Erik Krogh Kristensen
|
b09015380a
|
add support for String.prototype.replaceAll
|
2020-09-21 10:50:04 +02:00 |
|
Esben Sparre Andreasen
|
d27442e846
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2020-08-26 20:18:54 +02:00 |
|
Esben Sparre Andreasen
|
89305865d0
|
JS: make sanitization a "common" technique rather than "important"
|
2020-08-26 15:41:54 +02:00 |
|
Erik Krogh Kristensen
|
cc5ef4d5e1
|
rename JsonSerializeCall to JsonStringifyCall
|
2020-08-05 13:22:41 +02:00 |
|
Erik Krogh Kristensen
|
5a3f67a682
|
introduce model for JSON.stringify and similar libraries
|
2020-08-05 12:14:51 +02:00 |
|
Esben Sparre Andreasen
|
80981ec8f5
|
Update UnsafeHtmlExpansion-transformed.html
|
2020-06-30 12:01:02 +02:00 |
|
Esben Sparre Andreasen
|
3be094ea5b
|
JS: polish js/incomplete-html-attribute-sanitization
|
2020-06-22 14:35:00 +02:00 |
|
Esben Sparre Andreasen
|
678bb7c128
|
JS: simplify loop detection
|
2020-06-12 14:56:08 +02:00 |
|
Esben Sparre Andreasen
|
2d2468463b
|
JS: initial version of IncompleteMultiCharacterSanitization.ql
|
2020-06-09 08:59:59 +02:00 |
|
Esben Sparre Andreasen
|
9552352d6a
|
JS: address qhelp feedback
|
2020-05-13 12:53:59 +02:00 |
|
Esben Sparre Andreasen
|
7cc3a5a242
|
JS: qhelp fixups
|
2020-05-06 14:46:34 +02:00 |
|
Esben Sparre Andreasen
|
69191577d6
|
JS: qhelp for js/unsafe-html-expansion
|
2020-05-06 14:03:27 +02:00 |
|
Esben Sparre Andreasen
|
99e5db407f
|
JS: address review comments
|
2020-05-05 14:04:05 +02:00 |
|
Esben Sparre Andreasen
|
304b013f88
|
JS: query and tests for unsafe HTML expansion
|
2020-05-05 10:32:16 +02:00 |
|
Esben Sparre Andreasen
|
c0250894de
|
Apply suggestions from code review
Co-Authored-By: mc <42146119+mchammer01@users.noreply.github.com>
|
2020-04-27 12:37:39 +02:00 |
|
Esben Sparre Andreasen
|
0a8e371b0e
|
Update javascript/ql/src/Security/CWE-116/IncompleteHtmlAttributeSanitization.qhelp
Co-Authored-By: Asger F <asgerf@github.com>
|
2020-04-27 09:09:26 +02:00 |
|
Esben Sparre Andreasen
|
58b5bd5cfd
|
JS: fixup documentation
|
2020-04-24 10:56:53 +02:00 |
|
Esben Sparre Andreasen
|
6d6ec89ba8
|
JS: add qhelp
|
2020-04-24 09:18:09 +02:00 |
|
Esben Sparre Andreasen
|
89613dbd23
|
JS: add query for incomplete HTML attribute sanitization
|
2020-04-24 09:17:46 +02:00 |
|
Asger Feldthaus
|
fefcf1a7a6
|
JS: Autoformat everything
|
2020-02-27 09:41:01 +00:00 |
|
Max Schaefer
|
1951461f55
|
JavaScript: Simplify DoubleEscaping.
