Owen Mansel-Chan
|
349df54905
|
Ignore lambda data flow for now
|
2021-05-06 13:57:49 +01:00 |
|
Owen Mansel-Chan
|
daf73553f6
|
Sync shared dataflow libraries
|
2021-05-05 16:58:30 +01:00 |
|
Slavomir
|
ea2909a362
|
HTTP::HeaderWrite: Don't override string getHeaderValue() with none()
|
2021-04-30 15:39:09 +01:00 |
|
Slavomir
|
110a3983c1
|
Regenerate codeql: Refactor HTTP::HeaderWrite
|
2021-04-30 15:39:09 +01:00 |
|
Slavomir
|
5578afa189
|
Regenerate using latest codemill generator.
|
2021-04-30 15:39:09 +01:00 |
|
Chris Smowton
|
0beaa7fdc9
|
Model content-type setters as HeaderWrites.
|
2021-04-30 15:39:09 +01:00 |
|
Chris Smowton
|
9ea8b34e47
|
HTTP ResponseBody: support HeaderWrites with hard-coded header values.
|
2021-04-30 15:39:09 +01:00 |
|
Chris Smowton
|
3fd2c7d4bb
|
Note response writers for existing HeaderWrite and HttpRedirect instances
|
2021-04-30 15:39:09 +01:00 |
|
Slavomir
|
36396df271
|
HttpResponseBody: Move .getAPredecessor*() to the test query.
|
2021-04-30 15:39:09 +01:00 |
|
Slavomir
|
989bfa2b1d
|
Improve naming and comments.
|
2021-04-30 15:39:09 +01:00 |
|
Slavomir
|
78b403f42e
|
Stub alternative HTTP::ResponseBody model implementation
|
2021-04-30 15:39:09 +01:00 |
|
Slavomir
|
ff848a502a
|
ResponseBody: Use .getAPredecessor*().getStringValue() instead of just .getStringValue()
|
2021-04-30 15:39:09 +01:00 |
|
Sauyon Lee
|
bfe6e7510d
|
Evaluate symlinks for the dummy file
|
2021-04-27 08:32:21 -07:00 |
|
Sauyon Lee
|
d09cb7f228
|
Remove badpkg.go to make tests location-independent
|
2021-04-27 01:18:22 -07:00 |
|
Sauyon Lee
|
27b72b53e5
|
Add diagnostic queries
|
2021-04-27 01:18:21 -07:00 |
|
Sauyon Lee
|
9f85846980
|
Add lines of code summary query
|
2021-04-27 01:18:20 -07:00 |
|
Sauyon Lee
|
ed978e439f
|
Add GoFile and move HtmlFile to Files.qll
|
2021-04-27 01:18:19 -07:00 |
|
Sauyon Lee
|
2a80a60468
|
Add GeneratedFile concept
|
2021-04-27 01:18:19 -07:00 |
|
Sauyon Lee
|
3393588353
|
Move concepts imports to Concepts.qll
|
2021-04-27 01:18:18 -07:00 |
|
Sauyon Lee
|
b808c187cf
|
Add test with curly braces in filename
|
2021-04-21 21:14:41 -07:00 |
|
Chris Smowton
|
06c958e61f
|
Extractor: tolerate curly braces in struct field tags, directory names
These previously produced malformed TRAP. I have checked the other uses of GlobalID and don't see any others that should require escaping.
|
2021-04-21 21:14:39 -07:00 |
|
Chris Smowton
|
e50ad90856
|
Elaborate comment and change-note a little
|
2021-04-21 12:36:43 +01:00 |
|
Chris Smowton
|
a152eec9f2
|
Add test for ExtractTupleElementInstruction.getResultType()
|
2021-04-21 12:33:51 +01:00 |
|
Chris Smowton
|
4fb714f445
|
Simplify implementation of ExtractTupleElementInstruction.getResultType
|
2021-04-21 12:33:00 +01:00 |
|
Sauyon Lee
|
50bb6187b8
|
Revert ReflectedXss.go to example
|
2021-04-20 23:27:03 -07:00 |
|
Sauyon Lee
|
d1daca541e
|
Add types for more tuple extractions
Specifically, extractions where the RHS is a map element read or a channel receive
will now have types.
