Asger F
|
3f0d0e3a05
|
JS: Deprecate DataFlow::BarrierGuardNode
|
2024-12-03 14:30:50 +01:00 |
|
Asger F
|
62c17d3f4e
|
JS: Update SanitizerGuardNode use in BasicTaintTracking test
|
2024-12-03 14:30:34 +01:00 |
|
Asger F
|
2ef652da2c
|
JS: Add more deprecation annotations in tests
|
2024-12-03 14:30:31 +01:00 |
|
Asger F
|
08d25c122d
|
JS: Deprecate more uses of ConsistencyConfiguration
|
2024-12-03 14:30:27 +01:00 |
|
Asger F
|
0ce1fe767d
|
JS: Deprecate ConsistencyChecking to avoid deprecation warnings
|
2024-12-03 14:30:23 +01:00 |
|
Asger F
|
4d7401a074
|
JS: Deprecate tests for deprecated APIs
Mainly adds 'deprecated' in front of a bunch of tests for deprecated APIs.
|
2024-12-03 14:30:12 +01:00 |
|
Asger F
|
3548544970
|
JS: Avoid some uses of deprecated guard classes in tests
|
2024-12-03 14:30:11 +01:00 |
|
Asger F
|
a568d8c086
|
JS: Port threat-model test to ConfigSig
|
2024-12-03 14:30:10 +01:00 |
|
Asger F
|
054558d7b5
|
JS: Include content properties in type-tracker properties
Reminder: we have two PropertyName classes because the one in Contents.qll can't depend on DataFlow::Node.
|
2024-12-03 09:58:54 +01:00 |
|
Asger F
|
8bca66493f
|
JS: Add test showing lack of inclusion in PropertyName
|
2024-12-03 09:57:02 +01:00 |
|
Asger F
|
9c6b6981e2
|
JS: Add test to restrict dependencies
|
2024-11-29 14:23:56 +01:00 |
|
Asger F
|
2f0c80a98b
|
JS: Include summary steps in type tracking
|
2024-11-29 14:23:55 +01:00 |
|
Asger F
|
440cbb7f0a
|
JS: Add inline-expectation test for type tracking
|
2024-11-29 14:23:54 +01:00 |
|
Asger F
|
6349903110
|
JS: Move FlowSummary/Summaries.qll into testUtilities
|
2024-11-29 14:23:52 +01:00 |
|
Asger F
|
805fd0b46e
|
JS: Refine speculative step definition
|
2024-11-26 15:56:56 +01:00 |
|
Asger F
|
8818fcc207
|
JS: Benign test output changes
|
2024-11-26 15:47:13 +01:00 |
|
Asger F
|
82d61e4194
|
Merge branch 'js/shared-dataflow-branch' into js/shared-dataflow-merge-main
|
2024-11-26 15:36:16 +01:00 |
|
Napalys Klicius
|
e9dff4d68f
|
Merge pull request #17953 from Napalys/napalys/ts57
JS: upgrade TypeScript to 5.7
|
2024-11-25 14:16:40 +01:00 |
|
Napalys Klicius
|
61e00861e5
|
Merge pull request #18008 from Napalys/napalys/ES2024-group-functions
JS: Added support for [Object, Map].groupBy ES2024 feature
|
2024-11-21 19:03:57 +01:00 |
|
Napalys Klicius
|
edb9b47111
|
Merge pull request #18047 from Napalys/napalys/ES2023-string-protytpe-toWellFormed
JS: Added taint-step String.prototype.toWellFormed ES2023 feature
|
2024-11-21 14:01:21 +01:00 |
|
Asger F
|
1ac7591faf
|
JS: Update missed flow in capture-flow.js
We previously caught this flow because of a heuristic in capture flow. We'll have to fix it properly later.
