github / github/codeql

JavaScript: Restricting `isSource` predicate leads to more alerts

未關閉
#7,790 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
bug JS
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

I have the following test file for the `UnvalidatedDynamicMethodCall` query:

```js
var express = require('express');
var app = express();

var actions = {
play(data) {
// ...
},
pause(data) {
// ...
}
}

app.get('/perform/:action/:payload', function(req, res) {
if (actions.hasOwnProperty(req.params.action)) {
let action = actions[req.params.action];
if (typeof action === 'function') {
res.end(action(req.params.payload));
return;
}
}
res.end("Unsupported action.");
});
```

Running the query on it (using CodeQL 2.7.6) does not flag an alert.

Now I change the `UnvalidatedDynamicMethCallQuery` library by adding the following conjunct in its `isSource` predicate:

```ql
(...) and
source.getStartLine() = 15
```

And suddenly I get an alert on the call to `action`.

Quite apart from the question of whether or not this alert is correct, I don't see how adding a conjunct to the `isSource` predicate, thereby making it smaller (in this particular case, one source instead of three), can lead to more alerts being reported.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。