aegilops
|
e7881a8c7f
|
Fix typo
|
2025-01-09 17:11:06 +00:00 |
|
aegilops
|
62599b2a12
|
Formatted
|
2025-01-09 17:02:37 +00:00 |
|
aegilops
|
98b4c35844
|
Set doc string on getElementNode predicate
|
2025-01-09 17:00:01 +00:00 |
|
aegilops
|
4b57d5feb2
|
Added XSS sink for innerHTML/outerHTML using new Angular attribute def
|
2025-01-08 16:36:46 +00:00 |
|
aegilops
|
2dc9e7bab7
|
Moved def from AngularJSCore to Angular2
|
2025-01-08 16:36:10 +00:00 |
|
aegilops
|
4530118681
|
Comment out hardcoded definition of sink
|
2025-01-06 17:33:31 +00:00 |
|
aegilops
|
820fe6cd04
|
Formatting
|
2025-01-06 16:59:04 +00:00 |
|
aegilops
|
322c731ac3
|
Attempt at AttributeDefinition to generalise Angular Renderer2 support
|
2025-01-06 16:52:38 +00:00 |
|
aegilops
|
e414b8c5be
|
Remove @Input() decorated members as remote sources, in favour of a later Threat Model
|
2025-01-06 16:51:35 +00:00 |
|
aegilops
|
8dac00aa83
|
Change from getParameter() to getArgument()
|
2025-01-06 15:43:47 +00:00 |
|
aegilops
|
7128700003
|
Simplified AngularInputUse class
|
2025-01-03 17:02:55 +00:00 |
|
aegilops
|
4891c1e5fe
|
Added QLdoc and simplified QL in source class
|
2025-01-03 16:50:47 +00:00 |
|
aegilops
|
4773917876
|
Formatting
|
2025-01-03 16:43:00 +00:00 |
|
Paul Hodgkinson
|
a23f4ee007
|
Merge branch 'main' into angular-sources-sinks
|
2025-01-03 16:38:48 +00:00 |
|
aegilops
|
0f64822356
|
New remote source - reading from an @Input() decorated class member
|
2025-01-03 16:34:15 +00:00 |
|
aegilops
|
09e4c78b0f
|
New XSS sink - writing to innerHTML using the Angular Renderer2 API
|
2025-01-03 16:33:42 +00:00 |
|
Geoffrey White
|
44a0ad2942
|
Update data-flow -> data flow in all versions of ConceptsShared.qll.
|
2024-12-12 13:36:26 +00:00 |
|
Napalys Klicius
|
9ca0fe4cbf
|
Update RegExp handling and add test case
Co-authored-by: erik-krogh <erik-krogh@github.com>
|
2024-11-28 14:13:40 +01:00 |
|
Napalys
|
9a1c1f4be3
|
JS: Added in RegExpCreationNode maybeGlobal predicate for more convenience.
|
2024-11-28 12:03:51 +01:00 |
|
Napalys
|
1d2e08a3b6
|
JS: now Reg Exp injection treats unknownFlags as sanitization, MetacharEscapeSanitizer
|
2024-11-28 11:26:58 +01:00 |
|
Napalys
|
e673348ed3
|
JS: now RegExp with unknown flags is not flagged as an issue within password Clear text storage of sensitive information
|
2024-11-28 11:26:56 +01:00 |
|
Napalys
|
a2c46749c6
|
JS: fixed issue where MaskingReplacer would work only with regexp literals but not objects
|
2024-11-28 11:26:55 +01:00 |
|
Napalys
|
c71778f1aa
|
JS: xss does not flag anymore replace with RegExp unknown flags
|
2024-11-28 11:26:53 +01:00 |
|
Napalys
|
875478c1c6
|
JS: Fixed path query not flagging new RegExp with DotRemovingReplaceCall
|
2024-11-28 11:26:45 +01:00 |
|
Napalys
|
a0df33c3ac
|
JS: UnsafeShellCommand Using unknown flags in the RegExp object is no longer flagged as bad sanitization to reduce false positives.
