Erik Krogh Kristensen
|
4864e77430
|
Merge branch 'master' of git.semmle.com:Semmle/ql into UrlSearch
|
2020-03-27 15:59:29 +01:00 |
|
Erik Krogh Kristensen
|
0ebbd80745
|
autoformat
|
2020-03-27 14:54:34 +01:00 |
|
semmle-qlci
|
1975a83cdd
|
Merge pull request #3116 from max-schaefer/js/postgres-type-tracking
Approved by asgerf
|
2020-03-27 09:23:52 +00:00 |
|
Erik Krogh Kristensen
|
58af63d8cc
|
add test case for XSS on url suffix
|
2020-03-27 10:02:24 +01:00 |
|
Erik Krogh Kristensen
|
e2d2c2341e
|
autoformat and update expected output
|
2020-03-26 15:38:00 +01:00 |
|
Asger Feldthaus
|
816968d102
|
JS: Rename test files to avoid clash
|
2020-03-26 11:59:57 +00:00 |
|
Erik Krogh Kristensen
|
1cefa12315
|
update expected output
|
2020-03-25 23:54:57 +01:00 |
|
Erik Krogh Kristensen
|
00181e059b
|
add tests for type-tracking promises
|
2020-03-25 23:54:56 +01:00 |
|
semmle-qlci
|
e7fd97e72b
|
Merge pull request #3119 from erik-krogh/SockJS
Approved by esbena
|
2020-03-25 21:36:29 +00:00 |
|
Asger Feldthaus
|
54021a1c30
|
JS: Update old entry point and add a test
|
2020-03-25 13:24:18 +00:00 |
|
semmle-qlci
|
cf5b1f0cd5
|
Merge pull request #3019 from erik-krogh/ArrayStep
Approved by asgerf
|
2020-03-25 12:08:44 +00:00 |
|
Max Schaefer
|
efbcec09ef
|
JavaScript: Add type tracking to Postgres model.
|
2020-03-24 17:30:07 +00:00 |
|
Erik Krogh Kristensen
|
36981f385a
|
Merge branch 'master' of git.semmle.com:Semmle/ql into MorePathSinks
|
2020-03-24 11:20:33 +01:00 |
|
semmle-qlci
|
4c9a6b73ee
|
Merge pull request #3107 from erik-krogh/FArgs
Approved by esbena
|
2020-03-24 08:32:56 +00:00 |
|
Erik Krogh Kristensen
|
fa710c5864
|
Merge remote-tracking branch 'upstream/master' into UrlSearch
|
2020-03-24 00:23:15 +01:00 |
|
Erik Krogh Kristensen
|
5b4f091257
|
add test for remote flow sources in WebSockets
|
2020-03-23 23:58:20 +01:00 |
|
Erik Krogh Kristensen
|
6a1491d83d
|
add SockJS to the existing WebSocket model
|
2020-03-23 23:56:11 +01:00 |
|
Erik Krogh Kristensen
|
9a18dc32c1
|
autoformat WebSocket tests
|
2020-03-23 23:49:26 +01:00 |
|
Erik Krogh Kristensen
|
7b7eddff1e
|
remove previous SockJS implementation, and move example to WebSocket test
|
2020-03-23 23:45:05 +01:00 |
|
Erik Krogh Kristensen
|
f1e0d37273
|
Update javascript/ql/test/library-tests/frameworks/Concepts/file-access.js
Co-Authored-By: Asger F <asgerf@github.com>
|
2020-03-23 14:02:22 +01:00 |
|
Asger F
|
6c2842bd49
|
Merge pull request #2919 from asger-semmle/js/property-barriers
JS: Make sanitizers no longer block taint inside an object
|
2020-03-23 11:43:18 +00:00 |
|
Erik Krogh Kristensen
|
2c43d1d731
|
fix FP in superfluous-trailing-arguments related to Function.arguments
|
2020-03-23 10:40:35 +01:00 |
|
Erik Krogh Kristensen
|
90a324148d
|
add extra sinks to js/tainted-path
|
2020-03-20 09:07:39 +01:00 |
|
semmle-qlci
|
deb20fc37f
|
Merge pull request #3076 from esbena/js/even-more-mongoose-improvements
Approved by erik-krogh
|
2020-03-19 12:03:53 +00:00 |
