intrigus
|
7023793af4
|
Java: Fix compilation errors in test.
|
2021-06-25 16:47:23 +02:00 |
|
intrigus
|
592fd1e8ca
|
Java: Accept test changes
|
2021-06-25 16:47:22 +02:00 |
|
intrigus
|
1b96d0ac54
|
Java: Remove overlapping code
|
2021-06-25 16:47:22 +02:00 |
|
intrigus
|
87554a78d4
|
Java: Add insecure trust manager query.
|
2021-06-25 16:47:22 +02:00 |
|
Owen Mansel-Chan
|
044ecc51e5
|
Manually improve tests #2
|
2021-06-25 13:51:18 +01:00 |
|
Owen Mansel-Chan
|
2fd4c9f1b9
|
Manually improve tests
|
2021-06-25 11:17:11 +01:00 |
|
Owen Mansel-Chan
|
2e670c4050
|
Manually update automatically generated stubs
|
2021-06-25 11:17:08 +01:00 |
|
Owen Mansel-Chan
|
acc43fcaca
|
Add options file
|
2021-06-25 11:17:07 +01:00 |
|
Owen Mansel-Chan
|
5feee9cc17
|
Add automatically-generated stubs
|
2021-06-25 11:17:06 +01:00 |
|
Owen Mansel-Chan
|
7004c87ec0
|
Manually edit tests so they pass
|
2021-06-25 11:17:05 +01:00 |
|
Owen Mansel-Chan
|
4388f19ddf
|
Add automatically-generated tests
|
2021-06-25 11:17:04 +01:00 |
|
Chris Smowton
|
2acb4de2cb
|
Merge pull request #5955 from haby0/java/JShellCodeInjection
Java: JShell Injection
|
2021-06-24 17:03:30 +01:00 |
|
Anders Schack-Mulligen
|
95ad8b55fe
|
Merge pull request #6107 from aschackmull/dataflow/implicit-reads
Dataflow: Add support for implicit reads
|
2021-06-24 15:38:35 +02:00 |
|
haby0
|
3cf71c50b8
|
Mobile stubs
|
2021-06-24 19:24:38 +08:00 |
|
Anders Schack-Mulligen
|
1e511c0a9e
|
Merge pull request #6137 from smowton/smowton/feature/java-util-optional
Java: Model java.util.Optional
|
2021-06-24 13:21:36 +02:00 |
|
yo-h
|
ffdc752720
|
Merge pull request #6059 from smowton/smowton/fix/qualified-name-generic-types
Adapt to static methods and nested types returning unbound declaring types
|
2021-06-23 14:45:51 -04:00 |
|
Chris Smowton
|
74feaf2893
|
Adapt to static methods and nested types returning unbound declaring types
Previously these returned raw declaring types instead
|
2021-06-23 16:03:18 +01:00 |
|
Chris Smowton
|
b34448af87
|
{Generic,Parameterized,Raw}Type: implement getAPrimaryQlClass
An aid to debugging
|
2021-06-23 15:58:31 +01:00 |
|
Artem Smotrakov
|
14e724bce6
|
Added sinks for RmiBasedExporter and HessianExporter
|
2021-06-23 09:53:47 +02:00 |
|
Chris Smowton
|
9fd1606238
|
Model java.util.Optional
|
2021-06-22 21:17:22 +01:00 |
|
Anders Schack-Mulligen
|
206a37cf08
|
Merge pull request #6130 from aschackmull/java/collection-test
Java: Improve test and fix a few missing cases.
|
2021-06-22 11:56:44 +02:00 |
|
Anders Schack-Mulligen
|
38fc8a750c
|
Java: Improve test and fix a few missing cases.
|
2021-06-22 11:16:02 +02:00 |
|
Anders Schack-Mulligen
|
c06e152e90
|
Java: Remove outdated test.
|
2021-06-21 16:08:59 +02:00 |
|
Anders Schack-Mulligen
|
27c973e157
|
Java: Fix some qltests.
