semmle-qlci
|
9b3400337b
|
Merge pull request #3130 from erik-krogh/PreciseSteps
Approved by asgerf
|
2020-03-27 12:18:28 +00:00 |
|
semmle-qlci
|
1975a83cdd
|
Merge pull request #3116 from max-schaefer/js/postgres-type-tracking
Approved by asgerf
|
2020-03-27 09:23:52 +00:00 |
|
Erik Krogh Kristensen
|
58af63d8cc
|
add test case for XSS on url suffix
|
2020-03-27 10:02:24 +01:00 |
|
Erik Krogh Kristensen
|
d3e1a258fa
|
autoformat
|
2020-03-27 09:34:56 +01:00 |
|
Erik Krogh Kristensen
|
be11418c77
|
autoformat
|
2020-03-27 00:18:41 +01:00 |
|
Erik Krogh Kristensen
|
6b507c6933
|
add urlSuffix support to DomBasedXSS
|
2020-03-26 15:47:59 +01:00 |
|
Erik Krogh Kristensen
|
a850616927
|
delete Xss.actual
|
2020-03-26 15:40:37 +01:00 |
|
Erik Krogh Kristensen
|
e2d2c2341e
|
autoformat and update expected output
|
2020-03-26 15:38:00 +01:00 |
|
Erik Krogh Kristensen
|
baf50c832c
|
more precise charpreds in taint steps
|
2020-03-26 15:30:43 +01:00 |
|
Asger Feldthaus
|
816968d102
|
JS: Rename test files to avoid clash
|
2020-03-26 11:59:57 +00:00 |
|
Erik Krogh Kristensen
|
1cefa12315
|
update expected output
|
2020-03-25 23:54:57 +01:00 |
|
Erik Krogh Kristensen
|
8f45c8fe83
|
use LoadStoreStep for type-tracking promises
|
2020-03-25 23:54:57 +01:00 |
|
Erik Krogh Kristensen
|
1a2983fe39
|
support small steps for promise tracking
|
2020-03-25 23:54:57 +01:00 |
|
Erik Krogh Kristensen
|
00181e059b
|
add tests for type-tracking promises
|
2020-03-25 23:54:56 +01:00 |
|
Erik Krogh Kristensen
|
9a78d38df0
|
add a new LoadStoreStep as a StepSummary for TypeTracking
|
2020-03-25 23:54:56 +01:00 |
|
semmle-qlci
|
e7fd97e72b
|
Merge pull request #3119 from erik-krogh/SockJS
Approved by esbena
|
2020-03-25 21:36:29 +00:00 |
|
Erik Krogh Kristensen
|
4b0bc6b2b3
|
autoformat
|
2020-03-25 19:47:41 +01:00 |
|
Asger Feldthaus
|
ad1e0ec50b
|
JS: Inline variable again
|
2020-03-25 14:01:33 +00:00 |
|
Asger Feldthaus
|
54021a1c30
|
JS: Update old entry point and add a test
|
2020-03-25 13:24:18 +00:00 |
|
Asger Feldthaus
|
a78f1b864b
|
JS: Fix trailing whitespace
|
2020-03-25 12:45:48 +00:00 |
|
Asger Feldthaus
|
6c9e35c22e
|
JS: Skip .js files with a same-named .ts file next to it
|
2020-03-25 12:45:37 +00:00 |
|
semmle-qlci
|
cf5b1f0cd5
|
Merge pull request #3019 from erik-krogh/ArrayStep
Approved by asgerf
|
2020-03-25 12:08:44 +00:00 |
|
Erik Krogh Kristensen
|
abcdfe3c53
|
use LibraryName class for websocket library names
|
2020-03-25 13:06:21 +01:00 |
|
Erik Krogh Kristensen
|
f2b9e2019c
|
remove isRelevant from flowStep
|
2020-03-25 09:46:07 +01:00 |
|
Erik Krogh Kristensen
|
6f0e507242
|
outline predicate to fix join-ordering
|
2020-03-25 09:44:03 +01:00 |
|
Erik Krogh Kristensen
|
3000486b35
|
add more isRelevant calls
|
2020-03-25 09:42:24 +01:00 |
|
Erik Krogh Kristensen
|
1d8e103322
|
autoformat
|
2020-03-25 00:19:23 +01:00 |
|
Max Schaefer
|
efbcec09ef
|
JavaScript: Add type tracking to Postgres model.