|
2021-04-20 14:23:31 -07:00 |
|
Sauyon Lee
|
ba2da6d9a9
|
Add test exercising channel data flow
|
2021-04-20 14:23:31 -07:00 |
|
Chris Smowton
|
0cef5fb5d0
|
Add test case for map extraction
|
2021-04-20 14:23:29 -07:00 |
|
Chris Smowton
|
b2e92fa084
|
Remove needless model of Part.Read
Read already gets a model as an implementation of the `Reader` interface.
|
2021-04-20 11:05:36 +01:00 |
|
Chris Smowton
|
948e064440
|
Fix mis-modelling Part.Read
|
2021-04-20 11:03:17 +01:00 |
|
Chris Smowton
|
027a540c67
|
Update test expectations now that tuple-extracts not method calls are sources
|
2021-04-19 17:05:50 +01:00 |
|
Chris Smowton
|
a367950014
|
Restore OpenRedirect's exclusion of POST-only request components
|
2021-04-19 17:05:23 +01:00 |
|
Chris Smowton
|
7d258ae722
|
Improve net/http taint-tracking fidelity
* Don't taint error returns from http.Request methods
* Track taint across mime/multipart.Part methods
|
2021-04-19 16:05:23 +01:00 |
|
Sauyon Lee
|
80fe7384cd
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
|
2021-04-09 14:30:23 +01:00 |
|
Sauyon Lee
|
4462948cfc
|
Add a new diagnostics file class and use it for errors
|
2021-04-09 14:30:23 +01:00 |
|
Slavomir
|
8e839f376e
|
Put all tests file in to the CleverGo folder instead of having dedicated folders for each test.
|
2021-04-09 08:38:37 +01:00 |
|
Slavomir
|
4ae5bdbbec
|
Improve naming of files and elements.
|
2021-04-09 08:38:37 +01:00 |
|
Slavomir
|
7ea0434514
|
Move clevergo framework to experimental
|
2021-04-09 08:38:37 +01:00 |
|
Slavomir
|
3915305361
|
Refactor and improve HTTP:ResponseBody models and tests
|
2021-04-09 08:38:37 +01:00 |
|
Slavomir
|
8c18aa6cbd
|
Simplify HTTP::HeaderWrite
|
2021-04-09 08:38:37 +01:00 |
|
Slavomir
|
7edf739602
|
Model HTTP::HeaderWrite; regenerate stubs
|
2021-04-09 08:38:37 +01:00 |
|
Slavomir
|
93ff2459d1
|
Use docs instead of comments for classes.
|
2021-04-09 08:38:36 +01:00 |
|
Slavomir
|
0fe7050e7e
|
Add models for HTTP::ResponseBody
|
2021-04-09 08:38:36 +01:00 |
|
Slavomir
|
98b3cc2dc4
|
Fix autoformatting
|
2021-04-09 08:38:36 +01:00 |
|
Slavomir
|
c53d8d3e56
|
Add http redirect model
|
2021-04-09 08:38:36 +01:00 |
|
Slavomir
|
55c8d9b22c
|
Make naming more consistent
|
2021-04-09 08:38:36 +01:00 |
|
Slavomir
|
1de7196060
|
Regenerate dep stubs
|
2021-04-09 08:38:36 +01:00 |
|
Slavomir
|
0c1ae62ce9
|
Use //go:generate depstubber --vendor --auto
|
2021-04-09 08:38:36 +01:00 |
|
Slavomir
|
f95f35387f
|
Cleanup comments
|
2021-04-09 08:38:36 +01:00 |
|
Slavomir
|
bdc5f90c97
|
Cleanup comments
|
2021-04-09 08:38:36 +01:00 |
|