|
1 | 1 | import javascript |
2 | 2 | private import semmle.javascript.dataflow.internal.StepSummary |
| 3 | +import testUtilities.LegacyDataFlowDiff |
3 | 4 |
|
4 | | -class Configuration extends DataFlow::Configuration { |
5 | | - Configuration() { this = "PromiseDataFlowFlowTestingConfig" } |
6 | | - |
7 | | - override predicate isSource(DataFlow::Node source) { |
| 5 | +module ValueFlowConfig implements DataFlow::ConfigSig { |
| 6 | + predicate isSource(DataFlow::Node source) { |
8 | 7 | source.getEnclosingExpr().getStringValue() = "source" |
9 | 8 | } |
10 | 9 |
|
11 | | - override predicate isSink(DataFlow::Node sink) { |
| 10 | + predicate isSink(DataFlow::Node sink) { |
12 | 11 | any(DataFlow::InvokeNode call | call.getCalleeName() = "sink").getAnArgument() = sink |
13 | 12 | } |
14 | 13 | } |
15 | 14 |
|
16 | | -class TaintConfig extends TaintTracking::Configuration { |
17 | | - TaintConfig() { this = "PromiseTaintFlowTestingConfig" } |
| 15 | +module ValueFlow = DataFlow::Global<ValueFlowConfig>; |
18 | 16 |
|
19 | | - override predicate isSource(DataFlow::Node source) { |
| 17 | +module TaintConfig implements DataFlow::ConfigSig { |
| 18 | + predicate isSource(DataFlow::Node source) { |
20 | 19 | source.getEnclosingExpr().getStringValue() = "source" |
21 | 20 | } |
22 | 21 |
|
23 | | - override predicate isSink(DataFlow::Node sink) { |
| 22 | + predicate isSink(DataFlow::Node sink) { |
24 | 23 | any(DataFlow::InvokeNode call | call.getCalleeName() = "sink").getAnArgument() = sink |
25 | 24 | } |
26 | 25 | } |
27 | 26 |
|
28 | | -query predicate flow(DataFlow::Node source, DataFlow::Node sink) { |
29 | | - any(Configuration c).hasFlow(source, sink) |
30 | | -} |
| 27 | +module TaintFlow = TaintTracking::Global<TaintConfig>; |
| 28 | + |
| 29 | +query predicate flow(DataFlow::Node source, DataFlow::Node sink) { ValueFlow::flow(source, sink) } |
31 | 30 |
|
32 | 31 | query predicate exclusiveTaintFlow(DataFlow::Node source, DataFlow::Node sink) { |
33 | | - not any(Configuration c).hasFlow(source, sink) and |
34 | | - any(TaintConfig c).hasFlow(source, sink) |
| 32 | + not ValueFlow::flow(source, sink) and |
| 33 | + TaintFlow::flow(source, sink) |
35 | 34 | } |
36 | 35 |
|
37 | 36 | query predicate typetrack(DataFlow::SourceNode succ, DataFlow::SourceNode pred, StepSummary summary) { |
38 | 37 | succ = PromiseTypeTracking::promiseStep(pred, summary) |
39 | 38 | } |
| 39 | + |
| 40 | +class LegacyValueConfig extends DataFlow::Configuration { |
| 41 | + LegacyValueConfig() { this = "LegacyValueConfig" } |
| 42 | + |
| 43 | + override predicate isSource(DataFlow::Node source) { ValueFlowConfig::isSource(source) } |
| 44 | + |
| 45 | + override predicate isSink(DataFlow::Node sink) { ValueFlowConfig::isSink(sink) } |
| 46 | +} |
| 47 | + |
| 48 | +query predicate valueFlowDifference = |
| 49 | + DataFlowDiff<ValueFlow, LegacyValueConfig>::legacyDataFlowDifference/3; |
| 50 | + |
| 51 | +class LegacyTaintConfig extends TaintTracking::Configuration { |
| 52 | + LegacyTaintConfig() { this = "LegacyTaintConfig" } |
| 53 | + |
| 54 | + override predicate isSource(DataFlow::Node source) { TaintConfig::isSource(source) } |
| 55 | + |
| 56 | + override predicate isSink(DataFlow::Node sink) { TaintConfig::isSink(sink) } |
| 57 | +} |
| 58 | + |
| 59 | +query predicate taintFlowDifference = |
| 60 | + DataFlowDiff<TaintFlow, LegacyTaintConfig>::legacyDataFlowDifference/3; |
0 commit comments