Erik Krogh Kristensen
|
90596167b1
|
add taint-step for Array.reduce
|
2020-06-09 17:15:00 +02:00 |
|
Erik Krogh Kristensen
|
be71ddf7bb
|
introduce basic BuildArtifactLeak query
|
2020-06-09 15:27:55 +02:00 |
|
Erik Krogh Kristensen
|
896a9b05f6
|
refactor CleartextLogging to allow for reuse
|
2020-06-09 15:03:07 +02:00 |
|
Erik Krogh Kristensen
|
b510e470b1
|
support rest-patterns inside property patterns
|
2020-06-09 13:28:56 +02:00 |
|
Erik Krogh Kristensen
|
b04d7015ae
|
fix test
|
2020-06-09 11:23:46 +02:00 |
|
Asger Feldthaus
|
0345036420
|
JS: Fix 'match' call in StringOps::RegExpTest
|
2020-06-09 10:07:36 +01:00 |
|
Erik Krogh Kristensen
|
c2fbcea96f
|
base the chaining on yargs on the methods that are NOT chained
|
2020-06-09 10:22:25 +02:00 |
|
Esben Sparre Andreasen
|
2d2468463b
|
JS: initial version of IncompleteMultiCharacterSanitization.ql
|
2020-06-09 08:59:59 +02:00 |
|
Erik Krogh Kristensen
|
167239e745
|
add query to detect accidential leak of private files
|
2020-06-08 23:41:14 +02:00 |
|
ubuntu
|
ab65ec40c0
|
Add Codeql to detect missing 'Message.origin' validation when using postMessage API
|
2020-06-08 20:18:34 +02:00 |
|
Erik Krogh Kristensen
|
0f06f04e32
|
extend support for yargs for js/indirect-command-line-injection
|
2020-06-08 16:45:09 +02:00 |
|
Asger Feldthaus
|
53280a6b11
|
JS: Add test demonstrating new flow
|
2020-06-08 14:25:21 +01:00 |
|
Asger Feldthaus
|
2d9b9fa584
|
JS: Use PreCallGraphStep in select array steps
|
2020-06-08 13:45:28 +01:00 |
|
Asger Feldthaus
|
3d2bbbd3db
|
JS: Add PreCallGraphStep extension point
|
2020-06-08 13:45:28 +01:00 |
|
Asger Feldthaus
|
1f2ab605bd
|
JS: Add store/load steps to AdditionalTypeTrackingStep
|
2020-06-08 13:45:28 +01:00 |
|
Esben Sparre Andreasen
|
872ee13ba6
|
JS: formatting
|
2020-06-08 10:04:37 +02:00 |
|
Esben Sparre Andreasen
|
fa35a6a694
|
JS: formatting
|
2020-06-08 08:13:58 +02:00 |
|
semmle-qlci
|
ff6936caa7
|
Merge pull request #3625 from erik-krogh/CVE714
Approved by asgerf
|
2020-06-05 12:21:10 +01:00 |
|
semmle-qlci
|
69a1e11c06
|
Merge pull request #3609 from erik-krogh/CredFN
Approved by asgerf, esbena
|
2020-06-05 10:49:01 +01:00 |
|
Erik Krogh Kristensen
|
82cf53897f
|
TypeOfCheck -> TypeOfUndefinedSanitizer
Co-authored-by: Asger F <asgerf@github.com>
|
2020-06-05 11:35:39 +02:00 |
|
Erik Krogh Kristensen
|
f70453c544
|
autoformat
|
2020-06-05 10:10:57 +02:00 |
|
Erik Krogh Kristensen
|
05d7be8e23
|
autoformat
|
2020-06-05 09:59:45 +02:00 |
|
Erik Krogh Kristensen
|
96ca4cf7eb
|
add missing quote
|
2020-06-04 19:45:24 +00:00 |
|
Erik Krogh Kristensen
|
815671f5d0
|
add sanitizer guard for typeof undefined
|
2020-06-04 21:32:26 +02:00 |
|
Erik Krogh Kristensen
|
5ce2987cb2
|
adjust comments to reflect that tainted-path have no array-steps
|
2020-06-04 16:15:37 +02:00 |
|
Erik Krogh Kristensen
|
ed4e1bbbdf
|
don't have a MembershipTestBarrierGuard in Configuration.qll
|
2020-06-04 16:13:49 +02:00 |
|
Erik Krogh Kristensen
|
b7a3c4a3d6
|
autoformat
|
2020-06-04 16:07:28 +02:00 |
|
Esben Sparre Andreasen
|
f618d430e7
|
JS: simplify HTTP::ContainerCollection, and improve expressivity(!)
