Ed Minnix
|
909b1d70d9
|
Rename files to say "Allow" instead of "Permit"
|
2023-01-09 10:11:03 -05:00 |
|
Ed Minnix
|
c723df3ca7
|
Fix alert message in expected file
|
2023-01-09 10:08:19 -05:00 |
|
Ed Minnix
|
f626d4794a
|
Change wording from "permit" to "allow" in id and name
|
2023-01-09 10:03:12 -05:00 |
|
Ed Minnix
|
972b4629c8
|
Fix typo in change note
|
2023-01-09 10:01:38 -05:00 |
|
Ed Minnix
|
64668883a4
|
Add good example to documentation
|
2023-01-09 09:59:38 -05:00 |
|
Ed Minnix
|
2ec73c50f9
|
Mention WebView in alert message
|
2023-01-09 09:55:09 -05:00 |
|
Ed Minnix
|
81df89f93e
|
Use proper @id in changenote
|
2023-01-03 15:19:26 -05:00 |
|
Ed Minnix
|
28ad9d00fb
|
Merge both setAllowContentAccess queries into one query
Previously, the query to detect whether or not access to `content://`
links was done using two queries.
Now they can be merged into one query
|
2023-01-03 15:17:07 -05:00 |
|
Ed Minnix
|
35de551f6b
|
Formatting
|
2022-12-31 17:19:49 -05:00 |
|
Ed Minnix
|
515fa21aad
|
Change notes
|
2022-12-31 17:18:37 -05:00 |
|
Ed Minnix
|
df1a4d2ed1
|
Documentation fix: Add state1 and state2 to documentation
|
2022-12-31 15:25:37 -05:00 |
|
Ed Minnix
|
68392aa8d8
|
Fix test expectations
|
2022-12-31 15:25:25 -05:00 |
|
Ed Minnix
|
02f70f3536
|
Add @security-severity tag
|
2022-12-31 15:00:28 -05:00 |
|
Edward Minnix III
|
1d345c6101
|
Refactoring and simplification
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2022-12-31 15:00:28 -05:00 |
|
Ed Minnix
|
9ef319f659
|
Java: setAllowContentAccess query tests
|
2022-12-31 15:00:28 -05:00 |
|
Ed Minnix
|
5265cb4b03
|
Merge two dataflow configurations into one taint tracking
|
2022-12-31 15:00:28 -05:00 |
|
Ed Minnix
|
973f649e76
|
Break dataflow into two steps in order to capture flow from WebView to settings call
|
2022-12-31 15:00:28 -05:00 |
|
Ed Minnix
|
0e15dd9fa9
|
Query metadata
|
2022-12-31 15:00:28 -05:00 |
|
Edward Minnix III
|
778749184b
|
Change id to use android/ instead of prepending android-
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2022-12-31 15:00:28 -05:00 |
|
Ed Minnix
|
da25c586e6
|
Dataflow query for detecting paths that disable content access
Since the default value is `true`, we need to determine whether or not
the `setAllowContentAccess` method is ever called using dataflow.
|
2022-12-31 15:00:28 -05:00 |
|
Ed Minnix
|
8a763015e6
|
Reduce precision rating to medium
This query won't always be a security problem, so it should have a lower
precision rating than `high`.
