github / github/codeql

JavaScript: Restricting `isSource` predicate leads to more alerts

Aberta
#7,790 1 comentário 0 reações 0 responsáveis Ver no GitHub
bug JS
Linguagem predominante
CodeQL
Estrelas
10.1k
Forks
2.1k
Merge médio
2d 15h
PRs com merge (30d)
141

Descrição

I have the following test file for the `UnvalidatedDynamicMethodCall` query:

```js
var express = require('express');
var app = express();

var actions = {
play(data) {
// ...
},
pause(data) {
// ...
}
}

app.get('/perform/:action/:payload', function(req, res) {
if (actions.hasOwnProperty(req.params.action)) {
let action = actions[req.params.action];
if (typeof action === 'function') {
res.end(action(req.params.payload));
return;
}
}
res.end("Unsupported action.");
});
```

Running the query on it (using CodeQL 2.7.6) does not flag an alert.

Now I change the `UnvalidatedDynamicMethCallQuery` library by adding the following conjunct in its `isSource` predicate:

```ql
(...) and
source.getStartLine() = 15
```

And suddenly I get an alert on the call to `action`.

Quite apart from the question of whether or not this alert is correct, I don't see how adding a conjunct to the `isSource` predicate, thereby making it smaller (in this particular case, one source instead of three), can lead to more alerts being reported.

Guia de contribuição

Abrir o guia de contribuição

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.