github / github/codeql

JavaScript: Restricting `isSource` predicate leads to more alerts

Đang mở
#7,790 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
bug JS
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

I have the following test file for the `UnvalidatedDynamicMethodCall` query:

```js
var express = require('express');
var app = express();

var actions = {
play(data) {
// ...
},
pause(data) {
// ...
}
}

app.get('/perform/:action/:payload', function(req, res) {
if (actions.hasOwnProperty(req.params.action)) {
let action = actions[req.params.action];
if (typeof action === 'function') {
res.end(action(req.params.payload));
return;
}
}
res.end("Unsupported action.");
});
```

Running the query on it (using CodeQL 2.7.6) does not flag an alert.

Now I change the `UnvalidatedDynamicMethCallQuery` library by adding the following conjunct in its `isSource` predicate:

```ql
(...) and
source.getStartLine() = 15
```

And suddenly I get an alert on the call to `action`.

Quite apart from the question of whether or not this alert is correct, I don't see how adding a conjunct to the `isSource` predicate, thereby making it smaller (in this particular case, one source instead of three), can lead to more alerts being reported.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.