Skip to content
Closed
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
fix qldoc
  • Loading branch information
am0o0 committed Sep 22, 2023
commit 90a14bf38a2c5962c45e381ed5969b29c57c3070
20 changes: 2 additions & 18 deletions javascript/ql/lib/semmle/javascript/frameworks/Execa.qll
Original file line number Diff line number Diff line change
Expand Up @@ -6,21 +6,6 @@ import javascript
import semmle.javascript.security.dataflow.RequestForgeryCustomizations
import semmle.javascript.security.dataflow.UrlConcatenation

/**
* The dynamic import expression input can be a `data:` URL which loads any module from that data
*/
class DynamicImport extends SystemCommandExecution, DataFlow::ExprNode {
DynamicImport() { this = any(DynamicImportExpr e).getAChildExpr().flow() }

override DataFlow::Node getACommandArgument() { result = this }

override predicate isShellInterpreted(DataFlow::Node arg) { none() }

override predicate isSync() { none() }

override DataFlow::Node getOptionsArg() { none() }
}

/**
* Provide model for [Execa](https://github.com/sindresorhus/execa) package
*/
Expand Down Expand Up @@ -225,7 +210,7 @@ module Execa {
}
}

// Holds if left parameter is the the left child of a template literal and returns the template literal
// Holds if left parameter is the left child of a template literal and returns the template literal
private TemplateLiteral templateLiteralChildAsSink(Expr left) {
exists(TaggedTemplateExpr parent |
parent.getTemplate() = result and
Expand All @@ -235,8 +220,7 @@ module Execa {

// Holds whether Execa has shell enabled options or not, get Parameter responsible for options
private predicate isExecaShellEnable(API::Node n) {
n.getMember("shell").asSink().asExpr().(BooleanLiteral).getValue() = "true" and
exists(n.getMember("shell"))
n.getMember("shell").asSink().asExpr().(BooleanLiteral).getValue() = "true"
}

// Holds whether Execa has shell enabled options or not, get Parameter responsible for options
Expand Down
15 changes: 15 additions & 0 deletions javascript/ql/lib/semmle/javascript/frameworks/NodeJSLib.qll
Original file line number Diff line number Diff line change
Expand Up @@ -760,6 +760,21 @@ module NodeJSLib {
}
}

/**
* The dynamic import expression input can be a `data:` URL which loads any module from that data
*/
class DynamicImport extends SystemCommandExecution, DataFlow::ExprNode {
DynamicImport() { this = any(DynamicImportExpr e).getAChildExpr().flow() }

override DataFlow::Node getACommandArgument() { result = this }

override predicate isShellInterpreted(DataFlow::Node arg) { arg = this }

override predicate isSync() { none() }

override DataFlow::Node getOptionsArg() { none() }
}

/**
* A call to a method from module `child_process`.
*/
Expand Down
2 changes: 0 additions & 2 deletions javascript/ql/lib/semmle/javascript/frameworks/ShellJS.qll
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,6 @@ module ShellJS {
.getReturn()
}

API::Node test() { result = API::moduleImport("shelljs").getASuccessor*() }

/**
* Gets an import of the `shelljs` or `async-shelljs` module.
*/
Expand Down