semmle-qlci
|
70131e6ac8
|
Merge pull request #3598 from asger-semmle/js/regexp-test
Approved by esbena
|
2020-06-04 09:05:21 +01:00 |
|
Asger Feldthaus
|
945db4d86c
|
JS: Fix test output
|
2020-06-02 16:38:21 +01:00 |
|
Esben Sparre Andreasen
|
f9ed64fc45
|
Merge branch 'master' into js/membershiptest
|
2020-06-02 08:54:44 +02:00 |
|
Asger Feldthaus
|
707b0f33a0
|
JS: Use in ContainsHTMLGuard
|
2020-06-01 12:06:40 +01:00 |
|
Erik Krogh Kristensen
|
5bb308dc8f
|
sanitize variables used in an HTML escaping switch-case
|
2020-05-28 12:37:41 +02:00 |
|
Erik Krogh Kristensen
|
1a2db10a90
|
recognize barrier guard where the result is stored in a variable
|
2020-05-28 10:24:42 +02:00 |
|
Erik Krogh Kristensen
|
562a38cdd5
|
add ContainsHTMLGuard
|
2020-05-28 10:24:42 +02:00 |
|
Erik Krogh Kristensen
|
33da82d884
|
Merge branch 'master' of https://github.com/github/codeql into pr/erik-krogh/3566
|
2020-05-27 12:21:14 +00:00 |
|
Erik Krogh Kristensen
|
319363f56c
|
update expected output
|
2020-05-26 18:47:37 +02:00 |
|
Erik Krogh Kristensen
|
ad40c4b0f2
|
add a sanitizer guard for safe attribute string concatenations
|
2020-05-26 12:36:47 +02:00 |
|
Erik Krogh Kristensen
|
9254df1f78
|
sanitize optionally sanitized values
|
2020-05-26 00:09:11 +02:00 |
|
Esben Sparre Andreasen
|
76bce40a8b
|
JS: test fixups
|
2020-05-19 13:12:34 +02:00 |
|
Erik Krogh Kristensen
|
4b8b0cb379
|
update expected output
|
2020-05-05 09:13:21 +02:00 |
|
Erik Krogh Kristensen
|
7af19559d4
|
add test case for location.split("?")[0] for DomBasedXss
|
2020-05-05 09:13:21 +02:00 |
|
Erik Krogh Kristensen
|
ee43db1b58
|
slightly expand the $().each model
|
2020-04-23 16:49:47 +02:00 |
|
Erik Krogh Kristensen
|
448ed150df
|
allow the empty string to flow to a JQuery XSS sink
|
2020-04-23 16:45:37 +02:00 |
|
Erik Krogh Kristensen
|
ce106981b3
|
add tests
|
2020-04-23 14:24:33 +02:00 |
|
Erik Krogh Kristensen
|
d8c498bd15
|
add NOT OK comment
Co-Authored-By: Esben Sparre Andreasen <esbena@github.com>
|
2020-04-23 12:17:25 +02:00 |
|
Erik Krogh Kristensen
|
e1423b0fa5
|
add test for jGrowl
|
2020-04-23 11:58:06 +02:00 |
|
Erik Krogh Kristensen
|
ac26741816
|
reuse existing SanitizerGuard from UnsafeJQueryPlugin
|
2020-04-22 14:16:15 +02:00 |
|
Erik Krogh Kristensen
|
59b94b3d1b
|
revert back to having 2 separate cases in JQuery::MethodCall
|
2020-04-21 13:08:06 +02:00 |
|
Erik Krogh Kristensen
|
12f4ce8111
|
merge two cases of jQuery method calls
|
2020-04-20 13:28:55 +02:00 |
|
Erik Krogh Kristensen
|
14b551f887
|
Xss through DOM
|
2020-04-17 10:54:14 +02:00 |
|
Erik Krogh Kristensen
|
4864e77430
|
Merge branch 'master' of git.semmle.com:Semmle/ql into UrlSearch
|
2020-03-27 15:59:29 +01:00 |
|
Erik Krogh Kristensen
|
58af63d8cc
|
add test case for XSS on url suffix
|
2020-03-27 10:02:24 +01:00 |
|
semmle-qlci
|
cf5b1f0cd5
|
