Erik Krogh Kristensen
|
12c24c07df
|
improve the got model
|
2021-11-15 21:52:12 +01:00 |
|
Erik Krogh Kristensen
|
5d901ef728
|
move extend aliasing to getAnAliasedSourceNode
|
2021-11-10 18:08:50 +01:00 |
|
Erik Krogh Kristensen
|
2d907f825e
|
have the aliasPropertyPresenceStep step over extend calls
|
2021-11-10 16:26:00 +01:00 |
|
Erik Krogh Kristensen
|
8569d261f7
|
add test
|
2021-09-13 20:43:31 +02:00 |
|
CodeQL CI
|
cd26d97dd7
|
Merge pull request #6549 from erik-krogh/moreDom
Approved by asgerf
|
2021-09-08 05:10:47 -07:00 |
|
Erik Krogh Kristensen
|
cecb6c7bdd
|
add model for live-server
|
2021-08-31 14:23:23 +02:00 |
|
Erik Krogh Kristensen
|
81742528a2
|
add test
|
2021-08-27 10:04:39 +02:00 |
|
CodeQL CI
|
92804a3cc3
|
Merge pull request #6487 from erik-krogh/moreJquerySinks
Approved by asgerf
|
2021-08-17 11:46:24 +01:00 |
|
Erik Krogh Kristensen
|
cc2a267b07
|
recognize array elements from JQuery objects as DOM values
|
2021-08-16 22:35:57 +02:00 |
|
Asger Feldthaus
|
cb0075f15a
|
JS: Remove use of deprecated API
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
f1bcfa287b
|
JS: Add more tests
|
2021-08-10 08:55:03 +02:00 |
|
Asger Feldthaus
|
00f4694616
|
JS: Recognize methods returning DOM objects
|
2021-08-04 16:25:56 +02:00 |
|
CodeQL CI
|
6c2c51a767
|
Merge pull request #6287 from erik-krogh/react-tooltip
Approved by asgerf
|
2021-07-16 02:10:36 -07:00 |
|
CodeQL CI
|
d4fa1f7d96
|
Merge pull request #6295 from erik-krogh/sort-keys
Approved by asgerf
|
2021-07-16 02:09:47 -07:00 |
|
Erik Krogh Kristensen
|
28b98c1bfa
|
update expected output
|
2021-07-15 15:51:01 +02:00 |
|
Erik Krogh Kristensen
|
ae2fc7171b
|
add a taint step through the ansi-to-html library
|
2021-07-15 14:04:16 +02:00 |
|
Erik Krogh Kristensen
|
aaa8969537
|
add sort-keys as a clone call
|
2021-07-15 13:16:17 +02:00 |
|
Erik Krogh Kristensen
|
22dfe84ee8
|
add xss sink for react-tooltip
|
2021-07-14 20:03:50 +02:00 |
|
Erik Krogh Kristensen
|
23c3be6860
|
add support for the json-cycle library
|
2021-07-12 11:03:39 +02:00 |
|
Erik Krogh Kristensen
|
94cbc4b2c0
|
add step through the fclone library
|
2021-07-12 10:51:43 +02:00 |
|
Esben Sparre Andreasen
|
85b9003af4
|
JS: add Mootools XSS sinks
|
2021-07-01 09:17:27 +02:00 |
|
Erik Krogh Kristensen
|
c736606695
|
add support for moment/dayjs/luxon instances returned by @date-io adapters
|
2021-06-22 10:42:24 +02:00 |
|
Erik Krogh Kristensen
|
227f61b954
|
add model for the luxon library
|
2021-06-21 23:29:12 +02:00 |
|
Erik Krogh Kristensen
|
cdf3cdcf71
|
add model for the formatByString and formatByNumber functions in @date-io
|
2021-06-21 23:29:01 +02:00 |
|
Erik Krogh Kristensen
|
2a4570eaaa
|
add model for the dayjs library
|
2021-06-21 23:28:45 +02:00 |
|
CodeQL CI
