Skip to content

Commit bf56797

Browse files
committed
update expected output of tests
1 parent 9dd7d1c commit bf56797

File tree

4 files changed

+16
-25
lines changed

4 files changed

+16
-25
lines changed

javascript/ql/test/query-tests/Security/CWE-079/ExceptionXss.expected

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -76,10 +76,6 @@ nodes
7676
| exception-xss.js:154:11:154:11 | e |
7777
| exception-xss.js:155:18:155:18 | e |
7878
| exception-xss.js:155:18:155:18 | e |
79-
| exception-xss.js:159:13:159:15 | foo |
80-
| exception-xss.js:160:11:160:11 | e |
81-
| exception-xss.js:161:18:161:18 | e |
82-
| exception-xss.js:161:18:161:18 | e |
8379
| exception-xss.js:174:25:174:43 | exceptional return of inner(foo, resolve) |
8480
| exception-xss.js:174:31:174:33 | foo |
8581
| exception-xss.js:174:53:174:53 | e |
@@ -164,7 +160,6 @@ edges
164160
| exception-xss.js:136:26:136:30 | error | exception-xss.js:138:19:138:23 | error |
165161
| exception-xss.js:146:6:146:35 | foo | exception-xss.js:148:33:148:35 | foo |
166162
| exception-xss.js:146:6:146:35 | foo | exception-xss.js:153:8:153:10 | foo |
167-
| exception-xss.js:146:6:146:35 | foo | exception-xss.js:159:13:159:15 | foo |
168163
| exception-xss.js:146:6:146:35 | foo | exception-xss.js:174:31:174:33 | foo |
169164
| exception-xss.js:146:12:146:28 | document.location | exception-xss.js:146:12:146:35 | documen ... .search |
170165
| exception-xss.js:146:12:146:28 | document.location | exception-xss.js:146:12:146:35 | documen ... .search |
@@ -175,9 +170,6 @@ edges
175170
| exception-xss.js:153:8:153:10 | foo | exception-xss.js:154:11:154:11 | e |
176171
| exception-xss.js:154:11:154:11 | e | exception-xss.js:155:18:155:18 | e |
177172
| exception-xss.js:154:11:154:11 | e | exception-xss.js:155:18:155:18 | e |
178-
| exception-xss.js:159:13:159:15 | foo | exception-xss.js:160:11:160:11 | e |
179-
| exception-xss.js:160:11:160:11 | e | exception-xss.js:161:18:161:18 | e |
180-
| exception-xss.js:160:11:160:11 | e | exception-xss.js:161:18:161:18 | e |
181173
| exception-xss.js:174:25:174:43 | exceptional return of inner(foo, resolve) | exception-xss.js:174:53:174:53 | e |
182174
| exception-xss.js:174:31:174:33 | foo | exception-xss.js:174:25:174:43 | exceptional return of inner(foo, resolve) |
183175
| exception-xss.js:174:53:174:53 | e | exception-xss.js:175:18:175:18 | e |
@@ -209,7 +201,6 @@ edges
209201
| exception-xss.js:138:19:138:23 | error | exception-xss.js:136:10:136:22 | req.params.id | exception-xss.js:138:19:138:23 | error | Cross-site scripting vulnerability due to $@. | exception-xss.js:136:10:136:22 | req.params.id | user-provided value |
210202
| exception-xss.js:149:18:149:18 | e | exception-xss.js:146:12:146:28 | document.location | exception-xss.js:149:18:149:18 | e | Cross-site scripting vulnerability due to $@. | exception-xss.js:146:12:146:28 | document.location | user-provided value |
211203
| exception-xss.js:155:18:155:18 | e | exception-xss.js:146:12:146:28 | document.location | exception-xss.js:155:18:155:18 | e | Cross-site scripting vulnerability due to $@. | exception-xss.js:146:12:146:28 | document.location | user-provided value |
212-
| exception-xss.js:161:18:161:18 | e | exception-xss.js:146:12:146:28 | document.location | exception-xss.js:161:18:161:18 | e | Cross-site scripting vulnerability due to $@. | exception-xss.js:146:12:146:28 | document.location | user-provided value |
213204
| exception-xss.js:175:18:175:18 | e | exception-xss.js:146:12:146:28 | document.location | exception-xss.js:175:18:175:18 | e | Cross-site scripting vulnerability due to $@. | exception-xss.js:146:12:146:28 | document.location | user-provided value |
214205
| exception-xss.js:182:19:182:23 | error | exception-xss.js:180:10:180:22 | req.params.id | exception-xss.js:182:19:182:23 | error | Cross-site scripting vulnerability due to $@. | exception-xss.js:180:10:180:22 | req.params.id | user-provided value |
215206
| tst.js:306:20:306:20 | e | tst.js:304:9:304:16 | location | tst.js:306:20:306:20 | e | Cross-site scripting vulnerability due to $@. | tst.js:304:9:304:16 | location | user-provided value |

