Max Schaefer
|
1ab943c16b
|
JavaScript: Fix typo in query help.
|
2018-10-01 08:04:45 +01:00 |
|
Aditya Sharad
|
1c71a856e1
|
Version: Bump to 1.18.1 dev.
|
2018-09-28 16:39:44 +01:00 |
|
Aditya Sharad
|
f5bd737ada
|
Version: Fix C# and JavaScript Eclipse plugins for 1.18.
|
2018-09-28 14:10:06 +01:00 |
|
Asger F
|
e4c8653549
|
JS: Factor RequestHeaderAccess into separate class
|
2018-09-27 16:28:58 +01:00 |
|
semmle-qlci
|
df4bd36b0f
|
Merge pull request #236 from aschackmull/xml-qll/use-concat
Approved by hvitved, xiemaisi, yh-semmle
|
2018-09-27 11:58:58 +01:00 |
|
Asger F
|
c879654796
|
JS: add qhelp
|
2018-09-27 10:21:57 +01:00 |
|
Asger F
|
433db7a3e6
|
JS: add to security suite
|
2018-09-27 10:20:35 +01:00 |
|
Asger F
|
46336a5643
|
JS: Add HostHeaderPoisoningInEmailGeneration query
|
2018-09-27 10:20:35 +01:00 |
|
Asger F
|
1b4fc93e9d
|
JS: add HTTP::RequestInputAccess.getAHeaderName()
|
2018-09-27 10:20:35 +01:00 |
|
Asger F
|
f7775f36a8
|
JS: Add EmailClients lib
|
2018-09-27 10:20:35 +01:00 |
|
Aditya Sharad
|
51697f077c
|
Version: Bump to 1.18.0 release.
|
2018-09-26 18:18:20 +01:00 |
|
semmle-qlci
|
c36e7f07be
|
Merge pull request #231 from asger-semmle/express-headers
Approved by xiemaisi
|
2018-09-26 15:40:58 +01:00 |
|
Asger F
|
f0886fd0bb
|
JS: fix indefinite check on callback
|
2018-09-26 15:25:26 +01:00 |
|
Anders Schack-Mulligen
|
9198f5b9bd
|
CPP/CSharp/Java/Javascript: Use concat in XMLParent.allCharactersString().
|
2018-09-26 15:47:21 +02:00 |
|
Anders Schack-Mulligen
|
26c1397216
|
CPP/CSharp/Javascript: Clean up QLDoc and bring the different XML.qll files closer.
|
2018-09-26 15:36:20 +02:00 |
|
semmle-qlci
|
a93939b827
|
Merge pull request #230 from esben-semmle/js/ad-hoc-whitelisting
Approved by xiemaisi
|
2018-09-26 14:14:25 +01:00 |
|
Aditya Sharad
|
75680dbfef
|
Merge branch 'next' into qlucie/master
|
2018-09-26 12:08:33 +01:00 |
|
Asger F
|
057c3a92b4
|
JS: update other Express test outputs
|
2018-09-26 08:36:52 +01:00 |
|
Esben Sparre Andreasen
|
7c006d4530
|
Merge pull request #222 from xiemaisi/js/identity-replacement
JavaScript: Add new query flagging identity replacements.
|
2018-09-26 09:25:19 +02:00 |
|
Asger F
|
a47b1dc774
|
JS: recognize Express header access with dynamic name
|
2018-09-26 08:22:21 +01:00 |
|
Esben Sparre Andreasen
|
52061b35d8
|
JS: address review comments: improve regex, limit sanitizer usage
|
2018-09-26 09:20:07 +02:00 |
|
Asger F
|
e78a4e9f10
|
JS: update output from other Express tests
|
2018-09-26 07:58:44 +01:00 |
|
Asger F
|
ce11b5330d
|
JS: recognize Express headers as RequestInputAccess
|
2018-09-26 07:58:44 +01:00 |
|
Max Schaefer
|
0e63ea1b51
|
JavaScript: Update tests.
|
2018-09-25 11:27:12 +01:00 |
|
Max Schaefer
|
659c67c715
|
JavaScript: Produce friendlier message for empty-string replacements.