|
2024-11-21 12:57:34 +01:00 |
|
Asger F
|
84820adf3c
|
Add test for exception flow out of finally()
|
2024-11-21 11:01:03 +01:00 |
|
Asger F
|
948d21ca07
|
JS: Propagate exceptions from summarized callables by default
|
2024-11-21 10:24:31 +01:00 |
|
Asger F
|
dcdb2e5133
|
JS: Fix callback check so it works without parameters
|
2024-11-21 10:24:29 +01:00 |
|
Asger F
|
b7dd455aff
|
JS: Add test case
|
2024-11-21 09:21:36 +01:00 |
|
Napalys
|
afc2d3e6d2
|
JS: Add: String.protytpe.toWellFormed to StringManipulationTaintStep
|
2024-11-20 17:42:25 +01:00 |
|
Napalys
|
09f73d8d6f
|
JS: Add: test cases for toWellFormed
|
2024-11-20 17:36:43 +01:00 |
|
Asger F
|
d52bc971b8
|
Merge branch 'main' into js/shared-dataflow-merge-main
|
2024-11-20 14:05:03 +01:00 |
|
Napalys Klicius
|
a957e00fe5
|
Merge branch 'main' into napalys/ES2024-group-functions
|
2024-11-20 14:03:31 +01:00 |
|
Napalys
|
58faa2d71e
|
JS: Add: dataflow step for static method of groupBy from Map.
|
2024-11-20 13:34:11 +01:00 |
|
Napalys
|
6344f83e4b
|
JS: Add: tests for taint tracking in groupBy functions
|
2024-11-20 13:22:53 +01:00 |
|
Napalys
|
28ead4011a
|
JS: Add: taint step to handle propagation of data flow from the array to callback
|
2024-11-19 14:15:15 +01:00 |
|
Napalys
|
f1e95a8a1d
|
JS: Add: taint step test cases for findLastIndex, findLast, find
|
2024-11-19 14:09:58 +01:00 |
|
Asger F
|
80a5a5909e
|
JS: Use getUnderlyingValue() a few places in VariableCapture
|
2024-11-19 13:23:29 +01:00 |
|
Asger F
|
d2daec4c66
|
JS: Add tests explaining why the IIFE in f2 didn't work
|
2024-11-19 13:23:24 +01:00 |
|
Napalys
|
c03d69af1e
|
JS: Add: dataflow step for find, findLast, findLastIndex callback functions
|
2024-11-19 09:42:11 +01:00 |
|
Napalys
|
b64b837db3
|
JS: Add: test cases for find, findLast, findLastIndex with callbacks
|
2024-11-19 09:35:43 +01:00 |
|
Asger F
|
37676f41aa
|
JS: Remove jump steps from IIFE steps
|
2024-11-18 13:38:34 +01:00 |
|
Asger F
|
7f2eae0966
|
JS: Add test case for false flow through IIFEs
We generate local flow steps into and out of IIFEs, but these come jump steps automatically, resulting in FPs.
|
2024-11-18 13:34:35 +01:00 |
|
Asger F
|
7acc5689cf
|
JS: Port exception steps to a universal summary
|
2024-11-18 13:27:58 +01:00 |
|
Asger F
|
5ed362f7d6
|
JS: Add exception test case
|
2024-11-18 13:23:09 +01:00 |
|
Napalys
|
213ce225e0
|
JS: Add: taint step for Object.groupBy function, fixed test cases from 8ae05d8be4
|
2024-11-18 12:58:07 +01:00 |
|
Napalys
|
8ae05d8be4
|
JS: Add: test case for Object.groupBy
|
2024-11-18 12:55:17 +01:00 |
|
Napalys
|
c02ad65fdc
|
JS: Add: taint step for Map.groupBy function
|
2024-11-18 12:50:06 +01:00 |
|
Napalys
|
3786ad4277
|
JS: Add: test case for Map.groupBy
|
2024-11-18 12:44:49 +01:00 |
|
Napalys
|
fcb65534a8
|
JS: Add: Array.protype.findLast as taint step
|
2024-11-15 14:10:01 +01:00 |
|
Napalys
|
ea90698fc1
|
JS: Add: Test case taint step for findLast
|
2024-11-15 13:35:28 +01:00 |
|
Napalys
|
bed1f25b3f
|
JS: Fix: Now Array.prototype.with is properly flagged as taint step
|
2024-11-15 10:35:34 +01:00 |
|
Napalys
|
f04fd5cdcc
|
JS: Add: Test case for Array.protype.with taint step
|
2024-11-15 10:27:44 +01:00 |
|
Napalys Klicius
|
6fa3ff39a0
|
Merge branch 'main' into napalys/toSpliced-support
|
2024-11-14 16:56:32 +01:00 |
|