Erik Krogh Kristensen
|
d7b69fcfea
|
autoformat
|
2020-03-17 09:52:08 +01:00 |
|
Esben Sparre Andreasen
|
7dc80664e6
|
Merge pull request #3045 from Semmle/esbena-patch-2
JS: loosen qldoc for `barrierGuardIsRelevant`
|
2020-03-16 22:28:22 +01:00 |
|
Esben Sparre Andreasen
|
b75486bb58
|
JS: refactor NoSQL::Mongoose. Introduce Mongoose::CommonInterface
|
2020-03-16 22:12:30 +01:00 |
|
Esben Sparre Andreasen
|
9d9926fdbf
|
JS: model Mongoose Document for additional js/nosql-injection sinks
|
2020-03-16 22:11:22 +01:00 |
|
Esben Sparre Andreasen
|
dc27a8f52c
|
JS: model mongoose Model on createConnection.<model/models>
|
2020-03-16 22:11:22 +01:00 |
|
Erik Krogh Kristensen
|
7145a57db3
|
refactor StepSummary into an internal .qll
|
2020-03-16 17:52:04 +01:00 |
|
Erik Krogh Kristensen
|
cd6fe8115d
|
Update javascript/ql/src/semmle/javascript/Promises.qll
Co-Authored-By: Asger F <asgerf@github.com>
|
2020-03-16 16:27:50 +01:00 |
|
Erik Krogh Kristensen
|
f2548aa3b1
|
add more models for file related sinks and sources
|
2020-03-16 11:07:23 +01:00 |
|
Erik Krogh Kristensen
|
557b642a8e
|
add isRelevant check on flowStep predicate
|
2020-03-16 11:01:20 +01:00 |
|
semmle-qlci
|
1d4dd2b2f7
|
Merge pull request #3057 from esbena/js/infer-this-as-exports
Approved by asgerf
|
2020-03-15 12:55:12 +00:00 |
|
semmle-qlci
|
7e093a8e5c
|
Merge pull request #3041 from erik-krogh/JQueryAjax
Approved by esbena
|
2020-03-14 22:31:59 +00:00 |
|
Erik Krogh Kristensen
|
486efbab77
|
refactor based on review
|
2020-03-14 14:53:38 +01:00 |
|
Erik Krogh Kristensen
|
4f39c28741
|
Merge branch 'master' of git.semmle.com:Semmle/ql into CustomTrack
|
2020-03-14 14:37:52 +01:00 |
|
semmle-qlci
|
20cae302fd
|
Merge pull request #3054 from erik-krogh/NoDeferred
Approved by asgerf
|
2020-03-14 13:36:16 +00:00 |
|
Esben Sparre Andreasen
|
4d6aa20990
|
Merge pull request #3004 from esbena/js/additional-mongodb-and-mongoose-injection-sinks
JS: Mongoose and MongoDB improvements
|
2020-03-14 12:31:43 +01:00 |
|
Esben Sparre Andreasen
|
2fac7434df
|
JS: infer this to be module.exports in node modules
|
2020-03-13 14:10:35 +01:00 |
|
semmle-qlci
|
25b9fcfafd
|
Merge pull request #3058 from asger-semmle/js/may-receive-argument-fix
Approved by max-schaefer
|
2020-03-13 11:49:49 +00:00 |
|
Erik Krogh Kristensen
|
799c3eb06c
|
remove model of Deferred
|
2020-03-12 16:38:20 +01:00 |
|
Erik Krogh Kristensen
|
59d2d6d4fd
|
autoformat
|
2020-03-12 14:48:16 +01:00 |
|
Asger Feldthaus
|
4391b70b5f
|
JS: Fix perf issue in mayReceiveArgument
|
2020-03-12 13:45:34 +00:00 |
|
Erik Krogh Kristensen
|
172c5ccaca
|
changes based on review
|
2020-03-12 11:04:33 +01:00 |
|
Erik Krogh Kristensen
|
91bc124f78
|
autoformat
|
2020-03-12 10:45:25 +01:00 |
|
Erik Krogh Kristensen
|
d32d14f572
|
model responseText and responseXml on jqXHR objects
|
2020-03-11 17:00:44 +01:00 |
|
Erik Krogh Kristensen
|
26d8e33434
|
Autoformat
|
2020-03-11 16:42:48 +01:00 |
|
Erik Krogh Kristensen
|
e88dac3dea
|
remove FP for js/redundant-operation
|
2020-03-11 14:42:32 +01:00 |
|
semmle-qlci
|
1d5fba85f9
|