|
2020-06-04 14:34:52 +02:00 |
|
Esben Sparre Andreasen
|
44ebf84f4c
|
JS: more express tests
|
2020-06-04 14:33:03 +02:00 |
|
Max Schaefer
|
9549b01e3c
|
JavaScript: Turn on experimental language features for two tests.
All other tests already pass with experimental features turned on, so once this is merged we can do so by default.
|
2020-06-04 11:27:31 +01:00 |
|
Erik Krogh Kristensen
|
60320a9d78
|
update TaintedPath to use new consistency checking
|
2020-06-04 11:00:40 +02:00 |
|
Erik Krogh Kristensen
|
68ca8e23c0
|
introduce consistency-checking utility predicates
|
2020-06-04 11:00:01 +02:00 |
|
Erik Krogh Kristensen
|
c7c46ea3d6
|
update test comments to be consistent
|
2020-06-04 10:55:09 +02:00 |
|
Erik Krogh Kristensen
|
550c578c3c
|
use MemberShipTest in TaintedPath
|
2020-06-04 10:51:08 +02:00 |
|
Erik Krogh Kristensen
|
d513e6c5b5
|
update comments in TaintedPath tests
|
2020-06-04 10:40:14 +02:00 |
|
semmle-qlci
|
70131e6ac8
|
Merge pull request #3598 from asger-semmle/js/regexp-test
Approved by esbena
|
2020-06-04 09:05:21 +01:00 |
|
Erik Krogh Kristensen
|
a90c8769ee
|
update expected output
|
2020-06-03 15:24:04 +02:00 |
|
Erik Krogh Kristensen
|
7c26efbc12
|
case insensitive authorization header
|
2020-06-03 15:23:51 +02:00 |
|
Erik Krogh Kristensen
|
b508ad41c8
|
don't have a separate fetch module
|
2020-06-03 15:20:06 +02:00 |
|
Erik Krogh Kristensen
|
46cd0143d8
|
Update javascript/ql/src/semmle/javascript/frameworks/ClientRequests.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2020-06-03 15:18:10 +02:00 |
|
Esben Sparre Andreasen
|
8316121a44
|
JS: formatting
|
2020-06-03 15:02:36 +02:00 |
|
Erik Krogh Kristensen
|
28a1900612
|
treat all writes to Authorization as a CredentialsExpr
|
2020-06-03 13:55:49 +02:00 |
|
Erik Krogh Kristensen
|
6466ab19a0
|
Update javascript/ql/src/semmle/javascript/frameworks/ClientRequests.qll
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2020-06-03 13:51:04 +02:00 |
|
Erik Krogh Kristensen
|
f8caec76ab
|
move the Fetch module to ClientRequests
|
2020-06-03 13:37:34 +02:00 |
|
Erik Krogh Kristensen
|
aa463d8298
|
mention fetch instead of node-fetch
|
2020-06-03 13:33:43 +02:00 |
|
Erik Krogh Kristensen
|
1b53cd4bd9
|
update docstring of FetchAuthorization
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2020-06-03 13:31:16 +02:00 |
|
Erik Krogh Kristensen
|
a1940979ba
|
support credentials in a Buffer
|
2020-06-03 12:02:00 +02:00 |
|
Erik Krogh Kristensen
|
ba44ebe8a8
|
better support for browser based fetch API
|
2020-06-03 11:51:24 +02:00 |
|
Erik Krogh Kristensen
|
3622fb8716
|
support more variants of the Headers API
|
2020-06-03 11:50:10 +02:00 |
|
Esben Sparre Andreasen
|
afee864295
|
JS: make use of the colletions type tracking steps
|
2020-06-03 08:19:34 +02:00 |
|