Undo previous work on generalising the concept of a replacement, which did not work out.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
ff002a7af4
|
JavaScript: Whitelist more harmless incomplete escapes.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
659cc812fe
|
JavaScript: Rephrase two predicates to help the optimiser.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
db3eaa23ef
|
JavaScript: Introduce modelling of String.prototype.replace and use it in two queries.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
12ea81af9c
|
JavaScript: Move getAMatchedConstant(RegExpTerm) into the library.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
a5a5debdc7
|
JavaScript: Move getStringValue(RegExpLiteral) into the library.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
0edb70f373
|
JavaScript: Deal with escape-unescape-escape (and similar) chains.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
cb54618a5d
|
JavaScript: Deal with (un-)escaping on captured variables.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
61aa075e8d
|
JavaScript: Fix regexes for escaping schemes.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
4f899a9b0d
|
JavaScript: Recognize string escaping using .replace with a callback.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
5dcf55e113
|
JavaScript: Refactor DoubleEscaping.ql.
|
2019-11-22 09:24:34 +00:00 |
|
semmle-qlci
|
8cca9b05ea
|
Merge pull request #2393 from max-schaefer/js/improve-incomplete-sanitization-docs
Approved by mchammer01
|
2019-11-21 16:04:19 +00:00 |
|
Max Schaefer
|
cb20de8070
|
JavaScript: Add a warning to IncompleteSanitization help.
Sanitizing away multi-character strings using regular expressions is tricky business, and we should probably warn about it.
|
2019-11-20 11:57:50 +00:00 |
|
Max Schaefer
|
5565be14fc
|
JavaScript: Teach IncompleteSanitization to flag incomplete path sanitizers.
|
2019-11-19 15:06:16 +00:00 |
|
Max Schaefer
|
155cea7b5b
|
Revert "JavaScript: Improve double-escaping query"
|
2019-11-12 22:54:12 +00:00 |
|
Max Schaefer
|
016808b92e
|
JavaScript: Address review comments.
|
2019-11-04 17:00:12 +00:00 |
|
Max Schaefer
|
3bbded57d3
|
JavaScript: Autoformat.
|
2019-10-30 14:49:18 +00:00 |
|
Max Schaefer
|
bb0771b36c
|
JavaScript: Deal with escape-unescape-escape (and similar) chains.
|
2019-10-30 14:49:01 +00:00 |
|
Max Schaefer
|
8c133ff61d
|
JavaScript: Deal with (un-)escaping on captured variables.
|
2019-10-30 14:46:50 +00:00 |
|
Max Schaefer
|
a8214ce7ee
|
JavaScript: Fix regexes for escaping schemes.
|
2019-10-30 14:15:59 +00:00 |
|
Max Schaefer
|
5349e0f881
|
JavaScript: Recognise wrapped chains of replacements.
|
2019-10-30 13:14:38 +00:00 |
|
Max Schaefer
|
02d16b1dc9
|
JavaScript: Recognise wrapped string replacement functions.
|
2019-10-30 13:01:17 +00:00 |
|
Max Schaefer
|
aaeca32519
|
JavaScript: Recognize string escaping using .replace with a callback.
|
2019-10-30 12:45:32 +00:00 |
|
Max Schaefer
|
bd1c99d8a4
|
JavaScript: Recognise JSON.stringify and JSON.parse as escaper/unescaper.
|
2019-10-30 12:38:05 +00:00 |
|
Max Schaefer
|
63f24476e9
|
JavaScript: Refactor DoubleEscaping.ql.
|
2019-10-30 10:59:14 +00:00 |
|
semmle-qlci
|
16c95d8c5e
|
Merge pull request #1876 from esben-semmle/js/more-delimiter-stripping-whitelisting
Approved by xiemaisi
|
2019-09-11 09:16:57 +01:00 |
|
Anders Schack-Mulligen
|
ca45fb5a60
|
JavaScript: Autoformat.
|
2019-09-06 09:04:51 +02:00 |
|
Esben Sparre Andreasen
|
a9665f53b8
|
JS: whitelist quote stripping for js/incomplete-sanitization
|
2019-09-05 09:47:49 +01:00 |
|
Esben Sparre Andreasen
|
ac0913c878
|
JS: add newline removal whitelist for js/incomplete-sanitization
|
2019-04-23 08:38:23 +02:00 |
|
Esben Sparre Andreasen
|
c80ee3df01
|
Mergeback: rc/1.20 into Semmle/master
|
2019-04-16 08:46:15 +02:00 |
|