Merge pull request #3034 from esbena/js/sharpen-useless-regexp-character-escape
Approved by asgerf
|
2020-03-11 12:29:45 +00:00 |
|
Erik Krogh Kristensen
|
cb5ef7dbed
|
add basic support for jqXHR with ajax calls
|
2020-03-11 13:05:41 +01:00 |
|
Erik Krogh Kristensen
|
b987f2cf29
|
autoformat
|
2020-03-11 10:54:20 +01:00 |
|
Erik Krogh Kristensen
|
7f147221f5
|
refactor to include promise tracking as a core part of type tracking
|
2020-03-11 10:44:11 +01:00 |
|
Esben Sparre Andreasen
|
4dac835bb0
|
JS: loosen qldoc for barrierGuardIsRelevant
|
2020-03-11 07:54:38 +01:00 |
|
Erik Krogh Kristensen
|
13e855910e
|
add more ClientRequest models for JQuery
|
2020-03-10 17:21:22 +01:00 |
|
semmle-qlci
|
e3fed39f88
|
Merge pull request #3000 from asger-semmle/js/late-barrier-guards
Approved by erik-krogh
|
2020-03-10 15:38:35 +00:00 |
|
Erik Krogh Kristensen
|
62ae484545
|
autoformat and update expected output
|
2020-03-10 14:01:40 +01:00 |
|
Erik Krogh Kristensen
|
066568ea60
|
add promise tracking to Files.qll
|
2020-03-10 12:36:42 +01:00 |
|
Erik Krogh Kristensen
|
97f2760583
|
refactor Files.qll to use type-tracking (without tracking anything)
|
2020-03-10 12:34:20 +01:00 |
|
Erik Krogh Kristensen
|
6110f85748
|
refactor chrome-remote-interface to use type-tracking promise steps
|
2020-03-10 12:27:21 +01:00 |
|
Esben Sparre Andreasen
|
5b1b945c35
|
JS: distinguishes escapes in strings and regular expression literals
|
2020-03-10 12:26:20 +01:00 |
|
Erik Krogh Kristensen
|
69d8cf643d
|
add type tracking predicates for promises
|
2020-03-10 12:23:23 +01:00 |
|
Esben Sparre Andreasen
|
3bfda6cd38
|
JS: refactoring: make separate modules for mongoose Model and Query
|
2020-03-10 09:57:45 +01:00 |
|
Esben Sparre Andreasen
|
480be06d86
|
JS: replace Model class with opaque type tracking predicate
|
2020-03-10 09:57:45 +01:00 |
|
Esben Sparre Andreasen
|
dbeb216af0
|
JS: make use of TypeScript types for mongoose Model and Query
|
2020-03-10 09:57:45 +01:00 |
|
Esben Sparre Andreasen
|
0c46e4d1af
|
JS: fixup typetracking usage: t2 -> t2.continue()
|
2020-03-10 09:57:45 +01:00 |
|
Esben Sparre Andreasen
|
aae92ad795
|
JS: add test for DatabaseAccess
|
2020-03-10 09:57:45 +01:00 |
|
Esben Sparre Andreasen
|
7a2faa0b6b
|
JS: add additional mongoose and mongodb js/nosql-injection sinks
|
2020-03-10 09:57:45 +01:00 |
|
Esben Sparre Andreasen
|
b6c616efd3
|
JS: support optional options argument to MongoClient.connect
|
2020-03-10 09:57:45 +01:00 |
|
Esben Sparre Andreasen
|
21e6e69f22
|
JS: support mongodb v3 (minimally)
https://github.com/github/codeql-javascript-team/issues/79
|
2020-03-10 09:57:45 +01:00 |
|
Erik Krogh Kristensen
|
981eef2587
|
expose arrayFunctionTaintStep in TaintTracking.qll
|
2020-03-09 17:22:29 +01:00 |
|
Erik Krogh Kristensen
|
509941649c
|
remove redundant qldoc, and change parameter names to better reflect behavior
|
2020-03-09 17:20:12 +01:00 |
|
Erik Krogh Kristensen
|
a476fc5c3b
|
revert Array.from change
|
2020-03-09 17:09:31 +01:00 |
|
Erik Krogh Kristensen
|
b4b05696e1
|
two bugfixes
|
2020-03-09 16:45:03 +01:00 |
|