|
2022-12-31 15:00:28 -05:00 |
|
Ed Minnix
|
7cc53126f3
|
Java: WebView setAllowContentAccess query test cases
|
2022-12-31 15:00:28 -05:00 |
|
Ed Minnix
|
a023726c03
|
Java: add Android stubs to options file for CWE-200 tests
|
2022-12-31 15:00:28 -05:00 |
|
Ed Minnix
|
e4e13d38b7
|
Java: query for Android WebView setAllowContentAccess
|
2022-12-31 15:00:28 -05:00 |
|
Ed Minnix
|
e259ef5d1d
|
Java: Add class for android.webkit.WebSettings.setAllowContentAccess
|
2022-12-31 15:00:28 -05:00 |
|
Edward Minnix III
|
b77923f6e6
|
Merge pull request #11767 from atorralba/atorralba/java/fix-pinning-tests
Java: Small simplification in Missing Certificate Pinning tests
|
2022-12-21 11:21:47 -05:00 |
|
Edward Minnix III
|
597523e65a
|
Merge pull request #11766 from atorralba/atorralba/java/fix-android-query-id
Java: Fix new Android queries' IDs
|
2022-12-21 11:21:12 -05:00 |
|
Arthur Baars
|
98c5b81456
|
Merge pull request #11723 from aibaars/alert-suppression
CodeQL alert suppression
|
2022-12-21 10:59:57 +01:00 |
|
Arthur Baars
|
035ad65e43
|
AlertSuppression: move library into util folder
|
2022-12-21 10:39:57 +01:00 |
|
Tony Torralba
|
ab73d13d8b
|
Small simplification
|
2022-12-21 09:58:13 +01:00 |
|
Tony Torralba
|
345c383acc
|
Fix new Android queries' IDs
|
2022-12-21 09:36:57 +01:00 |
|
Jami
|
c9258effb6
|
Merge pull request #11572 from jcogs33/jcogs33/model-top-jdk-apis
Java: model top 100 JDK APIs
|
2022-12-20 09:13:53 -05:00 |
|
Jami
|
dc0bad3dc5
|
update change note
Co-authored-by: yo-h <55373593+yo-h@users.noreply.github.com>
|
2022-12-20 07:55:58 -05:00 |
|
Tony Torralba
|
149cae9603
|
Merge pull request #10971 from joefarebrother/android-certificate-pinning
Java: Add Android missing certificate pinning query (CWE-295)
|
2022-12-20 11:03:16 +01:00 |
|
Tony Torralba
|
3e7a819fe7
|
Simplification
|
2022-12-20 09:42:25 +01:00 |
|
Jeroen Ketema
|
edc768b43b
|
Merge pull request #11707 from smowton/smowton/fix/java-empty-multiline-comment
Java: handle printing an empty comment (/**/); add relevant tests
|
2022-12-20 08:07:42 +01:00 |
|
Jami Cogswell
|
19deb59d07
|
Java: sort neutral models alphabetically
|
2022-12-19 14:22:17 -05:00 |
|
Tony Torralba
|
a47ef17a0d
|
Update java/ql/src/Security/CWE/CWE-295/AndroidMissingCertificatePinning1.java
Co-authored-by: Edward Minnix III <egregius313@github.com>
|
2022-12-19 18:11:54 +01:00 |
|
Chris Smowton
|
ebc0b0c4d6
|
Merge pull request #11665 from smowton/smowton/admin/revert-kotlin-default-method-type-erasure
Kotlin: Revert type erasure within $default functions
|
2022-12-19 16:33:20 +00:00 |
|
Edward Minnix III
|
39a7c7bb12
|
Merge pull request #11282 from egregius313/egregiu313/webview-addjavascriptinterface
Java: Query for detecting addJavascriptInterface method calls
|
2022-12-19 11:28:45 -05:00 |
|
Tony Torralba
|
624c9ff834
|
Update java/ql/src/Security/CWE/CWE-295/AndroidMissingCertificatePinning1.java
|
2022-12-19 17:26:41 +01:00 |
|
Arthur Baars
|
a8be5d7274
|
AlertSuppression: add change notes
|
2022-12-19 17:02:52 +01:00 |
|
Arthur Baars
|
0f313231bc
|
AlertSuppression: add more tests
|
2022-12-19 16:43:11 +01:00 |
|
Tony Torralba
|
0c6ace350f
|
Update java/ql/src/Security/CWE/CWE-295/AndroidMissingCertificatePinning.ql
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-12-19 16:24:39 +01:00 |
|
Arthur Baars
|
c9739b21cb
|
AlertSuppression: add support for //codeql comments
|
2022-12-19 16:10:28 +01:00 |
|
Arthur Baars
|
c176606be5
|
AlertSuppression: allow //lgtm comments to scope over the next line
|
2022-12-19 16:10:26 +01:00 |
|
Arthur Baars
|
016c7a8ca7
|
Merge pull request #11719 from aibaars/alert-suppression-shared
Shared AlertSuppression library
|
2022-12-19 16:04:44 +01:00 |
|
Jami Cogswell
|
a8ee633acd
|
Java: apply review suggestions
|
2022-12-19 09:09:01 -05:00 |
|
Jami Cogswell
|
f37f0a09aa
|
Java: update change note
|
2022-12-19 08:41:56 -05:00 |
|
Jami Cogswell
|
42ddd66360
|
Java: add hasApiName predicate
|
2022-12-19 08:38:12 -05:00 |
|