semmle-qlci
|
da3292606c
|
Merge pull request #3191 from erik-krogh/XssDom
Approved by esbena, mchammer01
|
2020-04-23 09:17:07 +01:00 |
|
Erik Krogh Kristensen
|
957e4073b0
|
use getABoundCallbackParameter in SocketIO
|
2020-04-22 21:56:34 +02:00 |
|
Erik Krogh Kristensen
|
40822e10b4
|
add SocketIO test case
|
2020-04-22 21:55:20 +02:00 |
|
Erik Krogh Kristensen
|
ac26741816
|
reuse existing SanitizerGuard from UnsafeJQueryPlugin
|
2020-04-22 14:16:15 +02:00 |
|
Erik Krogh Kristensen
|
0a29d132d0
|
reuse existing logic in DomBasedXss
|
2020-04-22 13:50:43 +02:00 |
|
Erik Krogh Kristensen
|
7bfea946fd
|
update links in xss-through-dom qhelp
|
2020-04-22 10:23:03 +02:00 |
|
Erik Krogh Kristensen
|
8811455d49
|
Merge remote-tracking branch 'upstream/master' into XssDom
|
2020-04-22 10:20:40 +02:00 |
|
Erik Krogh Kristensen
|
76503d3536
|
user controlled -> user-controlled
|
2020-04-22 10:08:01 +02:00 |
|
Erik Krogh Kristensen
|
947e9828da
|
Update javascript/ql/src/Security/CWE-079/XssThroughDom.qhelp
Co-Authored-By: mc <42146119+mchammer01@users.noreply.github.com>
|
2020-04-22 10:07:50 +02:00 |
|
semmle-qlci
|
2fb711e460
|
Merge pull request #3169 from erik-krogh/Maps
Approved by asgerf, esbena
|
2020-04-21 12:12:06 +01:00 |
|
Erik Krogh Kristensen
|
59b94b3d1b
|
revert back to having 2 separate cases in JQuery::MethodCall
|
2020-04-21 13:08:06 +02:00 |
|
semmle-qlci
|
53abf83229
|
Merge pull request #3304 from asger-semmle/js/typescript-unary-type-expr
Approved by erik-krogh
|
2020-04-21 10:38:59 +01:00 |
|
semmle-qlci
|
2ecef33c9d
|
Merge pull request #3299 from asger-semmle/js/flows-to-redundant-check
Approved by esbena
|
2020-04-21 10:00:34 +01:00 |
|
semmle-qlci
|
80c20cb66e
|
Merge pull request #3297 from asger-semmle/js/isambient-refactor
Approved by esbena
|
2020-04-21 09:36:14 +01:00 |
|
Asger Feldthaus
|
883846dfb6
|
JS: Fix extraction of negative number literal types
|
2020-04-20 16:17:15 +01:00 |
|
Asger Feldthaus
|
ca60e8264e
|
JS: Autoformat
|
2020-04-20 14:42:41 +01:00 |
|
Erik Krogh Kristensen
|
9fc29ee0f8
|
update qhelp
|
2020-04-20 13:29:00 +02:00 |
|
Erik Krogh Kristensen
|
73b0aa4004
|
add more attributes potentially vulnerable to xss-through-dom
|
2020-04-20 13:29:00 +02:00 |
|
Erik Krogh Kristensen
|
12f4ce8111
|
merge two cases of jQuery method calls
|
2020-04-20 13:28:55 +02:00 |
|
Erik Krogh Kristensen
|
8b254f7b49
|
Merge remote-tracking branch 'upstream/master' into Maps
|
2020-04-20 13:00:39 +02:00 |
|
Asger Feldthaus
|
bccc27f1e7
|
JS: Rephrase flowsTo to avoid redundant SourceNode::Range check
|
2020-04-20 10:57:52 +01:00 |
|
Erik Krogh Kristensen
|
2d3e42e6d6
|
update qhelp for xss-through-dom
Co-Authored-By: Asger F <asgerf@github.com>
|
2020-04-20 11:50:46 +02:00 |
|
Erik Krogh Kristensen
|
c713ba7bfe
|
fix typo
|
2020-04-20 10:51:42 +02:00 |
|
Asger Feldthaus
|
bb9fea5a27
|
JS: Refactor isAmbient computation
|
2020-04-19 22:45:19 +01:00 |
|
Erik Krogh Kristensen
|
2632699397
|
Merge branch 'master' of git.semmle.com:Semmle/ql into Mispelled