javascript/ql/test/query-tests/Security/CWE-079/Xss.expected

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -15,9 +15,9 @@ nodes
1515
| addEventListener.js:12:24:12:28 | event |
1616
| addEventListener.js:12:24:12:33 | event.data |
1717
| addEventListener.js:12:24:12:33 | event.data |
18-
| exception-xss.js:2:9:2:31 | foo |
19-
| exception-xss.js:2:15:2:31 | document.location |
20-
| exception-xss.js:2:15:2:31 | document.location |
18+
| exception-xss.js:2:6:2:28 | foo |
19+
| exception-xss.js:2:12:2:28 | document.location |
20+
| exception-xss.js:2:12:2:28 | document.location |
2121
| exception-xss.js:86:17:86:19 | foo |
2222
| exception-xss.js:86:17:86:19 | foo |
2323
| jquery.js:2:7:2:40 | tainted |
@@ -368,10 +368,10 @@ edges
368368
| addEventListener.js:10:21:10:25 | event | addEventListener.js:12:24:12:28 | event |
369369
| addEventListener.js:12:24:12:28 | event | addEventListener.js:12:24:12:33 | event.data |
370370
| addEventListener.js:12:24:12:28 | event | addEventListener.js:12:24:12:33 | event.data |
371-
| exception-xss.js:2:9:2:31 | foo | exception-xss.js:86:17:86:19 | foo |
372-
| exception-xss.js:2:9:2:31 | foo | exception-xss.js:86:17:86:19 | foo |
373-
| exception-xss.js:2:15:2:31 | document.location | exception-xss.js:2:9:2:31 | foo |
374-
| exception-xss.js:2:15:2:31 | document.location | exception-xss.js:2:9:2:31 | foo |
371+
| exception-xss.js:2:6:2:28 | foo | exception-xss.js:86:17:86:19 | foo |
372+
| exception-xss.js:2:6:2:28 | foo | exception-xss.js:86:17:86:19 | foo |
373+
| exception-xss.js:2:12:2:28 | document.location | exception-xss.js:2:6:2:28 | foo |
374+
| exception-xss.js:2:12:2:28 | document.location | exception-xss.js:2:6:2:28 | foo |
375375
| jquery.js:2:7:2:40 | tainted | jquery.js:4:5:4:11 | tainted |
376376
| jquery.js:2:7:2:40 | tainted | jquery.js:4:5:4:11 | tainted |
377377
| jquery.js:2:7:2:40 | tainted | jquery.js:7:20:7:26 | tainted |
@@ -665,7 +665,7 @@ edges
665665
| addEventListener.js:2:20:2:29 | event.data | addEventListener.js:1:43:1:47 | event | addEventListener.js:2:20:2:29 | event.data | Cross-site scripting vulnerability due to $@. | addEventListener.js:1:43:1:47 | event | user-provided value |
666666
| addEventListener.js:6:20:6:23 | data | addEventListener.js:5:43:5:48 | {data} | addEventListener.js:6:20:6:23 | data | Cross-site scripting vulnerability due to $@. | addEventListener.js:5:43:5:48 | {data} | user-provided value |
667667
| addEventListener.js:12:24:12:33 | event.data | addEventListener.js:10:21:10:25 | event | addEventListener.js:12:24:12:33 | event.data | Cross-site scripting vulnerability due to $@. | addEventListener.js:10:21:10:25 | event | user-provided value |
668-
| exception-xss.js:86:17:86:19 | foo | exception-xss.js:2:15:2:31 | document.location | exception-xss.js:86:17:86:19 | foo | Cross-site scripting vulnerability due to $@. | exception-xss.js:2:15:2:31 | document.location | user-provided value |
668+
| exception-xss.js:86:17:86:19 | foo | exception-xss.js:2:12:2:28 | document.location | exception-xss.js:86:17:86:19 | foo | Cross-site scripting vulnerability due to $@. | exception-xss.js:2:12:2:28 | document.location | user-provided value |
669669
| jquery.js:4:5:4:11 | tainted | jquery.js:2:17:2:33 | document.location | jquery.js:4:5:4:11 | tainted | Cross-site scripting vulnerability due to $@. | jquery.js:2:17:2:33 | document.location | user-provided value |
670670
| jquery.js:7:5:7:34 | "<div i ... + "\\">" | jquery.js:2:17:2:33 | document.location | jquery.js:7:5:7:34 | "<div i ... + "\\">" | Cross-site scripting vulnerability due to $@. | jquery.js:2:17:2:33 | document.location | user-provided value |
671671
| jquery.js:8:18:8:34 | "XSS: " + tainted | jquery.js:2:17:2:33 | document.location | jquery.js:8:18:8:34 | "XSS: " + tainted | Cross-site scripting vulnerability due to $@. | jquery.js:2:17:2:33 | document.location | user-provided value |

