Asger F
|
cc8fe10801
|
JS: Update locations in expected files
|
2025-08-29 12:03:11 +02:00 |
|
Asger F
|
2a194a53af
|
raw test output
|
2025-02-28 13:29:39 +01:00 |
|
Asger F
|
64d39da5f8
|
JS: Accept Sources/Sink tags
|
2025-02-28 13:29:30 +01:00 |
|
Asger F
|
f5911c9e5a
|
JS: Accept raw test output
|
2025-02-28 13:27:38 +01:00 |
|
Asger F
|
d0ce53ed82
|
JS: Enable post-processing for all .qlref files
|
2025-02-28 13:27:33 +01:00 |
|
Asger F
|
9be041e27d
|
JS: Update OK-style comments to $-style
|
2025-02-28 13:27:28 +01:00 |
|
Asger F
|
7e5c24a8ec
|
JS: Remove uses of old inline expectation test library
|
2025-02-28 13:27:26 +01:00 |
|
Asger F
|
2c65946684
|
JS: Add setOtherInput example
|
2025-01-17 10:29:03 +01:00 |
|
Asger F
|
e983e26f68
|
JS: Add example with safe field
|
2025-01-17 10:28:07 +01:00 |
|
Asger F
|
859783c08b
|
JS: Support [(ngModel)]
|
2025-01-17 10:26:57 +01:00 |
|
Asger F
|
d55c68c1f1
|
JS: Add test case with [(ngModel)]
|
2025-01-17 10:24:16 +01:00 |
|
Asger F
|
97f5559e64
|
JS: Recognise form input from NgForm
|
2025-01-17 10:22:20 +01:00 |
|
Asger F
|
1ec3a62242
|
JS: Add test with NgForm.value
|
2025-01-17 10:20:59 +01:00 |
|
Asger F
|
d4daa21318
|
JS: Add DOM event sources in Angular2 model
|
2025-01-17 10:20:22 +01:00 |
|
Asger F
|
b8ba50a9ac
|
JS: Add Angular test case in XssThroughDom
|
2025-01-17 10:12:42 +01:00 |
|
Asger F
|
3acd4814de
|
Merge branch 'main' into js/shared-dataflow-merge-main
|
2024-12-19 10:14:38 +01:00 |
|
Michael Nebel
|
c3fe3e468c
|
Javascript: Update all test util paths to point to the new location.
|
2024-12-12 13:54:25 +01:00 |
|
Asger F
|
08d25c122d
|
JS: Deprecate more uses of ConsistencyConfiguration
|
2024-12-03 14:30:27 +01:00 |
|
Asger F
|
0ce1fe767d
|
JS: Deprecate ConsistencyChecking to avoid deprecation warnings
|
2024-12-03 14:30:23 +01:00 |
|
Asger F
|
53efb5837b
|
JS: Update some tests with provenance columns
Only includes the changes that purely contain the new provenance columns
|
2024-06-26 13:51:44 +02:00 |
|
Asger F
|
cf5450dbd5
|
JS: Port XssThroughDom
|
2023-10-13 13:15:03 +02:00 |
|
erik-krogh
|
2bba9057a0
|
better callgraph support for global variables
|
2023-03-22 13:49:33 +01:00 |
|
erik-krogh
|
a6c9af4182
|
add the html argument to the jQuery functions as an XSS sink
|
2023-03-03 11:09:53 +01:00 |
|
erik-krogh
|
94870b838f
|
add failing test
|
2023-03-03 11:08:33 +01:00 |
|
erik-krogh
|
b85bfc8ba6
|
add HtmlSanitizer as a sanitizer for DOMBasedXss
|
2023-02-13 11:57:29 +01:00 |
|
erik-krogh
|
c258e44772
|
add failing test for spurious edge through sanitizer
|
2023-02-13 11:49:57 +01:00 |
|
erik-krogh
|
ba2734909f
|
JS: don't use deprecated files in tests
|
2022-11-17 22:12:50 +01:00 |
|
Erik Krogh Kristensen
|
e80ee46fe4
|
add model for the cash library
|
2022-05-09 21:01:07 +02:00 |
|
bananabr
|
2e2d4c6e1f
|
updated tests to consider document.getSelection()
|
2022-05-03 21:03:35 -05:00 |
|
bananabr
|
57ae07017f
|
adds the Selection API as a new DOM text source
|
2022-04-30 18:27:31 -05:00 |
|
Erik Krogh Kristensen
|
0435cee57f
|
add a taint-step through URL.createObjectURL for js/xss-through-dom
|
2022-04-06 12:18:47 +02:00 |
|
Erik Krogh Kristensen
|
b11d48e749
|
add files in the DOM as a source for js/xss-through-dom
|
2022-04-06 12:09:07 +02:00 |
|
Erik Krogh Kristensen
|
c8385a1e80
|
js/xss-through-dom: filter away reads of .src that end in a URL sink
|
2022-03-21 16:48:59 +01:00 |
|
Erik Krogh Kristensen
|
81742528a2
|
add test
|
2021-08-27 10:04:39 +02:00 |
|
Erik Krogh Kristensen
|
cc2a267b07
|
recognize array elements from JQuery objects as DOM values
|
2021-08-16 22:35:57 +02:00 |
|
Erik Krogh Kristensen
|
e60628d463
|
add global replacements using inverted char classes as a sanitizer for DOM based XSS
|
2021-04-28 11:29:30 +02:00 |
|
Erik Krogh Kristensen
|
9178f4b1c5
|
add support for the anser library
|
2021-04-27 15:57:17 +02:00 |
|
Asger Feldthaus
|
a03cb11257
|
JS: Include $().prop() source in XssThroughDom
|
2021-03-11 16:27:31 +00:00 |
|
Erik Krogh Kristensen
|
101d4358a9
|
detect DOM nodes from event callbacks
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
be9636491b
|
add source for react-hook-form in xss-through-dom
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
65d93c9061
|
detect for DOM elements from DOM events in React
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
458dda9d25
|
add xss-through-dom source from react-final-form
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
ff3950ce98
|
add model for formik
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
3bad75dae5
|
better support for forms in js/xss-through-dom
|
2020-12-03 16:57:41 +01:00 |
|
Asger Feldthaus
|
4137d3f971
|
JS: Split CWE-079 tests into their own folders
|
2020-10-16 17:32:36 +01:00 |
|