr stmts
|
2020-01-13 16:03:03 +00:00 |
|
Erik Krogh Kristensen
|
c50de3a7e8
|
update expected output of tests
|
2020-01-10 17:49:24 +01:00 |
|