|
2020-04-18 17:58:57 +02:00 |
|
Erik Krogh Kristensen
|
4a93b91d59
|
make maybePromisified private
|
2020-04-17 11:47:03 +02:00 |
|
Erik Krogh Kristensen
|
4f32157a78
|
rename func to callback
Co-Authored-By: Esben Sparre Andreasen <esbena@github.com>
|
2020-04-17 11:36:48 +02:00 |
|
Erik Krogh Kristensen
|
427c32f211
|
report a local variable as the misspelling if there any many occourances of the global
|
2020-04-17 11:25:23 +02:00 |
|
Erik Krogh Kristensen
|
1b80f46f30
|
add QHelp for js/xss-through-dom query
|
2020-04-17 10:54:21 +02:00 |
|
Erik Krogh Kristensen
|
14b551f887
|
Xss through DOM
|
2020-04-17 10:54:14 +02:00 |
|
Erik Krogh Kristensen
|
55edfed1ee
|
support jQuery().get() returning a DOM node
|
2020-04-17 10:32:53 +02:00 |
|
Erik Krogh Kristensen
|
dd9aec056c
|
handle basic dynamic method dispatch for jQuery methods
|
2020-04-17 10:32:52 +02:00 |
|
Erik Krogh Kristensen
|
eca98b42d2
|
basic support for util.promisify for NodeJSFileSystemAccess
|
2020-04-17 09:54:37 +02:00 |
|
Erik Krogh Kristensen
|
ea0f6a367d
|
refactor into maybePromisified predicate
|
2020-04-17 09:50:08 +02:00 |
|
Erik Krogh Kristensen
|
69a16af152
|
Merge branch 'master' into Maps
|
2020-04-15 20:41:22 +02:00 |
|
Erik Krogh Kristensen
|
fd51142200
|
change succ in storeStep to be a SourceNode
|
2020-04-15 20:40:58 +02:00 |
|
Erik Krogh Kristensen
|
e8dc77d508
|
add support for util.promisify with child_process calls
|
2020-04-15 19:16:30 +02:00 |
|
semmle-qlci
|
bfd80b42a7
|
Merge pull request #3260 from asger-semmle/js/location-tweaks
Approved by erik-krogh
|
2020-04-15 10:47:35 +01:00 |
|
Asger F
|
34d40b5035
|
Merge pull request #3237 from asger-semmle/js/sparse-capture
JS: Add CapturedVariableNode to avoid N^2 edges
|
2020-04-15 10:42:48 +01:00 |
|
Chris Gavin
|
4e981d8e70
|
Merge rc/1.24 into master.
|
2020-04-14 21:30:29 +01:00 |
|
Asger Feldthaus
|
1107e7c6a6
|
JS: Rename other uses of getURL
|
2020-04-14 19:45:09 +01:00 |
|
Asger F
|
c178eecd43
|
Update javascript/ql/src/semmle/javascript/Variables.qll
Co-Authored-By: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-04-14 14:40:21 +01:00 |
|
Felicity Chapman
|
c570ebe5bd
|
Merge branch 'rc/1.24' into update-references
|
2020-04-14 14:10:26 +01:00 |
|
Asger Feldthaus
|
3515a2b412
|
JS: Update test output
|
2020-04-14 10:31:31 +01:00 |
|
Asger Feldthaus
|
88667206fc
|
JS: Remove default hasLocationInfo case
|
2020-04-14 10:03:10 +01:00 |
|
Asger Feldthaus
|
5da968e34c
|
JS: Specialize ASTNode.getFile
|
2020-04-14 10:03:10 +01:00 |
|
Asger Feldthaus
|
244a304e1d
|
JS: Implement getFile() directly instead of via locations
|
2020-04-14 10:03:10 +01:00 |
|
Asger Feldthaus
|
dc084628cc
|
JS: Avoid the special name getURL
|
2020-04-14 10:03:09 +01:00 |
|
Erik Krogh Kristensen
|
6827b84bdc
|
change docstring to inline comment, and refer directly to array class
|
2020-04-14 10:32:16 +02:00 |
|
Erik Krogh Kristensen
|
e47575ce5b
|
more precise getChild for matching "../"
|
2020-04-14 10:24:08 +02:00 |
|