|
2021-06-21 16:08:52 +02:00 |
|
Chris Smowton
|
e2aaae8181
|
Increase test fieldFlowBranchLimit to 1000
Might as well head off future failures in this test
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-06-21 12:51:37 +01:00 |
|
Chris Smowton
|
c5eef7be8c
|
Increase field flow branch limit in Jax-RS tests
This fixes apparently-missing results by allowing the dataflow library to persist even when there are many Map implementations possibly available.
|
2021-06-21 12:46:13 +01:00 |
|
haby0
|
1750efad2a
|
fix
|
2021-06-18 21:46:48 +08:00 |
|
haby0
|
dca737190b
|
Modify JShellInjection.expected
|
2021-06-18 21:36:45 +08:00 |
|
haby0
|
ed0aabef46
|
add isAdditionalTaintStep
|
2021-06-18 21:36:44 +08:00 |
|
haby0
|
921b8e80a2
|
Jshell Injection
|
2021-06-18 21:36:44 +08:00 |
|
Chris Smowton
|
6302187a5d
|
Merge pull request #5957 from haby0/java/BeanShellInjection
Java: BeanShell Injection
|
2021-06-18 12:38:51 +01:00 |
|
Anders Schack-Mulligen
|
7eb6da3888
|
Merge pull request #5772 from smowton/smowton/feature/apache-tuple-flow
Add models for Apache Commons Lang's tuple types
|
2021-06-18 11:25:07 +02:00 |
|
haby0
|
a73cb3f04a
|
Fix error
|
2021-06-18 17:22:26 +08:00 |
|
haby0
|
0d18e4ff9c
|
BeanShell Injection
|
2021-06-18 15:54:13 +08:00 |
|
Tony Torralba
|
1014400a08
|
Fix test comments
|
2021-06-17 15:03:45 +02:00 |
|
Tony Torralba
|
3ec2c1308e
|
Add RequestForgerySanitizer
|
2021-06-17 14:58:27 +02:00 |
|
Tony Torralba
|
0c71393171
|
Merge branch 'main' into atorralba/promote-unsafe-android-webview-fetch
|
2021-06-17 14:54:25 +02:00 |
|
Chris Smowton
|
2cc1f46871
|
Model constructors for (Imm|M)utable(Pair|Triple)
|
2021-06-17 12:34:40 +01:00 |
|
Chris Smowton
|
fbaa382158
|
Add tests for Pair.of and Triple.of
|
2021-06-17 12:34:40 +01:00 |
|
Chris Smowton
|
472a2a64dd
|
Add models for Apache Commons tuples
|
2021-06-17 12:25:21 +01:00 |
|
Chris Smowton
|
11b70326fd
|
Add Jakarta WS url-open sink
|
2021-06-17 11:58:41 +01:00 |
|
Chris Smowton
|
7509e36382
|
Remove no-longer-needed BasicRequestLine model from InsecureBasicAuth.ql; adjust test expectations accordingly
|
2021-06-17 11:43:33 +01:00 |
|
Chris Smowton
|
c531b81ebe
|
Rename RequestForgery.java -> SanitizationTests.java
|
2021-06-17 11:43:33 +01:00 |
|
Chris Smowton
|
cb99e17f4d
|
Split and rename JavaNetHttp and ApacheHttp tests for consistency
|
2021-06-17 11:43:32 +01:00 |
|
Chris Smowton
|
6c4a909b86
|
Remove dead code from test
|
2021-06-17 11:43:32 +01:00 |
|
Chris Smowton
|
08ab5f5546
|
Remove redundant test
|
2021-06-17 11:43:32 +01:00 |
|
Chris Smowton
|
74569ce316
|
Tidy Jax-RS test
|
2021-06-17 11:43:32 +01:00 |
|
Chris Smowton
|
57ca36baad
|
Tidy Spring test
|
2021-06-17 11:43:32 +01:00 |
|
Chris Smowton
|
8b080a94e7
|
Convert request forgery tests to inline expectations; add missing models revealed by this process.
|
2021-06-17 11:43:32 +01:00 |
|
Chris Smowton
|
b66dcbe5b6
|
Factor request-forgery config so it can be used in an inline-expectations test
|
2021-06-17 11:43:32 +01:00 |
|