Dave Bartolomeo
|
06783938d3
|
JavaScript: Rename sanity -> consistency
|
2020-05-11 13:46:12 -04:00 |
|
semmle-qlci
|
b2f1008a00
|
Merge pull request #3420 from max-schaefer/js/fix-missing-triple-backtick
Approved by asgerf
|
2020-05-06 13:52:18 +01:00 |
|
Max Schaefer
|
9335a6cb79
|
JavaScript: Fix missing triple backtick in qldoc comment.
|
2020-05-06 11:40:00 +01:00 |
|
Asger F
|
b2da4fe491
|
Update javascript/ql/src/semmle/javascript/internal/StmtContainers.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-05-06 07:59:04 +01:00 |
|
Asger Feldthaus
|
926e79d272
|
JS: Autoformat
|
2020-05-06 07:59:04 +01:00 |
|
Asger Feldthaus
|
f51e846439
|
JS: Fix ClosureModule implementation
|
2020-05-06 07:59:04 +01:00 |
|
Asger Feldthaus
|
0f870a4992
|
JS: Use TCapturedVariableNode as starting point of callInputStep
|
2020-05-06 07:59:04 +01:00 |
|
Asger Feldthaus
|
4d6da19173
|
JS: Improve performance of getExceptionTarget
|
2020-05-06 07:59:04 +01:00 |
|
Asger Feldthaus
|
639f04386c
|
JS: Avoid bad join ordering in ClosureModule
|
2020-05-06 07:59:04 +01:00 |
|
Asger Feldthaus
|
5f710bc881
|
JS: Move definition of getContainer() to a single rootdef
|
2020-05-06 07:59:04 +01:00 |
|
semmle-qlci
|
a805a63443
|
Merge pull request #3357 from erik-krogh/YetAnotherPerformancePatch
Approved by asgerf, esbena
|
2020-05-04 10:05:34 +01:00 |
|
semmle-qlci
|
a0800cecc4
|
Merge pull request #3386 from erik-krogh/lessJQueryChaining
Approved by asgerf
|
2020-05-04 09:16:17 +01:00 |
|
semmle-qlci
|
c66ec3c981
|
Merge pull request #3380 from asger-semmle/js/cache-amd
Approved by erik-krogh
|
2020-05-02 20:18:22 +01:00 |
|
Erik Krogh Kristensen
|
efbd74a4a4
|
remove more spurious jQuery objects by using externs
|
2020-05-01 18:54:32 +02:00 |
|
Erik Krogh Kristensen
|
2a1095abcc
|
autoformat, and apply naming suggestion
|
2020-05-01 18:35:34 +02:00 |
|
Erik Krogh Kristensen
|
87365357ba
|
remove spurious jQuery objects
|
2020-05-01 15:19:54 +02:00 |
|
Erik Krogh Kristensen
|
16823143dd
|
refactor getAPropertyUsedInLoadStore
|
2020-05-01 09:58:11 +02:00 |
|
Erik Krogh Kristensen
|
1a42c9fd80
|
make predicates private
Co-authored-by: Asger F <asgerf@github.com>
|
2020-05-01 09:42:09 +02:00 |
|
Erik Krogh Kristensen
|
8af08756b9
|
split store-steps into backwards and forwards, and prune even more.
