Skip to content

Commit 9e85afb

Browse files
committed
Update other test results in the same folder
1 parent 2b9c306 commit 9e85afb

File tree

4 files changed

+75
-4
lines changed

4 files changed

+75
-4
lines changed

java/ql/test/query-tests/security/CWE-089/semmle/examples/SqlConcatenated.expected

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,3 +10,8 @@
1010
| Test.java:108:47:108:61 | querySbToString | Query built by concatenation with $@, which may be untrusted. | Test.java:104:19:104:30 | categoryName | this expression |
1111
| Test.java:118:47:118:62 | querySb2ToString | Query built by concatenation with $@, which may be untrusted. | Test.java:114:46:114:57 | categoryName | this expression |
1212
| Test.java:221:81:221:111 | ... + ... | Query built by concatenation with $@, which may be untrusted. | Test.java:221:95:221:102 | category | this expression |
13+
| Test.java:236:48:236:52 | query | Query built by concatenation with $@, which may be untrusted. | Test.java:235:9:235:15 | tainted | this expression |
14+
| Test.java:246:48:246:52 | query | Query built by concatenation with $@, which may be untrusted. | Test.java:245:9:245:15 | tainted | this expression |
15+
| Test.java:257:48:257:52 | query | Query built by concatenation with $@, which may be untrusted. | Test.java:256:9:256:15 | tainted | this expression |
16+
| Test.java:268:48:268:52 | query | Query built by concatenation with $@, which may be untrusted. | Test.java:267:9:267:15 | tainted | this expression |
17+
| Test.java:281:48:281:52 | query | Query built by concatenation with $@, which may be untrusted. | Test.java:280:9:280:15 | tainted | this expression |

java/ql/test/query-tests/security/CWE-089/semmle/examples/controlledString.expected

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,40 @@
11
| <clinit> | 1 | Test.java:20:2:20:9 | FloorWax |
22
| <clinit> | 1 | Test.java:20:12:20:18 | Topping |
33
| <clinit> | 1 | Test.java:20:21:20:28 | Biscuits |
4+
| allowlist | 1 | Test.java:228:25:228:25 | 1 |
5+
| allowlist | 5 | Test.java:232:37:232:46 | "allowed1" |
6+
| allowlist | 5 | Test.java:232:49:232:58 | "allowed2" |
7+
| allowlist | 5 | Test.java:232:61:232:70 | "allowed3" |
8+
| allowlist | 6 | Test.java:233:7:233:33 | contains(...) |
9+
| allowlist | 7 | Test.java:234:20:234:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
10+
| allowlist | 8 | Test.java:235:19:235:36 | "' ORDER BY PRICE" |
11+
| allowlist | 15 | Test.java:242:37:242:46 | "allowed1" |
12+
| allowlist | 15 | Test.java:242:49:242:58 | "allowed2" |
13+
| allowlist | 15 | Test.java:242:66:242:66 | 2 |
14+
| allowlist | 16 | Test.java:243:7:243:33 | contains(...) |
15+
| allowlist | 17 | Test.java:244:20:244:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
16+
| allowlist | 18 | Test.java:245:19:245:36 | "' ORDER BY PRICE" |
17+
| allowlist | 25 | Test.java:252:29:252:38 | "allowed1" |
18+
| allowlist | 25 | Test.java:252:41:252:50 | "allowed2" |
19+
| allowlist | 25 | Test.java:252:53:252:62 | "allowed3" |
20+
| allowlist | 27 | Test.java:254:7:254:33 | contains(...) |
21+
| allowlist | 28 | Test.java:255:20:255:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
22+
| allowlist | 29 | Test.java:256:19:256:36 | "' ORDER BY PRICE" |
23+
| allowlist | 36 | Test.java:263:29:263:38 | "allowed1" |
24+
| allowlist | 36 | Test.java:263:41:263:50 | "allowed2" |
25+
| allowlist | 36 | Test.java:263:58:263:58 | 2 |
26+
| allowlist | 38 | Test.java:265:7:265:33 | contains(...) |
27+
| allowlist | 39 | Test.java:266:20:266:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
28+
| allowlist | 40 | Test.java:267:19:267:36 | "' ORDER BY PRICE" |
29+
| allowlist | 48 | Test.java:275:4:275:28 | add(...) |
30+
| allowlist | 48 | Test.java:275:18:275:27 | "allowed1" |
31+
| allowlist | 49 | Test.java:276:4:276:28 | add(...) |
32+
| allowlist | 49 | Test.java:276:18:276:27 | "allowed2" |
33+
| allowlist | 50 | Test.java:277:4:277:28 | add(...) |
34+
| allowlist | 50 | Test.java:277:18:277:27 | "allowed3" |
35+
| allowlist | 51 | Test.java:278:7:278:33 | contains(...) |
36+
| allowlist | 52 | Test.java:279:20:279:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
37+
| allowlist | 53 | Test.java:280:19:280:36 | "' ORDER BY PRICE" |
438
| bindingVars | 3 | Test.java:216:48:216:48 | 1 |
539
| bindingVars | 5 | Test.java:218:20:218:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
640
| bindingVars | 6 | Test.java:219:20:219:37 | "' ORDER BY PRICE" |