|
2020-03-24 17:30:07 +00:00 |
|
Erik Krogh Kristensen
|
36981f385a
|
Merge branch 'master' of git.semmle.com:Semmle/ql into MorePathSinks
|
2020-03-24 11:20:33 +01:00 |
|
semmle-qlci
|
4c9a6b73ee
|
Merge pull request #3107 from erik-krogh/FArgs
Approved by esbena
|
2020-03-24 08:32:56 +00:00 |
|
Erik Krogh Kristensen
|
fa710c5864
|
Merge remote-tracking branch 'upstream/master' into UrlSearch
|
2020-03-24 00:23:15 +01:00 |
|
Erik Krogh Kristensen
|
5b4f091257
|
add test for remote flow sources in WebSockets
|
2020-03-23 23:58:20 +01:00 |
|
Erik Krogh Kristensen
|
6a1491d83d
|
add SockJS to the existing WebSocket model
|
2020-03-23 23:56:11 +01:00 |
|
Erik Krogh Kristensen
|
9a18dc32c1
|
autoformat WebSocket tests
|
2020-03-23 23:49:26 +01:00 |
|
Erik Krogh Kristensen
|
7b7eddff1e
|
remove previous SockJS implementation, and move example to WebSocket test
|
2020-03-23 23:45:05 +01:00 |
|
Asger F
|
a1e032bee6
|
Merge pull request #3098 from kyprizel/master
Experimental SockJS support
|
2020-03-23 22:39:10 +00:00 |
|
kyprizel
|
dec1b8b070
|
Update javascript/ql/src/experimental/SockJS/SockJS.qll
Fix comments
Co-Authored-By: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-03-23 22:59:48 +03:00 |
|
kyprizel
|
b90ff5e84d
|
Update javascript/ql/src/experimental/SockJS/SockJS.qll
do not import specific libs
Co-Authored-By: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-03-23 22:59:23 +03:00 |
|
semmle-qlci
|
e5590091a0
|
Merge pull request #3109 from max-schaefer/js/performance-fixes
Approved by asgerf
|
2020-03-23 16:08:07 +00:00 |
|
Max Schaefer
|
55e7b22cdf
|
JavaScript: Autoformat.
|
2020-03-23 14:37:04 +00:00 |
|
kyprizel
|
49e5a22cab
|
Fixed code style for SockJS
also fixed appCreation, thanks to Erik Krogh.
|
2020-03-23 17:16:17 +03:00 |
|
Erik Krogh Kristensen
|
7bc7ffffd6
|
autoformat
|
2020-03-23 14:10:07 +01:00 |
|
Erik Krogh Kristensen
|
f1e0d37273
|
Update javascript/ql/test/library-tests/frameworks/Concepts/file-access.js
Co-Authored-By: Asger F <asgerf@github.com>
|
2020-03-23 14:02:22 +01:00 |
|
Max Schaefer
|
b13e6141a2
|
JavaScript: Inline promiseStep/4.
|
2020-03-23 12:01:52 +00:00 |
|
Asger F
|
6c2842bd49
|
Merge pull request #2919 from asger-semmle/js/property-barriers
JS: Make sanitizers no longer block taint inside an object
|
2020-03-23 11:43:18 +00:00 |
|
Erik Krogh Kristensen
|
2c43d1d731
|
fix FP in superfluous-trailing-arguments related to Function.arguments
|
2020-03-23 10:40:35 +01:00 |
|
Eldar T. Zaitov
|
ee0b65ad39
|
Added experimental SockJS support
|
2020-03-20 21:24:16 +03:00 |
|
Erik Krogh Kristensen
|
f88cc2a977
|
inline promiseStep predicate
|
2020-03-20 09:07:52 +01:00 |
|
Erik Krogh Kristensen
|
90a324148d
|
add extra sinks to js/tainted-path
|
2020-03-20 09:07:39 +01:00 |
|
semmle-qlci
|
deb20fc37f
|
Merge pull request #3076 from esbena/js/even-more-mongoose-improvements
Approved by erik-krogh
|
2020-03-19 12:03:53 +00:00 |
|