|
2020-04-29 09:16:22 +02:00 |
|
Erik Krogh Kristensen
|
7aa421fd8a
|
prune clearly infeasible store steps
|
2020-04-29 09:15:32 +02:00 |
|
Erik Krogh Kristensen
|
8cf71e59ce
|
prune infeasible load steps
|
2020-04-29 09:13:49 +02:00 |
|
Erik Krogh Kristensen
|
435b5cf42d
|
refactor how exploratoryFlowStep is used
|
2020-04-29 09:11:26 +02:00 |
|
Asger Feldthaus
|
9b014c36df
|
JS: Avoid lots of unhelpful magic
|
2020-04-28 08:56:27 +01:00 |
|
Asger Feldthaus
|
a8283593a9
|
JS: Make PropWrite not depend on SourceNode
|
2020-04-28 08:56:27 +01:00 |
|
Asger Feldthaus
|
e3440c1410
|
JS: Cache AMD modules
|
2020-04-28 08:56:27 +01:00 |
|
Asger Feldthaus
|
aa2a49d189
|
JS: Rewrite mayHaveStringValue to avoid misoptimization
|
2020-04-28 08:56:27 +01:00 |
|
Esben Sparre Andreasen
|
04b5a794f1
|
Merge pull request #3313 from esbena/js/typical-bad-sanitizer
New query: Incomplete HTML attribute sanitization
|
2020-04-27 14:31:13 +02:00 |
|
semmle-qlci
|
cbe417f5eb
|
Merge pull request #3336 from erik-krogh/MoarJQuery
Approved by esbena
|
2020-04-25 15:17:55 +01:00 |
|
semmle-qlci
|
28cfe548d5
|
Merge pull request #3325 from erik-krogh/MoreEventClasses
Approved by asgerf
|
2020-04-24 09:02:27 +01:00 |
|
semmle-qlci
|
671e7c6637
|
Merge pull request #3335 from asger-semmle/js/cached-chained-methods
Approved by esbena
|
2020-04-24 08:28:05 +01:00 |
|
Esben Sparre Andreasen
|
89613dbd23
|
JS: add query for incomplete HTML attribute sanitization
|
2020-04-24 09:17:46 +02:00 |
|
Jonas Jensen
|
d98e956c2b
|
Merge pull request #3322 from felicitymay/merge-124-master
Merge rc/1.24 into master
|
2020-04-24 08:48:54 +02:00 |
|
Erik Krogh Kristensen
|
19c6092998
|
autoformat
|
2020-04-23 20:59:34 +02:00 |
|
Erik Krogh Kristensen
|
ea1628ef54
|
fix typo in jQuery.qll
Co-Authored-By: Esben Sparre Andreasen <esbena@github.com>
|
2020-04-23 20:58:49 +02:00 |
|
Erik Krogh Kristensen
|
ee43db1b58
|
slightly expand the $().each model
|
2020-04-23 16:49:47 +02:00 |
|
Erik Krogh Kristensen
|
448ed150df
|
allow the empty string to flow to a JQuery XSS sink
|
2020-04-23 16:45:37 +02:00 |
|
Erik Krogh Kristensen
|
96896fd7f5
|
second round of UnsafeJQueryPlugin reuse
|
2020-04-23 15:12:32 +02:00 |
|
Erik Krogh Kristensen
|
ea569dba78
|
update doc for JQuery plugin predicate
Co-Authored-By: Esben Sparre Andreasen <esbena@github.com>
|
2020-04-23 15:03:39 +02:00 |
|
Asger Feldthaus
|
cafdcfa4de
|
JS: Preserve reflective calls in getAMethodCall
|
2020-04-23 13:57:14 +01:00 |
|
Erik Krogh Kristensen
|
1954a60b6e
|
reuse existing predicate from UnsafeJqueryPlugin
|
2020-04-23 14:25:34 +02:00 |
|
Erik Krogh Kristensen
|
09b6727e6d
|
refactor $.each model
|
2020-04-23 14:24:56 +02:00 |
|
Erik Krogh Kristensen
|
e7d8cd8e8c
|
Merge remote-tracking branch 'upstream/master' into MoarJQuery
|
2020-04-23 14:10:53 +02:00 |
|
Erik Krogh Kristensen
|
6897dda614
|
model that this in $().each(callback) is a DOM-node
|
2020-04-23 13:51:17 +02:00 |
|
Erik Krogh Kristensen
|
8de86967aa
|
model that this in a jQuery plugin is a jQuery object
|
2020-04-23 13:48:54 +02:00 |
|
Erik Krogh Kristensen
|
90652eeb25
|
add $.jGrowl as an XSS sink
|
2020-04-23 10:44:41 +02:00 |
|
semmle-qlci
|
da3292606c
|
Merge pull request #3191 from erik-krogh/XssDom
Approved by esbena, mchammer01
|
2020-04-23 09:17:07 +01:00 |
|
Erik Krogh Kristensen
|
6ada588dd1
|
add support for util.inherits
|
2020-04-22 22:55:12 +02:00 |
|
Erik Krogh Kristensen
|
957e4073b0
|
use getABoundCallbackParameter in SocketIO
|
2020-04-22 21:56:34 +02:00 |
|
Felicity Chapman
|
89bf35cd43
|
Merge branch 'rc/1.24' into merge-124-master
Conflicts:
change-notes/1.24/analysis-javascript.md
Resolved in favor of the rc/1.24 branch
|
2020-04-22 19:01:47 +01:00 |
|
Erik Krogh Kristensen
|
ac26741816
|
reuse existing SanitizerGuard from UnsafeJQueryPlugin
|
2020-04-22 14:16:15 +02:00 |
|