@@ -31,6 +31,50 @@ endpoints
3131| index.js:28:13:28:28 | UNDEFINED_GLOBAL | NosqlInjection | isConstantExpression | false | boolean |
3232| index.js:28:13:28:28 | UNDEFINED_GLOBAL | NosqlInjection | isExcludedFromEndToEndEvaluation | false | boolean |
3333| index.js:28:13:28:28 | UNDEFINED_GLOBAL | NosqlInjection | sinkLabel | Sink | string |
34+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | NosqlInjection | hasFlowFromSource | false | boolean |
35+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | NosqlInjection | isConstantExpression | false | boolean |
36+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | NosqlInjection | isExcludedFromEndToEndEvaluation | false | boolean |
37+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | NosqlInjection | notASinkReason | ClientRequest | string |
38+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | NosqlInjection | notASinkReason | JQueryArgument | string |
39+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | NosqlInjection | sinkLabel | NotASink | string |
40+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | SqlInjection | hasFlowFromSource | false | boolean |
41+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | SqlInjection | isConstantExpression | false | boolean |
42+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | SqlInjection | isExcludedFromEndToEndEvaluation | false | boolean |
43+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | SqlInjection | notASinkReason | ClientRequest | string |
44+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | SqlInjection | notASinkReason | JQueryArgument | string |
45+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | SqlInjection | sinkLabel | NotASink | string |
46+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | TaintedPath | hasFlowFromSource | false | boolean |
47+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | TaintedPath | isConstantExpression | false | boolean |
48+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | TaintedPath | isExcludedFromEndToEndEvaluation | false | boolean |
49+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | TaintedPath | notASinkReason | ClientRequest | string |
50+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | TaintedPath | notASinkReason | JQueryArgument | string |
51+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | TaintedPath | sinkLabel | NotASink | string |
52+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | Xss | hasFlowFromSource | false | boolean |
53+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | Xss | isConstantExpression | false | boolean |
54+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | Xss | isExcludedFromEndToEndEvaluation | false | boolean |
55+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | Xss | notASinkReason | ClientRequest | string |
56+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | Xss | notASinkReason | JQueryArgument | string |
57+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | Xss | sinkLabel | NotASink | string |
58+ | index.js:84:12:84:18 | foo.bar | NosqlInjection | hasFlowFromSource | false | boolean |
59+ | index.js:84:12:84:18 | foo.bar | NosqlInjection | isConstantExpression | false | boolean |
60+ | index.js:84:12:84:18 | foo.bar | NosqlInjection | isExcludedFromEndToEndEvaluation | false | boolean |
61+ | index.js:84:12:84:18 | foo.bar | NosqlInjection | notASinkReason | ClientRequest | string |
62+ | index.js:84:12:84:18 | foo.bar | NosqlInjection | sinkLabel | NotASink | string |
63+ | index.js:84:12:84:18 | foo.bar | SqlInjection | hasFlowFromSource | false | boolean |
64+ | index.js:84:12:84:18 | foo.bar | SqlInjection | isConstantExpression | false | boolean |
65+ | index.js:84:12:84:18 | foo.bar | SqlInjection | isExcludedFromEndToEndEvaluation | false | boolean |
66+ | index.js:84:12:84:18 | foo.bar | SqlInjection | notASinkReason | ClientRequest | string |
67+ | index.js:84:12:84:18 | foo.bar | SqlInjection | sinkLabel | NotASink | string |
68+ | index.js:84:12:84:18 | foo.bar | TaintedPath | hasFlowFromSource | false | boolean |
69+ | index.js:84:12:84:18 | foo.bar | TaintedPath | isConstantExpression | false | boolean |
70+ | index.js:84:12:84:18 | foo.bar | TaintedPath | isExcludedFromEndToEndEvaluation | false | boolean |
71+ | index.js:84:12:84:18 | foo.bar | TaintedPath | notASinkReason | ClientRequest | string |
72+ | index.js:84:12:84:18 | foo.bar | TaintedPath | sinkLabel | NotASink | string |
73+ | index.js:84:12:84:18 | foo.bar | Xss | hasFlowFromSource | false | boolean |
74+ | index.js:84:12:84:18 | foo.bar | Xss | isConstantExpression | false | boolean |
75+ | index.js:84:12:84:18 | foo.bar | Xss | isExcludedFromEndToEndEvaluation | false | boolean |
76+ | index.js:84:12:84:18 | foo.bar | Xss | notASinkReason | ClientRequest | string |
77+ | index.js:84:12:84:18 | foo.bar | Xss | sinkLabel | NotASink | string |
3478tokenFeatures
3579| index.js:9:15:9:45 | { 'isAd ... Admin } | argumentIndex | 0 |
3680| index.js:9:15:9:45 | { 'isAd ... Admin } | calleeAccessPath | mongoose model find |
@@ -64,3 +108,19 @@ tokenFeatures
64108| index.js:28:13:28:28 | UNDEFINED_GLOBAL | enclosingFunctionBody | User find UNDEFINED_GLOBAL |
65109| index.js:28:13:28:28 | UNDEFINED_GLOBAL | enclosingFunctionName | notConstantExpression |
66110| index.js:28:13:28:28 | UNDEFINED_GLOBAL | receiverName | User |
111+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | argumentIndex | 0 |
112+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | calleeAccessPath | |
113+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | calleeAccessPathWithStructuralInfo | |
114+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | calleeApiName | |
115+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | calleeName | ajax |
116+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | enclosingFunctionBody | foo $ ajax url foo bar |
117+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | enclosingFunctionName | effectiveSinkAndNotASink |
118+ | index.js:83:10:85:3 | {\\n " ... ar,\\n } | receiverName | $ |
119+ | index.js:84:12:84:18 | foo.bar | argumentIndex | |
120+ | index.js:84:12:84:18 | foo.bar | calleeAccessPath | |
121+ | index.js:84:12:84:18 | foo.bar | calleeAccessPathWithStructuralInfo | |
122+ | index.js:84:12:84:18 | foo.bar | calleeApiName | |
123+ | index.js:84:12:84:18 | foo.bar | calleeName | |
124+ | index.js:84:12:84:18 | foo.bar | enclosingFunctionBody | foo $ ajax url foo bar |
125+ | index.js:84:12:84:18 | foo.bar | enclosingFunctionName | effectiveSinkAndNotASink |
126+ | index.js:84:12:84:18 | foo.bar | receiverName | |
0 commit comments