|
d65e6bbfa1
|
Merge pull request #6035 from erik-krogh/joi
Approved by asgerf
|
2021-06-09 04:42:54 -07:00 |
|
CodeQL CI
|
169e67cbb8
|
Merge pull request #5990 from erik-krogh/prettier
Approved by asgerf
|
2021-06-08 12:17:24 -07:00 |
|
Erik Krogh Kristensen
|
be7abede22
|
add model for the joi library
|
2021-06-07 20:04:17 +02:00 |
|
Erik Krogh Kristensen
|
0adc001df0
|
add taint-step for serialize-javascript
|
2021-06-06 22:48:53 +02:00 |
|
Erik Krogh Kristensen
|
788c5ba701
|
add support for the prettier API
|
2021-06-02 15:33:08 +02:00 |
|
Erik Krogh Kristensen
|
e9d2dd0b57
|
support the chaining methods on Express apps
|
2021-05-18 22:23:27 +02:00 |
|
Erik Krogh Kristensen
|
1435ac715a
|
add support for the clone library
|
2021-05-18 12:46:34 +02:00 |
|
Erik Krogh Kristensen
|
3815797dda
|
add sanitizers from DOM and jQuery queries
|
2021-05-06 11:05:03 +02:00 |
|
Erik Krogh Kristensen
|
8ba5bddae8
|
add jQuery options objects as sources
|
2021-05-06 11:05:02 +02:00 |
|
Erik Krogh Kristensen
|
23908f9ec2
|
remove flowpaths that has a returns without a matching call
|
2021-05-06 11:05:02 +02:00 |
|
Erik Krogh Kristensen
|
6e754c70aa
|
add test for js/html-constructed-from-input
|
2021-05-06 11:05:02 +02:00 |
|
Erik Krogh Kristensen
|
e60628d463
|
add global replacements using inverted char classes as a sanitizer for DOM based XSS
|
2021-04-28 11:29:30 +02:00 |
|
Erik Krogh Kristensen
|
9178f4b1c5
|
add support for the anser library
|
2021-04-27 15:57:17 +02:00 |
|
Erik Krogh Kristensen
|
62dfd1fa7d
|
improve the markdown-it model
|
2021-04-20 15:23:03 +02:00 |
|
Erik Krogh Kristensen
|
7046f1a902
|
add taint-step for markdown-it when the HTML flag is set
|
2021-04-20 14:39:54 +02:00 |
|
Asger Feldthaus
|
e30fa89405
|
JS: Update more test expectations
|
2021-03-18 10:04:39 +00:00 |
|
Asger Feldthaus
|
9cfbb90591
|
JS: Add test case for insufficient replace-sanitizer
|
2021-03-17 15:20:40 +00:00 |
|
Asger Feldthaus
|
97b8e35426
|
JS: Update test expectations
|
2021-03-16 15:09:01 +00:00 |
|
Asger Feldthaus
|
710cca5395
|
JS: Update expectations with new sources
|
2021-03-16 13:28:12 +00:00 |
|
Asger Feldthaus
|
2e57a7d3e9
|
JS: Add ClientSideRemoteFlowSource
|
2021-03-16 13:28:09 +00:00 |
|
CodeQL CI
|
40acb95105
|
Merge pull request #5397 from erik-krogh/globalSanitizer
Approved by asgerf
|
2021-03-16 05:37:32 -07:00 |
|
CodeQL CI
|
a9c292e265
|
Merge pull request #5391 from erik-krogh/additionalXss
Approved by asgerf
|
2021-03-15 04:50:54 -07:00 |
|
Erik Krogh Kristensen
|
1dcfc3840d
|
add test
|
2021-03-12 16:25:33 +01:00 |
|
Asger Feldthaus
|
a2d1e88bb3
|
JS: Update more test expectations
|
2021-03-12 12:57:21 +00:00 |
|
Erik Krogh Kristensen
|
d7b0f628a1
|
add test
|
2021-03-12 00:03:20 +01:00 |
|