|
2024-11-28 11:26:43 +01:00 |
|
Napalys
|
23b18aeca9
|
JS: Now unknown flags are not flagged in taint paths
|
2024-11-28 11:26:41 +01:00 |
|
Napalys
|
eca7a88615
|
JS: Fixed docs description
|
2024-11-28 11:26:40 +01:00 |
|
Napalys
|
7db6f7c721
|
JS: Added test cases with new RegExp for Tainted paths, currently works only with literals
|
2024-11-28 11:26:39 +01:00 |
|
Napalys
|
faef9dd877
|
JS: protyte poluting now treats unknownFlags as potentially good sanitization.
|
2024-11-28 11:26:38 +01:00 |
|
Napalys
|
18c7b18f82
|
JS: Now BadHtmlSanitizers new RegExp with unknown flags is also flagged.
|
2024-11-28 11:26:36 +01:00 |
|
Napalys
|
38be0e4c0a
|
JS: Now BadHtmlSanitizers also flags new RegExp as potential issue
|
2024-11-28 11:26:34 +01:00 |
|
Napalys Klicius
|
61e00861e5
|
Merge pull request #18008 from Napalys/napalys/ES2024-group-functions
JS: Added support for [Object, Map].groupBy ES2024 feature
|
2024-11-21 19:03:57 +01:00 |
|
Napalys Klicius
|
7ee0a7b398
|
Update javascript/ql/lib/semmle/javascript/Collections.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2024-11-21 14:02:42 +01:00 |
|
Napalys Klicius
|
edb9b47111
|
Merge pull request #18047 from Napalys/napalys/ES2023-string-protytpe-toWellFormed
JS: Added taint-step String.prototype.toWellFormed ES2023 feature
|
2024-11-21 14:01:21 +01:00 |
|
Napalys
|
afc2d3e6d2
|
JS: Add: String.protytpe.toWellFormed to StringManipulationTaintStep
|
2024-11-20 17:42:25 +01:00 |
|
Napalys
|
64c45debdb
|
JS: removed unnecessary getALocalSource from ArrayCallBackDataFlowStep
|
2024-11-20 14:57:00 +01:00 |
|
Napalys
|
9dbf7d1828
|
JS: removed unnecessary getALocalSource from ArrayCallBackDataTaintStep
|
2024-11-20 14:54:06 +01:00 |
|
Napalys Klicius
|
a957e00fe5
|
Merge branch 'main' into napalys/ES2024-group-functions
|
2024-11-20 14:03:31 +01:00 |
|
Napalys
|
58faa2d71e
|
JS: Add: dataflow step for static method of groupBy from Map.
|
2024-11-20 13:34:11 +01:00 |
|
Napalys
|
28ead4011a
|
JS: Add: taint step to handle propagation of data flow from the array to callback
|
2024-11-19 14:15:15 +01:00 |
|
Napalys
|
c03d69af1e
|
JS: Add: dataflow step for find, findLast, findLastIndex callback functions
|
2024-11-19 09:42:11 +01:00 |
|
Napalys
|
1b0f8aa657
|
JS: removed unnecessary findlast module import
|
2024-11-19 09:30:05 +01:00 |
|
Napalys
|
213ce225e0
|
JS: Add: taint step for Object.groupBy function, fixed test cases from 8ae05d8be4
|
2024-11-18 12:58:07 +01:00 |
|
Napalys
|
c02ad65fdc
|
JS: Add: taint step for Map.groupBy function
|
2024-11-18 12:50:06 +01:00 |
|
Napalys
|
fcb65534a8
|
JS: Add: Array.protype.findLast as taint step
|
2024-11-15 14:10:01 +01:00 |
|
Napalys
|
bed1f25b3f
|
JS: Fix: Now Array.prototype.with is properly flagged as taint step
|
2024-11-15 10:35:34 +01:00 |
|
Napalys Klicius
|
6fa3ff39a0
|
Merge branch 'main' into napalys/toSpliced-support
|
2024-11-14 16:56:32 +01:00 |
|
Napalys Klicius
|
c8c15a0899
|
Merge pull request #17910 from Napalys/napalys/matchAll-support
JS: Support for matchAll
|
2024-11-14 15:36:20 +01:00 |
|
Napalys
|
b333f523df
|
JS: Fix: now one can determine regex via Array.prototype.toSpliced function call.
|
2024-11-14 15:35:03 +01:00 |
|
Napalys
|
84234d59b9
|
JS: Fix: Ensure toSpliced with spread operator is flagged
|
2024-11-13 17:21:34 +01:00 |
|