|
2018-09-25 11:27:12 +01:00 |
|
Max Schaefer
|
5fb22ba021
|
JavaScript: Handle zero-width assertions and sequences.
|
2018-09-25 11:27:12 +01:00 |
|
Max Schaefer
|
ec9a3c87a7
|
JavaScript: Do not flag case-insensitive replace.
|
2018-09-25 11:27:11 +01:00 |
|
Max Schaefer
|
1ab11109f9
|
JavaScript: Add new query flagging identity replacements.
|
2018-09-25 11:27:11 +01:00 |
|
Asger F
|
0936cda0e9
|
JS: avoid expensive join_rhs in callInputStep
|
2018-09-25 10:16:40 +01:00 |
|
Asger F
|
52c913b325
|
JavaScript: cache AdditionalPartialInvokeNode
|
2018-09-25 10:16:40 +01:00 |
|
Asger F
|
3ca7d6b4bf
|
JavaScript: address comments
|
2018-09-25 10:16:40 +01:00 |
|
Asger F
|
269bbc9a1a
|
JavaScript: add flow steps through partial function application
|
2018-09-25 10:16:40 +01:00 |
|
Denis Levin
|
1438cae362
|
Correction to the test's expected file as the test was modified.
|
2018-09-24 10:45:54 -07:00 |
|
semmle-qlci
|
7f56be6fe2
|
Merge pull request #216 from asger-semmle/lusca-csrf
Approved by esben-semmle
|
2018-09-24 11:34:24 +01:00 |
|
semmle-qlci
|
46178271d1
|
Merge pull request #213 from asger-semmle/sendfile
Approved by xiemaisi
|
2018-09-24 11:32:46 +01:00 |
|
Esben Sparre Andreasen
|
42fc28bc55
|
JS: add ad hoc whitelist checks as sanitizers
|
2018-09-24 11:17:35 +02:00 |
|
Dave Bartolomeo
|
1f36f5552f
|
Normalize all text files to LF
Use `* text=auto eol=lf`
|
2018-09-23 16:24:31 -07:00 |
|
Dave Bartolomeo
|
26abf5d4a2
|
Force LF for basically everything.
|
2018-09-23 16:24:31 -07:00 |
|
Denis Levin
|
8152cefa60
|
Squished changes for HttpToFileAccess commint
|
2018-09-21 16:44:01 -07:00 |
|
Asger F
|
4797924bea
|
JS: review comments
|
2018-09-21 14:46:21 +01:00 |
|
Asger F
|
5f467d2fc5
|
JS: recognize CSRF middleware from lusca package
|
2018-09-21 13:15:40 +01:00 |
|
Asger F
|
6f109a742f
|
JS: add a test case for res.sendfile
|
2018-09-21 11:04:33 +01:00 |
|
alexet
|
b94df82833
|
JavaScript: Fix expected output due to qltest change.
|
2018-09-20 15:56:20 +01:00 |
|
semmle-qlci
|
f146e34e26
|
Merge pull request #207 from dave-bartolomeo/dave/JSNewlines
Approved by esben-semmle
|
2018-09-20 14:49:54 +01:00 |
|
Dave Bartolomeo
|
b12c739915
|
JavaScript: Normalize line endings of .js and .html files
Added .gitattributes files for the two directories where we intentionally have line endings other than LF
|
2018-09-19 21:33:27 -07:00 |
|
semmle-qlci
|
4aca8f4fd3
|
Merge pull request #201 from asger-semmle/string-concatenation-squashed
Approved by esben-semmle
|
2018-09-19 21:59:17 +01:00 |
|
Asger F
|
1d793c0a7b
|
JavaScript: fix expected output
|
2018-09-19 14:33:23 +01:00 |
|
Esben Sparre Andreasen
|
2cedc81774
|
JS: polish js/enabling-electron-renderer-node-integration meta info
|
2018-09-19 13:45:42 +02:00 |
|
semmle-qlci
|
89f2dbf8db
|
Merge pull request #195 from esben-semmle/js/reflected-xss-through-filenames
Approved by asger-semmle
|
2018-09-19 12:42:22 +01:00 |
|
Asger F
|
9384b85bcc
|
JavaScript: ensure prefix sanitizers work for array.join()
|
2018-09-17 14:31:26 +01:00 |
|