Asger F
|
52c913b325
|
JavaScript: cache AdditionalPartialInvokeNode
|
2018-09-25 10:16:40 +01:00 |
|
Asger F
|
3ca7d6b4bf
|
JavaScript: address comments
|
2018-09-25 10:16:40 +01:00 |
|
Asger F
|
269bbc9a1a
|
JavaScript: add flow steps through partial function application
|
2018-09-25 10:16:40 +01:00 |
|
Denis Levin
|
1438cae362
|
Correction to the test's expected file as the test was modified.
|
2018-09-24 10:45:54 -07:00 |
|
semmle-qlci
|
7f56be6fe2
|
Merge pull request #216 from asger-semmle/lusca-csrf
Approved by esben-semmle
|
2018-09-24 11:34:24 +01:00 |
|
semmle-qlci
|
46178271d1
|
Merge pull request #213 from asger-semmle/sendfile
Approved by xiemaisi
|
2018-09-24 11:32:46 +01:00 |
|
Esben Sparre Andreasen
|
42fc28bc55
|
JS: add ad hoc whitelist checks as sanitizers
|
2018-09-24 11:17:35 +02:00 |
|
Dave Bartolomeo
|
1f36f5552f
|
Normalize all text files to LF
Use `* text=auto eol=lf`
|
2018-09-23 16:24:31 -07:00 |
|
Dave Bartolomeo
|
26abf5d4a2
|
Force LF for basically everything.
|
2018-09-23 16:24:31 -07:00 |
|
Denis Levin
|
8152cefa60
|
Squished changes for HttpToFileAccess commint
|
2018-09-21 16:44:01 -07:00 |
|
Asger F
|
4797924bea
|
JS: review comments
|
2018-09-21 14:46:21 +01:00 |
|
Asger F
|
5f467d2fc5
|
JS: recognize CSRF middleware from lusca package
|
2018-09-21 13:15:40 +01:00 |
|
Asger F
|
6f109a742f
|
JS: add a test case for res.sendfile
|
2018-09-21 11:04:33 +01:00 |
|
alexet
|
b94df82833
|
JavaScript: Fix expected output due to qltest change.
|
2018-09-20 15:56:20 +01:00 |
|
semmle-qlci
|
f146e34e26
|
Merge pull request #207 from dave-bartolomeo/dave/JSNewlines
Approved by esben-semmle
|
2018-09-20 14:49:54 +01:00 |
|
Dave Bartolomeo
|
b12c739915
|
JavaScript: Normalize line endings of .js and .html files
Added .gitattributes files for the two directories where we intentionally have line endings other than LF
|
2018-09-19 21:33:27 -07:00 |
|
semmle-qlci
|
4aca8f4fd3
|
Merge pull request #201 from asger-semmle/string-concatenation-squashed
Approved by esben-semmle
|
2018-09-19 21:59:17 +01:00 |
|
Asger F
|
1d793c0a7b
|
JavaScript: fix expected output
|
2018-09-19 14:33:23 +01:00 |
|
Esben Sparre Andreasen
|
2cedc81774
|
JS: polish js/enabling-electron-renderer-node-integration meta info
|
2018-09-19 13:45:42 +02:00 |
|
semmle-qlci
|
89f2dbf8db
|
Merge pull request #195 from esben-semmle/js/reflected-xss-through-filenames
Approved by asger-semmle
|
2018-09-19 12:42:22 +01:00 |
|
Asger F
|
9384b85bcc
|
JavaScript: ensure prefix sanitizers work for array.join()
|
2018-09-17 14:31:26 +01:00 |
|
Asger F
|
e2cdf5d7ed
|
JavaScript: add string concatenation library
|
2018-09-17 12:47:37 +01:00 |
|
Asger F
|
b20fd3c084
|
JS: recognize res.sendfile as alias for res.sendFile in Express
|
2018-09-17 11:31:10 +01:00 |
|
Esben Sparre Andreasen
|
bb48421d77
|
JS: address doc review comments
|
2018-09-17 11:08:35 +02:00 |
|
semmle-qlci
|
782e91bb97
|
Merge pull request #167 from bnxi/NodeIntegration
Approved by esben-semmle
|
2018-09-15 21:35:56 +01:00 |
|
Behrang Fouladi Azarnaminy
|
7071c75567
|
revert "Chaning EOL in two files"
This reverts commit ecd08d4560.
