Chris Smowton
|
3c25301593
|
Extend documentation
|
2021-10-19 11:28:55 +01:00 |
|
Chris Smowton
|
d0d17e3b84
|
Make import private
|
2021-10-19 11:28:55 +01:00 |
|
Chris Smowton
|
b71920209e
|
Factor out string prefix logic
|
2021-10-19 11:28:54 +01:00 |
|
Anders Schack-Mulligen
|
90a50e7ca9
|
Java: Fix bad join-order.
|
2021-10-19 10:55:52 +02:00 |
|
Anders Schack-Mulligen
|
6508afe824
|
Merge pull request #6900 from Marcono1234/marcono1234/MemberRefExpr-receiver-type
Java: Add `MemberRefExpr.getReceiverType()`
|
2021-10-19 10:49:15 +02:00 |
|
Jonathan Leitschuh
|
db2892b9ea
|
Resove taint tracking issues from asMultimap
Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
|
2021-10-18 14:30:46 -04:00 |
|
Jonathan Leitschuh
|
5a2bdc9a0f
|
Jackson taint tracking of elements
Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
|
2021-10-18 12:21:11 -04:00 |
|
Jonathan Leitschuh
|
8fecc158ff
|
Add support for Map.forEach
Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
|
2021-10-18 12:21:11 -04:00 |
|
Jonathan Leitschuh
|
23e60e2c52
|
Add full integration test for Ratpack example
Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
|
2021-10-18 12:21:11 -04:00 |
|
Jonathan Leitschuh
|
ebbbda70c0
|
Ratpack tests all passing
Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
|
2021-10-18 12:21:11 -04:00 |
|
Jonathan Leitschuh
|
fe374f5e9c
|
Ratpack: Add support for Promise::apply
Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
|
2021-10-18 12:21:10 -04:00 |
|
Jonathan Leitschuh
|
6562ac3680
|
Ratpack conversion to new lambda model
Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
|
2021-10-18 12:21:10 -04:00 |
|
Jonathan Leitschuh
|
4f90f0a748
|
Begin refactoring Ratpack to use functional taint tracking
Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
|
2021-10-18 12:21:10 -04:00 |
|
Jonathan Leitschuh
|
6497a61c1d
|
Ratpack: Drop support for flatMap like methods
|
2021-10-18 12:21:10 -04:00 |
|
Jonathan Leitschuh
|
af90b00e63
|
Ratpack: Release note and typo fix
|
2021-10-18 12:21:10 -04:00 |
|
Jonathan Leitschuh
|
901631ceb8
|
Ratpack Promise add support for apply method
|
2021-10-18 12:21:10 -04:00 |
|
Jonathan Leitschuh
|
b9dc3d0cfe
|
Ratpack: Better support for Promise API
|
2021-10-18 12:21:09 -04:00 |
|
Jonathan Leitschuh
|
cdfdcc66bd
|
Ratpack fix formatting and non-ascii characters
|
2021-10-18 12:21:09 -04:00 |
|
Jonathan Leitschuh
|
a3b1736a73
|
Ratpack improve support for parsing types
|
2021-10-18 12:21:09 -04:00 |
|
Jonathan Leitschuh
|
ac185d9bd5
|
Remove RatpackGetRequestDataMethod
|
2021-10-18 12:21:09 -04:00 |
|
Jonathan Leitschuh
|
563e5690df
|
Refactor Ratpack to use CSV format
|
2021-10-18 12:21:09 -04:00 |
|
Jonathan Leitschuh
|
4f658df0ac
|
Apply suggestions from code review
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
|
2021-10-18 12:21:09 -04:00 |
|
Jonathan Leitschuh
|
18c74c5030
|
Simplify Ratpack API using standard abstract classes
|
2021-10-18 12:21:08 -04:00 |
|
Jonathan Leitschuh
|
b2e3df29b3
|
Add support for Promise.value and Promise::flatMap
|
2021-10-18 12:21:08 -04:00 |
|
Jonathan Leitschuh
|
b2ad128beb
|
Refactors Ratpack lambda taint tracking to use generic API
|
2021-10-18 12:21:08 -04:00 |
|
Jonathan Leitschuh
|
170657b9a4
|
Add additional Ratpack test and improve Promise based dataflow tracking
|
2021-10-18 12:21:08 -04:00 |
|
Jonathan Leitschuh
|
dabf00e8b4
|
Add Tests to Ratpack Framework Support
|
2021-10-18 12:21:08 -04:00 |
|
Jonathan Leitschuh
|
f5c3723a99
|
Java: Simple support for Ratpack HTTP Framework
|
2021-10-18 12:21:08 -04:00 |
|
Marcono1234
|
86d53931aa
|
Java: Improve MemberRefExpr.getReceiverType() documentation
|
2021-10-18 18:20:22 +02:00 |
|
Geoffrey White
|
3f3c79f48f
|
Merge pull request #6884 from geoffw0/setliterals
Replace or chains with set literals.
