Erik Krogh Kristensen
|
ace484a519
|
change the typeahead.js model to be semantically correct
|
2019-11-26 14:35:13 +01:00 |
|
Erik Krogh Kristensen
|
4a94c49d37
|
changes based on review feedback
|
2019-11-26 13:40:48 +01:00 |
|
Erik Krogh Kristensen
|
97718bf1d4
|
the callback function can both be the second and third argument
|
2019-11-26 13:00:00 +01:00 |
|
Erik Krogh Kristensen
|
c7235bb372
|
add sources and sinks for typeahead.js
|
2019-11-25 10:46:54 +01:00 |
|
Esben Sparre Andreasen
|
5d34806e50
|
Merge pull request #2379 from asger-semmle/typescript-fixes
TS: A bunch of TypeScript fixes
|
2019-11-22 13:31:30 +01:00 |
|
Max Schaefer
|
83f5b614e9
|
JavaScript: Switch detection of callback-based string replacement to data flow.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
659cc812fe
|
JavaScript: Rephrase two predicates to help the optimiser.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
db3eaa23ef
|
JavaScript: Introduce modelling of String.prototype.replace and use it in two queries.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
f43e843b20
|
JavaScript: Introduce class RegExpLiteralNode.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
12ea81af9c
|
JavaScript: Move getAMatchedConstant(RegExpTerm) into the library.
|
2019-11-22 09:24:34 +00:00 |
|
Max Schaefer
|
a5a5debdc7
|
JavaScript: Move getStringValue(RegExpLiteral) into the library.
|
2019-11-22 09:24:34 +00:00 |
|
Asger F
|
ec8ced7963
|
TS: Fix a typos and leftover todo
|
2019-11-21 15:39:37 +00:00 |
|
Asger F
|
4a885cbf92
|
TS: Expose optional parameters at syntax level
|
2019-11-21 15:39:37 +00:00 |
|
Asger F
|
b6b8213e13
|
TS: Handle rest parameters in call signatures
|
2019-11-21 15:39:37 +00:00 |
|
Asger F
|
8205a59688
|
TS: Unfold aliases in Type.unfold()
|
2019-11-21 15:39:37 +00:00 |
|
Asger F
|
e25ee182a0
|
TS: Extract type alias relation
|
2019-11-21 15:39:37 +00:00 |
|
Esben Sparre Andreasen
|
03c83c9c9d
|
JS: model React's getDerivedStateFromError
|
2019-11-21 13:18:43 +01:00 |
|
semmle-qlci
|
77c869f528
|
Merge pull request #2220 from erik-krogh/processEnvTaint
Approved by esbena, max-schaefer
|
2019-11-20 13:16:43 +00:00 |
|
Erik Krogh Kristensen
|
0a428a8f44
|
typo
Co-Authored-By: Esben Sparre Andreasen <esbena@github.com>
|
2019-11-19 13:05:13 +01:00 |
|
Erik Krogh Kristensen
|
8ff515a58d
|
address review feedback on MaskingReplacer
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
4ec2070e48
|
remove property reads on process.env as a taint step, and add a barrier for masking replace calls
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
052a331395
|
rename ProcessEnvLabel to PartiallySensitiveMap
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
2bd48db8cd
|
refactor isSanitizerEdge in clear-text-logging
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
92dc759cf9
|
remove type cast, and fix expected test results
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
850278c62f
|
some changes based on review. And change to only flag unknown reads of process.env
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
68c30aaef3
|
add flowlabels to js/clear-text-logging
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
14e4decffa
|
changes based on review feedback. No flow-labels yet
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
1766f6a6d8
|
simplify global var "process"
Co-Authored-By: Esben Sparre Andreasen <esbena@github.com>
|
2019-11-16 15:20:41 +01:00 |
|
Erik Krogh Kristensen
|
297c71a64b
|
add process.env as source for js/clear-text-logging
|
2019-11-16 15:20:41 +01:00 |
|
Erik Krogh Kristensen
|
b12e255fd8
|
add indirect calls to logging methods as logging methods
|
2019-11-16 15:20:41 +01:00 |
|
Erik Krogh Kristensen
|
ddd217628f
|
Merge pull request #2347 from esbena/js/fix-mjs-check
JS: fix the check for an "mjs" extension on an extensionless file
|
2019-11-15 17:39:10 +01:00 |
|
Esben Sparre Andreasen
|
8e8215893f
|
JS: fix mjs check for extensionless files
|
2019-11-15 14:38:27 +01:00 |
|
Erik Krogh Kristensen
|
f813e06680
|
Merge pull request #2345 from Semmle/esbena-patch-3
Update FlowSteps.qll
|
2019-11-15 14:04:14 +01:00 |
|
semmle-qlci
|
2f63b89941
|
Merge pull request #2338 from esbena/js/model-get-them-args
Approved by max-schaefer
|
2019-11-15 11:50:45 +00:00 |
|
Esben Sparre Andreasen
|
a3deb7d4e0
|
Update FlowSteps.qll
|
2019-11-15 12:44:04 +01:00 |
|
Esben Sparre Andreasen
|
c3fdfdecab
|
JS: rename DefaultParsedCommandLineArgumentsAsSource
|
2019-11-15 10:40:15 +01:00 |
|
Asger F
|
607aed37ee
|
Update javascript/ql/src/semmle/javascript/Expr.qll
Co-Authored-By: Max Schaefer <54907921+max-schaefer@users.noreply.github.com>
|
2019-11-15 09:27:21 +00:00 |
|
Asger F
|
2242df920f
|
JS: More qldoc
|
2019-11-15 09:27:20 +00:00 |
|
Asger F
|
dc6c15cbb9
|
Update javascript/ql/src/semmle/javascript/Regexp.qll
Co-Authored-By: Max Schaefer <54907921+max-schaefer@users.noreply.github.com>
|
2019-11-15 09:27:20 +00:00 |
|
Asger F
|
dd9274e42c
|
JS: Docs regarding regexp terms in string literals
|
2019-11-15 09:27:20 +00:00 |
|
Asger F
|
20fb7717d8
|
JS: Use type inference to refine regexp string tracking
|
2019-11-15 09:27:20 +00:00 |
|
Asger F
|
8bc89ee254
|
JS: Update semi-anchored regex query
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
c21d095d38
|
JS: Restrict RegExp queries to actual regular expressions
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
b6c1c174a9
|
JS: Deabstractify RegExpTerm classes
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
e0bdc777b9
|
JS: Make ReDoS check string-based regexes
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
57de6382cd
|
JS: Update QL API
|
2019-11-15 09:27:19 +00:00 |
|
Esben Sparre Andreasen
|
8e6a19b3d3
|
JS: add DefaultParsedCommandLineArgumentsAsSource
|
2019-11-15 08:42:02 +01:00 |
|
Esben Sparre Andreasen
|
cc768345d0
|
JS: add security tests for malicious torrents
|
2019-11-14 13:54:19 +01:00 |
|
Esben Sparre Andreasen
|
bea59ec8ad
|
JS: add some parsed torrent properties as remote flow sources
|
2019-11-14 13:54:19 +01:00 |
|
Erik Krogh Kristensen
|
538690eee6
|
remove duplicate reflectiveCallNode method, and removing redundant getExpr() method
|
2019-11-13 15:53:21 +01:00 |
|