Skip to content

Commit 210e71c

Browse files
committed
update expected output
1 parent 02c8253 commit 210e71c

2 files changed

Lines changed: 39 additions & 0 deletions

File tree

javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/CodeInjection.expected

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,16 @@ nodes
6969
| bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) |
7070
| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") |
7171
| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") |
72+
| bad-code-sanitization.js:56:7:56:47 | taint |
73+
| bad-code-sanitization.js:56:15:56:36 | [req.bo ... "foo"] |
74+
| bad-code-sanitization.js:56:15:56:47 | [req.bo ... n("\\n") |
75+
| bad-code-sanitization.js:56:16:56:23 | req.body |
76+
| bad-code-sanitization.js:56:16:56:23 | req.body |
77+
| bad-code-sanitization.js:56:16:56:28 | req.body.name |
78+
| bad-code-sanitization.js:58:14:58:53 | `(funct ... nt)}))` |
79+
| bad-code-sanitization.js:58:14:58:53 | `(funct ... nt)}))` |
80+
| bad-code-sanitization.js:58:29:58:49 | JSON.st ... (taint) |
81+
| bad-code-sanitization.js:58:44:58:48 | taint |
7282
| express.js:7:24:7:69 | "return ... + "];" |
7383
| express.js:7:24:7:69 | "return ... + "];" |
7484
| express.js:7:44:7:62 | req.param("wobble") |
@@ -202,6 +212,15 @@ edges
202212
| bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) | bad-code-sanitization.js:54:14:54:67 | `(funct ... "))}))` |
203213
| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) |
204214
| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) |
215+
| bad-code-sanitization.js:56:7:56:47 | taint | bad-code-sanitization.js:58:44:58:48 | taint |
216+
| bad-code-sanitization.js:56:15:56:36 | [req.bo ... "foo"] | bad-code-sanitization.js:56:15:56:47 | [req.bo ... n("\\n") |
217+
| bad-code-sanitization.js:56:15:56:47 | [req.bo ... n("\\n") | bad-code-sanitization.js:56:7:56:47 | taint |
218+
| bad-code-sanitization.js:56:16:56:23 | req.body | bad-code-sanitization.js:56:16:56:28 | req.body.name |
219+
| bad-code-sanitization.js:56:16:56:23 | req.body | bad-code-sanitization.js:56:16:56:28 | req.body.name |
220+
| bad-code-sanitization.js:56:16:56:28 | req.body.name | bad-code-sanitization.js:56:15:56:36 | [req.bo ... "foo"] |
221+
| bad-code-sanitization.js:58:29:58:49 | JSON.st ... (taint) | bad-code-sanitization.js:58:14:58:53 | `(funct ... nt)}))` |
222+
| bad-code-sanitization.js:58:29:58:49 | JSON.st ... (taint) | bad-code-sanitization.js:58:14:58:53 | `(funct ... nt)}))` |
223+
| bad-code-sanitization.js:58:44:58:48 | taint | bad-code-sanitization.js:58:29:58:49 | JSON.st ... (taint) |
205224
| express.js:7:44:7:62 | req.param("wobble") | express.js:7:24:7:69 | "return ... + "];" |
206225
| express.js:7:44:7:62 | req.param("wobble") | express.js:7:24:7:69 | "return ... + "];" |
207226
| express.js:7:44:7:62 | req.param("wobble") | express.js:7:24:7:69 | "return ... + "];" |
@@ -271,6 +290,7 @@ edges
271290
| angularjs.js:50:22:50:36 | location.search | angularjs.js:50:22:50:29 | location | angularjs.js:50:22:50:36 | location.search | $@ flows to here and is interpreted as code. | angularjs.js:50:22:50:29 | location | User-provided value |
272291
| angularjs.js:53:32:53:46 | location.search | angularjs.js:53:32:53:39 | location | angularjs.js:53:32:53:46 | location.search | $@ flows to here and is interpreted as code. | angularjs.js:53:32:53:39 | location | User-provided value |
273292
| bad-code-sanitization.js:54:14:54:67 | `(funct ... "))}))` | bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | bad-code-sanitization.js:54:14:54:67 | `(funct ... "))}))` | $@ flows to here and is interpreted as code. | bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | User-provided value |
293+
| bad-code-sanitization.js:58:14:58:53 | `(funct ... nt)}))` | bad-code-sanitization.js:56:16:56:23 | req.body | bad-code-sanitization.js:58:14:58:53 | `(funct ... nt)}))` | $@ flows to here and is interpreted as code. | bad-code-sanitization.js:56:16:56:23 | req.body | User-provided value |
274294
| express.js:7:24:7:69 | "return ... + "];" | express.js:7:44:7:62 | req.param("wobble") | express.js:7:24:7:69 | "return ... + "];" | $@ flows to here and is interpreted as code. | express.js:7:44:7:62 | req.param("wobble") | User-provided value |
275295
| express.js:9:34:9:79 | "return ... + "];" | express.js:9:54:9:72 | req.param("wobble") | express.js:9:34:9:79 | "return ... + "];" | $@ flows to here and is interpreted as code. | express.js:9:54:9:72 | req.param("wobble") | User-provided value |
276296
| express.js:12:8:12:53 | "return ... + "];" | express.js:12:28:12:46 | req.param("wobble") | express.js:12:8:12:53 | "return ... + "];" | $@ flows to here and is interpreted as code. | express.js:12:28:12:46 | req.param("wobble") | User-provided value |

javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/HeuristicSourceCodeInjection.expected

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,16 @@ nodes
6969
| bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) |
7070
| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") |
7171
| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") |
72+
| bad-code-sanitization.js:56:7:56:47 | taint |
73+
| bad-code-sanitization.js:56:15:56:36 | [req.bo ... "foo"] |
74+
| bad-code-sanitization.js:56:15:56:47 | [req.bo ... n("\\n") |
75+
| bad-code-sanitization.js:56:16:56:23 | req.body |
76+
| bad-code-sanitization.js:56:16:56:23 | req.body |
77+
| bad-code-sanitization.js:56:16:56:28 | req.body.name |
78+
| bad-code-sanitization.js:58:14:58:53 | `(funct ... nt)}))` |
79+
| bad-code-sanitization.js:58:14:58:53 | `(funct ... nt)}))` |
80+
| bad-code-sanitization.js:58:29:58:49 | JSON.st ... (taint) |
81+
| bad-code-sanitization.js:58:44:58:48 | taint |
7282
| eslint-escope-build.js:20:22:20:22 | c |
7383
| eslint-escope-build.js:20:22:20:22 | c |
7484
| eslint-escope-build.js:21:16:21:16 | c |
@@ -206,6 +216,15 @@ edges
206216
| bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) | bad-code-sanitization.js:54:14:54:67 | `(funct ... "))}))` |
207217
| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) |
208218
| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) |
219+
| bad-code-sanitization.js:56:7:56:47 | taint | bad-code-sanitization.js:58:44:58:48 | taint |
220+
| bad-code-sanitization.js:56:15:56:36 | [req.bo ... "foo"] | bad-code-sanitization.js:56:15:56:47 | [req.bo ... n("\\n") |
221+
| bad-code-sanitization.js:56:15:56:47 | [req.bo ... n("\\n") | bad-code-sanitization.js:56:7:56:47 | taint |
222+
| bad-code-sanitization.js:56:16:56:23 | req.body | bad-code-sanitization.js:56:16:56:28 | req.body.name |
223+
| bad-code-sanitization.js:56:16:56:23 | req.body | bad-code-sanitization.js:56:16:56:28 | req.body.name |
224+
| bad-code-sanitization.js:56:16:56:28 | req.body.name | bad-code-sanitization.js:56:15:56:36 | [req.bo ... "foo"] |
225+
| bad-code-sanitization.js:58:29:58:49 | JSON.st ... (taint) | bad-code-sanitization.js:58:14:58:53 | `(funct ... nt)}))` |
226+
| bad-code-sanitization.js:58:29:58:49 | JSON.st ... (taint) | bad-code-sanitization.js:58:14:58:53 | `(funct ... nt)}))` |
227+
| bad-code-sanitization.js:58:44:58:48 | taint | bad-code-sanitization.js:58:29:58:49 | JSON.st ... (taint) |
209228
| eslint-escope-build.js:20:22:20:22 | c | eslint-escope-build.js:21:16:21:16 | c |
210229
| eslint-escope-build.js:20:22:20:22 | c | eslint-escope-build.js:21:16:21:16 | c |
211230
| eslint-escope-build.js:20:22:20:22 | c | eslint-escope-build.js:21:16:21:16 | c |

0 commit comments

Comments
 (0)