java/ql/test/query-tests/security/CWE-089/semmle/examples/endsInQuote.expected

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,8 @@
1+
| allowlist | 7 | Test.java:234:20:234:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
2+
| allowlist | 17 | Test.java:244:20:244:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
3+
| allowlist | 28 | Test.java:255:20:255:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
4+
| allowlist | 39 | Test.java:266:20:266:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
5+
| allowlist | 52 | Test.java:279:20:279:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
16
| bindingVars | 5 | Test.java:218:20:218:73 | "SELECT ITEM,PRICE FROM PRODUCT WHERE ITEM_CATEGORY='" |
27
| bindingVars | 7 | Test.java:220:11:220:16 | prefix |
38
| bindingVars | 8 | Test.java:221:34:221:39 | prefix |

java/ql/test/query-tests/security/CWE-089/semmle/examples/taintedString.expected

Lines changed: 31 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -64,10 +64,37 @@
6464
| Test.java:213:22:213:32 | bindingVars | 8 | Test.java:221:81:221:102 | ... + ... |
6565
| Test.java:213:22:213:32 | bindingVars | 8 | Test.java:221:81:221:111 | ... + ... |
6666
| Test.java:213:22:213:32 | bindingVars | 8 | Test.java:221:95:221:102 | category |
67-
| Test.java:227:21:227:24 | main | 1 | Test.java:228:11:228:14 | args |
68-
| Test.java:227:21:227:24 | main | 3 | Test.java:230:8:230:11 | args |
69-
| Test.java:227:21:227:24 | main | 5 | Test.java:232:14:232:17 | args |
70-
| Test.java:227:21:227:24 | main | 6 | Test.java:233:15:233:18 | args |
67+
| Test.java:227:22:227:30 | allowlist | 1 | Test.java:228:20:228:23 | args |
68+
| Test.java:227:22:227:30 | allowlist | 1 | Test.java:228:20:228:26 | ...[...] |
69+
| Test.java:227:22:227:30 | allowlist | 6 | Test.java:233:26:233:32 | tainted |
70+
| Test.java:227:22:227:30 | allowlist | 15 | Test.java:242:61:242:64 | args |
71+
| Test.java:227:22:227:30 | allowlist | 15 | Test.java:242:61:242:67 | ...[...] |
72+
| Test.java:227:22:227:30 | allowlist | 16 | Test.java:243:7:243:15 | allowlist |
73+
| Test.java:227:22:227:30 | allowlist | 16 | Test.java:243:26:243:32 | tainted |
74+
| Test.java:227:22:227:30 | allowlist | 17 | Test.java:244:20:245:15 | ... + ... |
75+
| Test.java:227:22:227:30 | allowlist | 17 | Test.java:244:20:245:36 | ... + ... |
76+
| Test.java:227:22:227:30 | allowlist | 18 | Test.java:245:9:245:15 | tainted |
77+
| Test.java:227:22:227:30 | allowlist | 19 | Test.java:246:48:246:52 | query |
78+
| Test.java:227:22:227:30 | allowlist | 27 | Test.java:254:26:254:32 | tainted |
79+
| Test.java:227:22:227:30 | allowlist | 36 | Test.java:263:53:263:56 | args |
80+
| Test.java:227:22:227:30 | allowlist | 36 | Test.java:263:53:263:59 | ...[...] |
81+
| Test.java:227:22:227:30 | allowlist | 37 | Test.java:264:37:264:48 | allowedArray |
82+
| Test.java:227:22:227:30 | allowlist | 38 | Test.java:265:7:265:15 | allowlist |
83+
| Test.java:227:22:227:30 | allowlist | 38 | Test.java:265:26:265:32 | tainted |
84+
| Test.java:227:22:227:30 | allowlist | 39 | Test.java:266:20:267:15 | ... + ... |
85+
| Test.java:227:22:227:30 | allowlist | 39 | Test.java:266:20:267:36 | ... + ... |
86+
| Test.java:227:22:227:30 | allowlist | 40 | Test.java:267:9:267:15 | tainted |
87+
| Test.java:227:22:227:30 | allowlist | 41 | Test.java:268:48:268:52 | query |
88+
| Test.java:227:22:227:30 | allowlist | 51 | Test.java:278:26:278:32 | tainted |
89+
| Test.java:227:22:227:30 | allowlist | 52 | Test.java:279:20:280:15 | ... + ... |
90+
| Test.java:227:22:227:30 | allowlist | 52 | Test.java:279:20:280:36 | ... + ... |
91+
| Test.java:227:22:227:30 | allowlist | 53 | Test.java:280:9:280:15 | tainted |
92+
| Test.java:227:22:227:30 | allowlist | 54 | Test.java:281:48:281:52 | query |
93+
| Test.java:286:21:286:24 | main | 1 | Test.java:287:11:287:14 | args |
94+
| Test.java:286:21:286:24 | main | 3 | Test.java:289:8:289:11 | args |
95+
| Test.java:286:21:286:24 | main | 5 | Test.java:291:14:291:17 | args |
96+
| Test.java:286:21:286:24 | main | 6 | Test.java:292:15:292:18 | args |
97+
| Test.java:286:21:286:24 | main | 7 | Test.java:293:13:293:16 | args |
7198
| Validation.java:6:21:6:35 | checkIdentifier | 1 | Validation.java:7:23:7:24 | id |
7299
| Validation.java:6:21:6:35 | checkIdentifier | 2 | Validation.java:8:13:8:14 | id |
73100
| Validation.java:6:21:6:35 | checkIdentifier | 2 | Validation.java:8:13:8:24 | charAt(...) |

0 commit comments

Comments
 (0)