github / github/codeql

Get full string for exported JavaScript results

Đang mở
#18,723 4 bình luận 0 reaction 0 người được giao Xem trên GitHub
question
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

Consider the query below, which attempts to get the callee and the associated parameters. The returned string for the parameters is often truncated (sanitized) when the length is longer than 20 characters [as seen in the source code](https://github.com/github/codeql/blob/7361ad977a5dd5252d21f5fd23de47d75b763651/javascript/extractor/src/com/semmle/js/extractor/TextualExtractor.java#L121). For instance, if the expected full string is `bd0be325-86d9-4f16-95fa-b677f7455177`, it returns something like `bd0be ... 5177`, which is not helpful for my project.

While there's a good reason for this behavior, I would really like to be able to export the full string for a follow-up analysis.

```
import javascript

from CallExpr call, Expr parameters
where
parameters = call.getArgument(_)

select call.getCallee(), parameters.toString()
```

I have seen a similar issue ([results abbreviation #9890](https://github.com/github/codeql/issues/9890)), but the suggestions do not address my problem.

I would really appreciate any support I can get here. Thank you.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Start with javascript/extractor/src/com/semmle/js/extractor/TextualExtractor.java at the linked line, then reproduce the query using parameters.toString() to observe the current truncation. Trace how exported result strings are sanitized and identify the relevant coverage for full-string output. Done means the query can export the complete parameter value without the current abbreviation, with behavior verified by an appropriate test or reproduction.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
javascript
Lĩnh vực
devtools
Loại issue
Tính năng
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.