|
2018-09-14 09:03:48 -07:00 |
|
Esben Sparre Andreasen
|
444a09a17c
|
JS: add models of five file system libraries
|
2018-09-14 15:30:44 +02:00 |
|
Esben Sparre Andreasen
|
33f98dd1a7
|
JS: add query: js/stored-xss
|
2018-09-14 15:30:44 +02:00 |
|
Asger F
|
a3562aa4a7
|
Merge pull request #193 from esben-semmle/js/reduce-precision-of-remote-property-injection
JS: lower @precision of js/remote-property-injection
|
2018-09-14 11:14:13 +01:00 |
|
Esben Sparre Andreasen
|
e2fac8a03c
|
JS: introduce concept: FileNameSource
|
2018-09-14 11:09:29 +02:00 |
|
Esben Sparre Andreasen
|
6d3c1a1d22
|
JS: introduce fsModuleMember
|
2018-09-14 11:09:29 +02:00 |
|
Esben Sparre Andreasen
|
8de269e1fb
|
JS: add support for fs-extra in NodeJSFileSystemAccess
|
2018-09-14 11:09:29 +02:00 |
|
semmle-qlci
|
abbadf24f0
|
Merge pull request #192 from esben-semmle/js/additional-array-taint-steps
Approved by asger-semmle
|
2018-09-14 10:02:36 +01:00 |
|
Esben Sparre Andreasen
|
81aeda69e1
|
JS: lower @precision of js/remote-property-injection
|
2018-09-14 07:37:47 +02:00 |
|
semmle-qlci
|
961ecfb43f
|
Merge pull request #187 from esben-semmle/js/additional-whitelisting-form-unbound-event-handlers
Approved by asger-semmle
|
2018-09-14 06:35:39 +01:00 |
|
Esben Sparre Andreasen
|
4c13e6b46b
|
JS: add additional array-specific taint steps
|
2018-09-13 21:36:53 +02:00 |
|
Jonas Jensen
|
9886e4a056
|
Merge remote-tracking branch 'upstream/master' into merge-master-next-20180913
|
2018-09-13 20:28:17 +02:00 |
|
Esben Sparre Andreasen
|
763da72ce5
|
JS: modernize old array taint steps
|
2018-09-13 15:52:25 +02:00 |
|
Esben Sparre Andreasen
|
ea37665ec6
|
JS: move array-specific taint steps to separate class
|
2018-09-13 15:52:25 +02:00 |
|
semmle-qlci
|
3d022298dc
|
Merge pull request #186 from Semmle/rc/1.18
Approved by esben-semmle
|
2018-09-13 12:34:54 +01:00 |
|
Esben Sparre Andreasen
|
fcc33ce93d
|
JS: whitelist auto-bind methods in js/unbound-event-handler-receiver
|
2018-09-13 08:41:41 +02:00 |
|
Esben Sparre Andreasen
|
eb10f603ab
|
JS: whitelist decorator-bound methods in js/unbound-event-handler-receiver
|
2018-09-13 08:41:41 +02:00 |
|
Esben Sparre Andreasen
|
1220b50737
|
JS: whitelist _.bindAll-methods in js/unbound-event-handler-receiver
|
2018-09-13 08:41:41 +02:00 |
|
Behrang Fouladi Azarnaminy
|
ecd08d4560
|
Chaning EOL in two files
|
2018-09-12 12:05:57 -07:00 |
|
Aditya Sharad
|
767045b55d
|
Merge rc/1.18 into next.
|
2018-09-12 14:59:54 +01:00 |
|
semmle-qlci
|
9e0ba51280
|
Merge pull request #179 from esben-semmle/js/classify-multi-license-fix
Approved by asger-semmle
|
2018-09-11 21:30:10 +01:00 |
|
Behrang Fouladi Azarnaminy
|
fc087ffb71
|
Replaceing query and test files with suggested ones
|
2018-09-11 12:32:56 -07:00 |
|
Behrang Fouladi Azarnaminy
|
befca6cafa
|
Remove webview example and its reference in qlhelp file
|
2018-09-11 12:31:00 -07:00 |
|
semmle-qlci
|
b17aeb689c
|
Merge pull request #118 from esben-semmle/js/request-forgery
Approved by asger-semmle
|
2018-09-11 16:28:59 +01:00 |
|
Esben Sparre Andreasen
|
43c65e02ec
|
JS: classify bundle files based on multiple license comments
|
2018-09-11 15:40:24 +02:00 |
|