Esben Sparre Andreasen
b00aa36cdc
JS: polish HttpToFileAccess.ql
2018-10-10 12:12:54 +02:00
Esben Sparre Andreasen
d261915598
JS: polish FileAccessToHttp.ql
2018-10-10 12:12:54 +02:00
Asger F
74f115fa40
JS: add test case
2018-10-10 10:46:40 +01:00
Asger F
fd58039753
JS: update additional QL test output
2018-10-09 08:54:14 +01:00
Asger F
030bae9454
JS: Canonicalize ThisNode
2018-10-09 08:53:41 +01:00
Tom Hvitved
ccebd5eb11
Merge remote-tracking branch 'upstream/master' into mergeback-2018-10-08
2018-10-08 16:23:29 +02:00
Asger F
d2af4ab94a
Merge pull request #227 from xiemaisi/js/taint-kinds
...
JavaScript: Add support for state-based taint tracking.
2018-10-08 15:09:12 +01:00
Tom Hvitved
49644bfb47
Merge remote-tracking branch 'upstream/master' into mergeback-2018-10-08
2018-10-08 11:48:56 +02:00
Esben Sparre Andreasen
a668f906bc
JS: recognize binding decorators on classes
2018-10-08 07:58:12 +02:00
semmle-qlci
98254e87e1
Merge pull request #132 from denislevin/denisl/js/HttpToFileAccessTest
...
Approved by xiemaisi
2018-10-04 14:06:46 +01:00
Asger F
8bc92bd534
TS: test case for type expansion through type parameter bound
2018-10-04 12:05:05 +01:00
semmle-qlci
bea86e52fb
Merge pull request #275 from xiemaisi/js/workaround-for-nested-imports
...
Approved by asger-semmle
2018-10-04 08:25:52 +01:00
Max Schaefer
5727b2a5f4
JavaScript: Properly handle value-preserving paths.
...
When constructing a path through a property write/read pair, we want to make sure that we only use value-preserving steps to track the base object. However, the value flowing in from the right-hand side of the assignment may have a different flow label (such as `taint()`), so we cannot use the normal `append` predicate to construct the composite path.
2018-10-03 15:49:02 +01:00
Max Schaefer
910d6de47d
JavaScript: Add new tests.
2018-10-03 15:49:02 +01:00
Max Schaefer
017ae4990d
JavaScript: Use custom flow labels in ClientSideUrlRedirect.
2018-10-03 15:49:02 +01:00
Max Schaefer
f4ea8bc82a
JavaScript: Introduce flow labels.
2018-10-03 15:49:02 +01:00
Max Schaefer
f3239cbec9
JavaScript: Respect barriers on return edges.
2018-10-03 15:49:01 +01:00
Max Schaefer
cc1c7b11d6
Merge pull request #263 from asger-semmle/ts-tokens
...
TypeScript: add tokenization test cases
2018-10-03 15:38:58 +01:00
Max Schaefer
8b7bb8cecc
JavaScript: Add test case for type inference in the presence of non-toplevel imports.
2018-10-03 13:08:31 +01:00
semmle-qlci
e9adc63d91
Merge pull request #260 from xiemaisi/js/confusing-precedence
...
Approved by esben-semmle, mc-semmle
2018-10-03 09:07:18 +01:00
Denis Levin
e147e690ee
Merge branch 'master' into denisl/js/HttpToFileAccessTest
2018-10-02 15:13:35 -07:00
Max Schaefer
425d2bfba7
Merge pull request #266 from esben-semmle/js/improve-dead-store-of-local
...
JS: support noop parentheses in js/useless-assignment-to-local
2018-10-02 16:19:56 +01:00
semmle-qlci
b35f450b01
Merge pull request #162 from asger-semmle/partial-calls
...