|
2021-10-18 16:46:55 +01:00 |
|
Anders Schack-Mulligen
|
b67032d1cc
|
Merge pull request #6891 from erik-krogh/fix-java-this
add explicit this qualifier on all of java
|
2021-10-18 17:13:37 +02:00 |
|
Tom Hvitved
|
a10bde5795
|
Merge pull request #6872 from hvitved/dataflow/path-into-callable0-join
Data flow: Performance tweaks
|
2021-10-18 16:25:10 +02:00 |
|
Tony Torralba
|
a5749a5eb1
|
Add ComponentName tests to existing Intent tests
|
2021-10-18 15:23:52 +02:00 |
|
Tom Hvitved
|
e6954292aa
|
Address review comments
|
2021-10-18 14:09:44 +02:00 |
|
Anders Schack-Mulligen
|
df9836cce0
|
Work around compiler bug.
|
2021-10-18 14:04:16 +02:00 |
|
Ian Lynagh
|
9371737331
|
Merge pull request #6894 from igfoo/igfoo/exprs
Java: Don't use dbscheme tables in CloseType.qll
|
2021-10-18 12:04:11 +01:00 |
|
Tony Torralba
|
392e2eebeb
|
Add intent creation from a URI as a taint step
|
2021-10-18 12:18:07 +02:00 |
|
Tony Torralba
|
d1d2d61d7e
|
Add more sinks
Also, fix things after rebase
|
2021-10-18 12:00:07 +02:00 |
|
Ian Lynagh
|
54d2028920
|
Update java/ql/src/Likely Bugs/Resource Leaks/CloseType.qll
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-10-18 10:12:01 +01:00 |
|
Tony Torralba
|
28ae4c211f
|
Update java/ql/src/Security/CWE/CWE-940/AndroidIntentRedirection.qhelp
Co-authored-by: Ethan Palm <56270045+ethanpalm@users.noreply.github.com>
|
2021-10-18 11:10:23 +02:00 |
|
Tony Torralba
|
e7983fb269
|
Add test and check for another edge case
|
2021-10-18 11:10:23 +02:00 |
|
Tony Torralba
|
bc6c13be69
|
Refactor to actually build the full flows from src to sink
Add more tests for edge cases
|
2021-10-18 11:10:22 +02:00 |
|
Tony Torralba
|
4dd9e7d6a0
|
Remove unnecessary import
Add comment
|
2021-10-18 11:10:22 +02:00 |
|
Tony Torralba
|
14963103aa
|
Add full path reconstruction from RemoteFlowSource to sink
|
2021-10-18 11:10:21 +02:00 |
|
Tony Torralba
|
445da1e71e
|
Move files to new location
|
2021-10-18 11:10:21 +02:00 |
|
Tony Torralba
|
8263524d70
|
Add tests for Intent and ComponentName summaries
|
2021-10-18 11:10:17 +02:00 |
|
Tony Torralba
|
2ab7a55545
|
Improve intermediate flow to add more potential sources
|
2021-10-18 11:09:52 +02:00 |
|
Tony Torralba
|
28369d1822
|
Apply suggestions from code review
Co-authored-by: Steve Guntrip <12534592+stevecat@users.noreply.github.com>
|
2021-10-18 11:09:31 +02:00 |
|
Tony Torralba
|
aa2cdb7a53
|
Add intermediate dataflow
Make sure that source intents are obtained from another intent's extras
|
2021-10-18 11:09:30 +02:00 |
|
Tony Torralba
|
f90220436f
|
Move sinks to security library
|
2021-10-18 11:09:28 +02:00 |
|