Merge pull request #3019 from erik-krogh/ArrayStep
Approved by asgerf
|
2020-03-25 12:08:44 +00:00 |
|
Erik Krogh Kristensen
|
fa710c5864
|
Merge remote-tracking branch 'upstream/master' into UrlSearch
|
2020-03-24 00:23:15 +01:00 |
|
Asger Feldthaus
|
7393844699
|
JS: Update some queries that used data as source
|
2020-03-18 11:55:13 +00:00 |
|
Erik Krogh Kristensen
|
68ffd52d4c
|
update expected output
|
2020-03-09 16:45:10 +01:00 |
|
semmle-qlci
|
85ee5fc988
|
Merge pull request #2955 from erik-krogh/BetterHeader
Approved by asgerf
|
2020-03-05 08:24:43 +00:00 |
|
Erik Krogh Kristensen
|
bc13204193
|
refactor header checks to be based on dominance
|
2020-03-03 12:04:31 +01:00 |
|
Erik Krogh Kristensen
|
9016f43d80
|
update expected output
|
2020-03-03 10:04:57 +01:00 |
|
Asger Feldthaus
|
e405a9769c
|
JS: Really autoformat everything
|
2020-03-02 10:48:33 +00:00 |
|
Erik Krogh Kristensen
|
c14a485ca7
|
recognize more HttpResponseSink by restricting the hasNonHtmlHeader check
|
2020-03-02 10:10:34 +01:00 |
|
Esben Sparre Andreasen
|
abe7aeef7c
|
Merge pull request #2643 from esbena/js/unsafe-jquery
JS: add query js/unsafe-jquery-plugin
|
2020-02-18 09:26:14 +01:00 |
|
Erik Krogh Kristensen
|
ffc6fddddd
|
update expected test output
|
2020-02-05 10:52:40 +01:00 |
|
Erik Krogh Kristensen
|
76aca02752
|
change the pseudo-property on URL to a two-stage process
|
2020-02-05 10:27:03 +01:00 |
|
Erik Krogh Kristensen
|
8d37c03209
|
using pseudo-properties to model URL parsing
|
2020-02-04 16:30:07 +01:00 |
|
Esben Sparre Andreasen
|
c70997febf
|
JS: address review comments for js/unsafe-jquery-plugin
|
2020-01-31 19:33:04 +01:00 |
|
Esben Sparre Andreasen
|
2ad9b843ae
|
JS: fix FP for js/unsafe-jquery-plugin
|
2020-01-31 19:33:04 +01:00 |
|
Esben Sparre Andreasen
|
cfd567f01d
|
JS: fix FP for js/unsafe-jquery-plugin
|
2020-01-31 19:33:04 +01:00 |
|
Esben Sparre Andreasen
|
9e247921fc
|
JS: add FP tests for js/unsafe-jquery-plugin
|
2020-01-31 19:33:04 +01:00 |
|
Esben Sparre Andreasen
|
fef918ac13
|
JS: add query "Unsafe jQuery plugin"
|
2020-01-31 19:33:04 +01:00 |
|
Erik Krogh Kristensen
|
162c19c348
|
changes based on review
|
2020-01-30 14:04:04 +01:00 |
|
Erik Krogh Kristensen
|
6494649125
|
fix a number of FPs in js/exception-xss
|
2020-01-20 15:11:57 +01:00 |
|
Erik Krogh Kristensen
|
bf56797ad7
|
update expected output of tests
|
2019-12-17 16:27:55 +01:00 |
|
Erik Krogh Kristensen
|
7c931452d9
|
autoformat
|
2019-12-16 13:45:42 +01:00 |
|
Erik Krogh Kristensen
|
904976c7ac
|
update tests after removing control-flow checks from error-callbacks
|
2019-12-16 08:30:21 +01:00 |
|
Erik Krogh Kristensen
|
e164f46330
|
changes based on review feedback
|
2019-12-13 11:44:31 +01:00 |
|
Erik Krogh Kristensen
|
f35dc5d274
|
Merge remote-tracking branch 'upstream/master' into moarExceptions
|
2019-12-12 16:13:52 +01:00 |
|