Erik Krogh Kristensen
|
f719e0ca1b
|
remove nunjucks template URLs from the target-blank query
|
2021-08-02 22:46:59 +02:00 |
|
Calum Grant
|
771e686946
|
Update security-severity scores
|
2021-06-15 13:25:17 +01:00 |
|
Calum Grant
|
a594afb828
|
Add security-severity metadata
|
2021-06-10 20:11:08 +01:00 |
|
Asger Feldthaus
|
d8c9dba990
|
JS: Autoformat
|
2021-01-18 12:19:09 +00:00 |
|
Asger Feldthaus
|
3c0867125b
|
JS: Remove FP in TargetBlank
|
2021-01-18 12:19:08 +00:00 |
|
Erik Krogh Kristensen
|
d6dc4bb655
|
allow flask url_for urls in TargetBlank.ql
|
2020-10-05 21:40:24 +02:00 |
|
Erik Krogh Kristensen
|
1f9749fbfe
|
revert mailto: change in TargetBlank.ql
|
2020-09-03 09:39:01 +02:00 |
|
Erik Krogh Kristensen
|
f0a0f41c3c
|
allow urls that are prefixed with # or ? in js/unsafe-external-link
|
2020-09-02 10:19:42 +02:00 |
|
Erik Krogh Kristensen
|
f7edf28d0d
|
allow mailto links in js/unsafe-external-link
|
2020-08-31 16:01:28 +02:00 |
|
Max Schaefer
|
cf22761ccc
|
JavaScript: Add CWE-1022 to TargetBlank.
|
2019-05-21 12:16:32 +01:00 |
|
Max Schaefer
|
31bb39a810
|
JavaScript: Autoformat all QL files.
|
2019-01-07 10:15:45 +00:00 |
|
Max Schaefer
|
c1690a69e5
|
JavaScript: Make TargetBlank only highlight the first line of the link.
Otherwise alerts for multi-line `<a>` elements end up looking very red.
I also took the opportunity to improve the tests slightly.
|
2018-11-20 12:53:27 +00:00 |
|
Pavel Avgustinov
|
b55526aa58
|
QL code and tests for C#/C++/JavaScript.
|
2018-08-02 17:53:23 +01:00 |
|