Erik Krogh Kristensen
|
1435ac715a
|
add support for the clone library
|
2021-05-18 12:46:34 +02:00 |
|
CodeQL CI
|
12b1bbe484
|
Merge pull request #5897 from erik-krogh/uid
Approved by RasmusWL, esbena
|
2021-05-17 06:01:04 -07:00 |
|
CodeQL CI
|
af0d31695a
|
Merge pull request #5862 from asgerf/js/has-underlying-type
Approved by erik-krogh, max-schaefer
|
2021-05-14 04:10:43 -07:00 |
|
Erik Krogh Kristensen
|
33641c84f6
|
recognize sanitizing string replace call for regexp-injection
|
2021-05-14 11:58:27 +02:00 |
|
Erik Krogh Kristensen
|
9d60ec035f
|
fix casing on the uid regexp
|
2021-05-13 23:04:30 +02:00 |
|
Erik Krogh Kristensen
|
51067af784
|
add "uid" (and friends) as maybe being sensitive account info
|
2021-05-13 22:34:10 +02:00 |
|
CodeQL CI
|
9b0c24abc2
|
Merge pull request #5876 from erik-krogh/moreAxios
Approved by asgerf
|
2021-05-13 08:03:33 -07:00 |
|
Erik Krogh Kristensen
|
e0f78dde56
|
make the axios error catch match the non-error case
|
2021-05-12 16:23:37 +02:00 |
|
yoff
|
a7f97895ac
|
Merge pull request #5863 from erik-krogh/printReg
JS: add printAst.ql support for regular expressions
|
2021-05-11 12:45:49 +02:00 |
|
CodeQL CI
|
a87731115a
|
Merge pull request #5860 from max-schaefer/js/improve-sql-modelling
Approved by asgerf
|
2021-05-11 02:24:52 -07:00 |
|
Erik Krogh Kristensen
|
99e98419dc
|
add support for error values in an axios client request
|
2021-05-11 11:24:21 +02:00 |
|
CodeQL CI
|
beb66fc4db
|
Merge pull request #5719 from asgerf/js/nestjs
Approved by esbena
|
2021-05-11 02:08:27 -07:00 |
|
CodeQL CI
|
a3d17a1437
|
Merge pull request #5769 from erik-krogh/libXss
Approved by esbena
|
2021-05-10 05:58:07 -07:00 |
|
Erik Krogh Kristensen
|
d6f9e37e39
|
add printAst.ql support for regular expressions
|
2021-05-10 13:31:00 +02:00 |
|
Asger Feldthaus
|
3e5dc1efb7
|
JS: More robust hasUnderlyingType
|
2021-05-10 13:17:25 +02:00 |
|
Max Schaefer
|
8f91e9eba0
|
JavaScript: Model chaining calls in sqlite3.
|
2021-05-10 10:58:58 +01:00 |
|
CodeQL CI
|
097b6e5e33
|
Merge pull request #5794 from erik-krogh/rxPipe
Approved by asgerf
|
2021-05-10 02:06:34 -07:00 |
|
CodeQL CI
|
7a7586488a
|
Merge pull request #5833 from erik-krogh/filterStep
Approved by esbena
|
2021-05-06 13:47:23 -07:00 |
|
Erik Krogh Kristensen
|
3815797dda
|
add sanitizers from DOM and jQuery queries
|
2021-05-06 11:05:03 +02:00 |
|
Erik Krogh Kristensen
|
8ba5bddae8
|
add jQuery options objects as sources
|
2021-05-06 11:05:02 +02:00 |
|
Erik Krogh Kristensen
|
23908f9ec2
|
remove flowpaths that has a returns without a matching call
|
2021-05-06 11:05:02 +02:00 |
|
Erik Krogh Kristensen
|
6e754c70aa
|
add test for js/html-constructed-from-input
|
2021-05-06 11:05:02 +02:00 |
|
Erik Krogh Kristensen
|
ab53f3b380
|
add array.filter() as a taint-step
|
2021-05-05 12:03:14 +02:00 |
|
Erik Krogh Kristensen
|
e333267e69
|
require that the factory function is in a main module file
|