javascript/ql/test/query-tests/Security/CWE-079/XssWithAdditionalSources.expected

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -15,9 +15,9 @@ nodes
1515
| addEventListener.js:12:24:12:28 | event |
1616
| addEventListener.js:12:24:12:33 | event.data |
1717
| addEventListener.js:12:24:12:33 | event.data |
18-
| exception-xss.js:2:9:2:31 | foo |
19-
| exception-xss.js:2:15:2:31 | document.location |
20-
| exception-xss.js:2:15:2:31 | document.location |
18+
| exception-xss.js:2:6:2:28 | foo |
19+
| exception-xss.js:2:12:2:28 | document.location |
20+
| exception-xss.js:2:12:2:28 | document.location |
2121
| exception-xss.js:86:17:86:19 | foo |
2222
| exception-xss.js:86:17:86:19 | foo |
2323
| jquery.js:2:7:2:40 | tainted |
@@ -372,10 +372,10 @@ edges
372372
| addEventListener.js:10:21:10:25 | event | addEventListener.js:12:24:12:28 | event |
373373
| addEventListener.js:12:24:12:28 | event | addEventListener.js:12:24:12:33 | event.data |
374374
| addEventListener.js:12:24:12:28 | event | addEventListener.js:12:24:12:33 | event.data |
375-
| exception-xss.js:2:9:2:31 | foo | exception-xss.js:86:17:86:19 | foo |
376-
| exception-xss.js:2:9:2:31 | foo | exception-xss.js:86:17:86:19 | foo |
377-
| exception-xss.js:2:15:2:31 | document.location | exception-xss.js:2:9:2:31 | foo |
378-
| exception-xss.js:2:15:2:31 | document.location | exception-xss.js:2:9:2:31 | foo |
375+
| exception-xss.js:2:6:2:28 | foo | exception-xss.js:86:17:86:19 | foo |
376+
| exception-xss.js:2:6:2:28 | foo | exception-xss.js:86:17:86:19 | foo |
377+
| exception-xss.js:2:12:2:28 | document.location | exception-xss.js:2:6:2:28 | foo |
378+
| exception-xss.js:2:12:2:28 | document.location | exception-xss.js:2:6:2:28 | foo |
379379
| jquery.js:2:7:2:40 | tainted | jquery.js:4:5:4:11 | tainted |
380380
| jquery.js:2:7:2:40 | tainted | jquery.js:4:5:4:11 | tainted |
381381
| jquery.js:2:7:2:40 | tainted | jquery.js:7:20:7:26 | tainted |

javascript/ql/test/query-tests/Security/CWE-079/exception-xss.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -158,7 +158,7 @@ app.get('/user/:id', function (req, res) {
158158
try {
159159
unknown()[foo];
160160
} catch (e) {
161-
$('myId').html(e); // NOT OK
161+
$('myId').html(e); // OK. We are not sure that `unknown()` is null-ish.
162162
}
163163

164164
try {

0 commit comments

Comments
 (0)