Approved by esben-semmle, xiemaisi
2018-10-02 11:24:02 +01:00
Asger F
057af7c865
TypeScript: add test case with mixed rescanned tokens
2018-10-02 10:42:33 +01:00
Max Schaefer
768368498f
JavaScript: Introduce new query UnclearOperatorPrecedence.
2018-10-02 08:46:51 +01:00
Max Schaefer
a63b7fc215
JavaScript: Introduce new library predicate for computing whitespace around binary operators.
2018-10-02 08:46:11 +01:00
semmle-qlci
829a5cc451
Merge pull request #259 from asger-semmle/open-redirect-expr
...
Approved by xiemaisi
2018-10-02 08:32:48 +01:00
Esben Sparre Andreasen
595fe217dd
JS: support noop parentheses in js/useless-assignment-to-local
...
The syntatic recognizer `isNullOrUndef` did not handle expressions
that were wrapped in parentheses.
This eliminates some results here:
https://lgtm.com/projects/g/vuejs/vue/alerts?mode=tree&ruleFocus=7900088
2018-10-02 09:31:32 +02:00
Denis Levin
9c487bc6d9
Merge branch 'master'
2018-10-01 14:51:56 -07:00
Denis Levin
82d8b4e371
Adding the source link to the test case samples
2018-10-01 11:45:38 -07:00
Aditya Sharad
337defdf3d
Merge master into next.
2018-10-01 17:39:27 +01:00
Asger F
d3a1df644c
TypeScript: test case for tokens starting with ">"
2018-10-01 17:35:21 +01:00
Asger F
a199035a05
TypeScript: test case for whitespace before a rescanned token
2018-10-01 17:35:15 +01:00
Asger F
9146cc26bd
TypeScript: test case for tokenization of template literals
2018-10-01 14:36:19 +01:00
Asger F
9f07b1011d
JS: bugfix in server-side redirect query
2018-10-01 12:34:13 +01:00
Asger F
e4c8653549
JS: Factor RequestHeaderAccess into separate class
2018-09-27 16:28:58 +01:00
Asger F
46336a5643
JS: Add HostHeaderPoisoningInEmailGeneration query
2018-09-27 10:20:35 +01:00
Asger F
1b4fc93e9d
JS: add HTTP::RequestInputAccess.getAHeaderName()
2018-09-27 10:20:35 +01:00
Asger F
f7775f36a8
JS: Add EmailClients lib
2018-09-27 10:20:35 +01:00
semmle-qlci
c36e7f07be
Merge pull request #231 from asger-semmle/express-headers
...
Approved by xiemaisi
2018-09-26 15:40:58 +01:00
semmle-qlci
a93939b827
Merge pull request #230 from esben-semmle/js/ad-hoc-whitelisting
...
Approved by xiemaisi
2018-09-26 14:14:25 +01:00
Aditya Sharad
75680dbfef
Merge branch 'next' into qlucie/master
2018-09-26 12:08:33 +01:00
Asger F
057c3a92b4
JS: update other Express test outputs
2018-09-26 08:36:52 +01:00
Esben Sparre Andreasen
7c006d4530
Merge pull request #222 from xiemaisi/js/identity-replacement
...
JavaScript: Add new query flagging identity replacements.
2018-09-26 09:25:19 +02:00
Asger F
a47b1dc774
JS: recognize Express header access with dynamic name
2018-09-26 08:22:21 +01:00
Esben Sparre Andreasen
52061b35d8
JS: address review comments: improve regex, limit sanitizer usage
2018-09-26 09:20:07 +02:00
Asger F
e78a4e9f10
JS: update output from other Express tests
2018-09-26 07:58:44 +01:00
Asger F
ce11b5330d
JS: recognize Express headers as RequestInputAccess
2018-09-26 07:58:44 +01:00
Max Schaefer
0e63ea1b51
JavaScript: Update tests.
2018-09-25 11:27:12 +01:00
Max Schaefer
1ab11109f9
JavaScript: Add new query flagging identity replacements.
2018-09-25 11:27:11 +01:00