Skip to content

JS: Add model for needle in ClientRequests.qll#4348

Merged
codeql-ci merged 4 commits into
github:mainfrom
erik-krogh:needle
Sep 29, 2020
Merged

JS: Add model for needle in ClientRequests.qll#4348
codeql-ci merged 4 commits into
github:mainfrom
erik-krogh:needle

Conversation

@erik-krogh
Copy link
Copy Markdown
Contributor

Inspired by this benchmark.

With this PR we get a TP for js/request-forgery in that benchmark.

@github-actions github-actions Bot added the JS label Sep 25, 2020
@erik-krogh erik-krogh marked this pull request as ready for review September 28, 2020 19:23
@erik-krogh erik-krogh requested a review from a team as a code owner September 28, 2020 19:23
Copy link
Copy Markdown
Contributor

@esbena esbena left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, except for two minor bits:

  • We should be able to use getLastArgument() in two places.
  • We are also missing the change-note.

Comment thread javascript/ql/src/semmle/javascript/frameworks/ClientRequests.qll Outdated
Comment thread javascript/ql/src/semmle/javascript/frameworks/ClientRequests.qll Outdated
@codeql-ci codeql-ci merged commit 910c19e into github:main Sep 29, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants