Asger Feldthaus
|
e30fa89405
|
JS: Update more test expectations
|
2021-03-18 10:04:39 +00:00 |
|
Asger Feldthaus
|
9cfbb90591
|
JS: Add test case for insufficient replace-sanitizer
|
2021-03-17 15:20:40 +00:00 |
|
Asger Feldthaus
|
97b8e35426
|
JS: Update test expectations
|
2021-03-16 15:09:01 +00:00 |
|
Asger Feldthaus
|
710cca5395
|
JS: Update expectations with new sources
|
2021-03-16 13:28:12 +00:00 |
|
Asger Feldthaus
|
2e57a7d3e9
|
JS: Add ClientSideRemoteFlowSource
|
2021-03-16 13:28:09 +00:00 |
|
CodeQL CI
|
40acb95105
|
Merge pull request #5397 from erik-krogh/globalSanitizer
Approved by asgerf
|
2021-03-16 05:37:32 -07:00 |
|
CodeQL CI
|
a9c292e265
|
Merge pull request #5391 from erik-krogh/additionalXss
Approved by asgerf
|
2021-03-15 04:50:54 -07:00 |
|
Erik Krogh Kristensen
|
1dcfc3840d
|
add test
|
2021-03-12 16:25:33 +01:00 |
|
Asger Feldthaus
|
a2d1e88bb3
|
JS: Update more test expectations
|
2021-03-12 12:57:21 +00:00 |
|
Erik Krogh Kristensen
|
d7b0f628a1
|
add test
|
2021-03-12 00:03:20 +01:00 |
|
Asger Feldthaus
|
a03cb11257
|
JS: Include $().prop() source in XssThroughDom
|
2021-03-11 16:27:31 +00:00 |
|
Asger Feldthaus
|
18cfe72e99
|
JS: Add model of d3
|
2021-03-11 10:05:05 +00:00 |
|
CodeQL CI
|
d7b9251b0d
|
Merge pull request #5262 from max-schaefer/event-handler-receiver-is-dom-element
Approved by asgerf
|
2021-03-05 02:04:59 -08:00 |
|
CodeQL CI
|
15049ca853
|
Merge pull request #5183 from erik-krogh/next
Approved by asgerf
|
2021-03-04 04:57:43 -08:00 |
|
Asger Feldthaus
|
7afa755597
|
JS: Add ajv error as source of ExceptionXss
|
2021-03-02 12:39:04 +00:00 |
|
Erik Krogh Kristensen
|
a79c30a818
|
support NextJS API endpoints
|
2021-03-02 12:25:49 +01:00 |
|
Erik Krogh Kristensen
|
1fdbbb682d
|
support Next.js page request/response objects
|
2021-03-02 12:25:49 +01:00 |
|
Max Schaefer
|
2e252ba3e4
|
JavaScript: Learn that receivers of DOM event handlers are themselves DOM nodes.
|
2021-02-25 09:06:58 +00:00 |
|
Max Schaefer
|
ae2a5da63f
|
JavaScript: Add new tests for recognising receiver of event handler as DOM element.
|
2021-02-25 09:04:46 +00:00 |
|
CodeQL CI
|
8716cbd7ee
|
Merge pull request #5140 from erik-krogh/mark
Approved by asgerf
|
2021-02-17 11:50:11 -08:00 |
|
Erik Krogh Kristensen
|
69d8aa143c
|
add taint step for the snarkdown libary
|
2021-02-11 16:16:46 +01:00 |
|
Erik Krogh Kristensen
|
7cff1f441b
|
add model for the unified and remark libraries
|
2021-02-10 18:13:01 +01:00 |
|
Erik Krogh Kristensen
|
0d497e8b9a
|
add model for the showdown library
|
2021-02-10 17:22:42 +01:00 |
|
Erik Krogh Kristensen
|
f76018c039
|
add taint step for the markdown-table library
|
2021-02-10 15:11:41 +01:00 |
|
Erik Krogh Kristensen
|
b4704f7016
|
add taint-step for the marked library
|
2021-02-10 14:51:08 +01:00 |
|
Erik Krogh Kristensen
|
101d4358a9
|
detect DOM nodes from event callbacks
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
be9636491b
|
add source for react-hook-form in xss-through-dom
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
65d93c9061
|
detect for DOM elements from DOM events in React
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
458dda9d25
|
add xss-through-dom source from react-final-form
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
ff3950ce98
|
add model for formik
|
2021-02-10 14:17:49 +01:00 |
|
Esben Sparre Andreasen
|
9678534f25
|
JS: add tests for some syntactic XSS vector obfuscations
|
2021-02-01 10:20:23 +01:00 |
|
Asger Feldthaus
|
3db6069372
|
JS: Add test for new sink
|
2021-01-18 10:55:34 +00:00 |
|
Asger Feldthaus
|
2752b4ba64
|
JS: Shift line numbers in test
|
2021-01-18 10:54:39 +00:00 |
|
Erik Krogh Kristensen
|
3bad75dae5
|
better support for forms in js/xss-through-dom
|
2020-12-03 16:57:41 +01:00 |
|
Erik Krogh Kristensen
|
49be7e959f
|
Merge branch 'main' into jwt
|
2020-11-12 21:36:09 +01:00 |
|
Erik Krogh Kristensen
|
e75259d3a6
|
model the verify function in jsonwebtoken
|
2020-11-10 10:41:39 +01:00 |
|
Erik Krogh Kristensen
|
6732493377
|
add model for jwt-decode
|
2020-11-10 10:41:36 +01:00 |
|
Asger Feldthaus
|
24714c41be
|
JS: Update test output after rebase
|
2020-11-06 09:14:03 +00:00 |
|
Asger Feldthaus
|
7bf21d80b2
|
JS: Shift line numbers in test file
|
2020-11-06 09:13:52 +00:00 |
|
Asger Feldthaus
|
9418c6c8fe
|
JS: Add support for dateformat package
|
2020-11-06 09:13:52 +00:00 |
|
Asger Feldthaus
|
790526b529
|
JS: Some fixes and address review comments
|
2020-11-06 09:06:20 +00:00 |
|
Asger Feldthaus
|
8a3fba05e9
|
JS: Add steps through date-formatting functions
|
2020-11-06 09:06:18 +00:00 |
|
Erik Krogh Kristensen
|
e124ba66b4
|
moving jsdom sink to js/xss
|
2020-11-05 16:10:33 +01:00 |
|
CodeQL CI
|
4a59e69722
|
Merge pull request #4564 from asgerf/js/react-hooks
Approved by esbena
|
2020-10-30 21:00:31 +00:00 |
|
Asger Feldthaus
|
469767d279
|
JS: Fix test output
|
2020-10-28 17:00:05 +00:00 |
|
Asger Feldthaus
|
f99db23e7b
|
JS: Add test and fix for contextType
|
2020-10-28 16:23:36 +00:00 |
|
Asger Feldthaus
|
3d86e855f3
|
JS: Add model of classnames and clsx
|
2020-10-28 13:56:35 +00:00 |
|
Asger Feldthaus
|
d116b424f4
|
JS: Add model of react hooks and react-router
|
2020-10-28 11:57:11 +00:00 |
|
Asger Feldthaus
|
8779b7c1ce
|
JS: Update expected output after rebase
|
2020-10-20 11:10:30 +01:00 |
|
Asger Feldthaus
|
28a73c1e18
|
JS: Add test case
|
2020-10-20 10:53:15 +01:00 |
|