2021-05-05 12:00:38 +02:00 |
|
Erik Krogh Kristensen
|
aaf754ebf5
|
recognize more library input
|
2021-05-04 10:06:14 +02:00 |
|
CodeQL CI
|
6931d9a6f7
|
Merge pull request #5785 from edvraa/httponlyjs
Approved by esbena
|
2021-05-03 23:14:26 -07:00 |
|
edvraa
|
6fa2f1e653
|
update test message
|
2021-05-04 00:32:01 +03:00 |
|
edvraa
|
cef845ac47
|
Support string expressions
|
2021-05-03 13:46:56 +03:00 |
|
edvraa
|
ea38f0d3bd
|
a new test for simple flow
|
2021-05-03 12:19:05 +03:00 |
|
edvraa
|
fa94fedfc3
|
simple dataflow for sensitive name
|
2021-05-03 00:36:26 +03:00 |
|
edvraa
|
97bc7e38d2
|
check for sensitive property name
|
2021-05-03 00:31:29 +03:00 |
|
Rasmus Wriedt Larsen
|
af0723c185
|
Merge pull request #5656 from asgerf/js/files-diagnostics
JS: Add file diagnostics queries
|
2021-04-29 11:53:11 +02:00 |
|
CodeQL CI
|
3240536d0e
|
Merge pull request #5798 from erik-krogh/trackLoc
Approved by esbena
|
2021-04-29 00:45:21 -07:00 |
|
Erik Krogh Kristensen
|
dfd63e5d5a
|
track window object to where .location is read
|
2021-04-28 18:52:00 +02:00 |
|
Erik Krogh Kristensen
|
902a4368a1
|
assume that all pipe elements that return something, return outputs
|
2021-04-28 12:36:07 +02:00 |
|
Erik Krogh Kristensen
|
2f14a6218a
|
generalize RxJS pipes
|
2021-04-28 12:26:02 +02:00 |
|
Erik Krogh Kristensen
|
e60628d463
|
add global replacements using inverted char classes as a sanitizer for DOM based XSS
|
2021-04-28 11:29:30 +02:00 |
|
Erik Krogh Kristensen
|
9178f4b1c5
|
add support for the anser library
|
2021-04-27 15:57:17 +02:00 |
|
edvraa
|
3aec9c1a41
|
Cookies without HttpOnly
|
2021-04-27 16:28:32 +03:00 |
|
Asger Feldthaus
|
71e3041370
|
JS: Fewer spurious reflected xss sinks
|
2021-04-23 13:15:35 +01:00 |
|
Asger Feldthaus
|
671e968936
|
JS: Model NestJS
|
2021-04-23 13:15:35 +01:00 |
|
CodeQL CI
|
635fb4c25a
|
Merge pull request #5685 from erik-krogh/markdownIt
Approved by asgerf
|
2021-04-22 14:55:31 -07:00 |
|
Erik Krogh Kristensen
|
62dfd1fa7d
|
improve the markdown-it model
|
2021-04-20 15:23:03 +02:00 |
|
Erik Krogh Kristensen
|
7046f1a902
|
add taint-step for markdown-it when the HTML flag is set
|
2021-04-20 14:39:54 +02:00 |
|
Asger Feldthaus
|
f8d428cb2d
|
JS: Use function-forwarding steps when tracking rate limiters
|
2021-04-20 13:00:42 +01:00 |
|
Asger Feldthaus
|
581f4ed757
|
JS: Generalize handling of route handler wrapper functions
|
2021-04-20 12:46:40 +01:00 |
|
CodeQL CI
|
578ce1e512
|
Merge pull request #5683 from asgerf/js/typescript-template-literal-type-crash
Approved by erik-krogh
|
2021-04-15 05:11:11 -07:00 |
|
Asger Feldthaus
|
b4a2a9db25
|
JS: Fix extraction of non-substitution template literal types
|
2021-04-15 09:23:45 +01:00 |
|
Erik Krogh Kristensen
|
fd23e0bdda
|
use more API nodes in XmlParsers, and recognize more results from parsing XML
|
2021-04-14 11:48:31 +02:00 |
|
Asger Feldthaus
|
d2fad180f8
|
JS: Add test
|
2021-04-12 15:07:45 +01:00 |
|