|
Asger Feldthaus
|
4f42675b35
|
JS: Autformat
|
2020-03-19 09:36:27 +00:00 |
|
Asger Feldthaus
|
7393844699
|
JS: Update some queries that used data as source
|
2020-03-18 11:55:13 +00:00 |
|
Asger Feldthaus
|
506ddaf3f4
|
JS: Add explanation for test failure
|
2020-03-18 11:55:13 +00:00 |
|
Asger Feldthaus
|
028022158d
|
JS: Add variant of test that passes
|
2020-03-18 11:55:13 +00:00 |
|
Asger Feldthaus
|
a7e337ab28
|
JS: Add some lines in test case
|
2020-03-18 11:55:13 +00:00 |
|
Asger Feldthaus
|
3e68072e38
|
JS: Accept test case change
|
2020-03-18 11:55:13 +00:00 |
|
Asger Feldthaus
|
a9901a44e8
|
JS: Update TaintBarriers/isBarrier test
|
2020-03-18 11:55:13 +00:00 |
|
Asger Feldthaus
|
0edb765958
|
JS: Split test case function in two
|
2020-03-18 11:55:13 +00:00 |
|
Asger Feldthaus
|
a195429471
|
JS: Add test with non-guard sanitizer
|
2020-03-18 11:55:12 +00:00 |
|
Asger Feldthaus
|
83606e7b60
|
JS: Dont use data label in taint-tracking configs
|
2020-03-18 11:55:12 +00:00 |
|
Asger Feldthaus
|
8da0584b12
|
JS: Add test
|
2020-03-18 11:55:12 +00:00 |
|
semmle-qlci
|
fa08258c14
|
Merge pull request #3036 from erik-krogh/CustomTrack
Approved by asgerf
|
2020-03-17 13:44:51 +00:00 |
|
Esben Sparre Andreasen
|
833d1b1ab0
|
JS: fixup mongoose test
|
2020-03-16 22:11:22 +01:00 |
|
Esben Sparre Andreasen
|
9d9926fdbf
|
JS: model Mongoose Document for additional js/nosql-injection sinks
|
2020-03-16 22:11:22 +01:00 |
|
Esben Sparre Andreasen
|
55ab519fbe
|
JS: add Mongoose Document tests
|
2020-03-16 22:11:22 +01:00 |
|
Esben Sparre Andreasen
|
dc27a8f52c
|
JS: model mongoose Model on createConnection.<model/models>
|
2020-03-16 22:11:22 +01:00 |
|
Esben Sparre Andreasen
|
730396df12
|
JS: add Mongoose createConnection tests
|
2020-03-16 22:11:22 +01:00 |
|
Erik Krogh Kristensen
|
f2548aa3b1
|
add more models for file related sinks and sources
|
2020-03-16 11:07:23 +01:00 |
|
semmle-qlci
|
1d4dd2b2f7
|
Merge pull request #3057 from esbena/js/infer-this-as-exports
Approved by asgerf
|
2020-03-15 12:55:12 +00:00 |
|
semmle-qlci
|
7e093a8e5c
|
Merge pull request #3041 from erik-krogh/JQueryAjax
Approved by esbena
|
2020-03-14 22:31:59 +00:00 |
|
semmle-qlci
|
ff03478ae8
|
Merge pull request #3049 from asger-semmle/js/fix-cyclic-join
Approved by erik-krogh
|
2020-03-14 16:19:25 +00:00 |
|
Erik Krogh Kristensen
|
4f39c28741
|
Merge branch 'master' of git.semmle.com:Semmle/ql into CustomTrack
|
2020-03-14 14:37:52 +01:00 |
|
Esben Sparre Andreasen
|
4d6aa20990
|
Merge pull request #3004 from esbena/js/additional-mongodb-and-mongoose-injection-sinks
JS: Mongoose and MongoDB improvements
|
2020-03-14 12:31:43 +01:00 |
|
Esben Sparre Andreasen
|
2fac7434df
|
JS: infer this to be module.exports in node modules
|
2020-03-13 14:10:35 +01:00 |
|
Esben Sparre Andreasen
|
ae8d38236b
|
JS: add some tests for this
|
2020-03-13 14:09:23 +01:00 |
|
Erik Krogh Kristensen
|
91bc124f78
|
autoformat
|
2020-03-12 10:45:25 +01:00 |
|