Skip to content

Commit 4282005

Browse files
committed
JS: Add summary model for graphql's rootValue
1 parent a6d728a commit 4282005

File tree

4 files changed

+35
-2
lines changed

4 files changed

+35
-2
lines changed
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/javascript-all
4+
extensible: summaryModel
5+
data:
6+
- ["graphql", "Member[graphql]", "Argument[0].Member[source]", "Argument[0].Member[rootValue].AnyMember.Parameter[0].AnyMember", "taint"]

javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/CodeInjection.expected

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,7 @@
6161
| fastify.js:107:23:107:31 | userInput | fastify.js:106:21:106:38 | request.query.code | fastify.js:107:23:107:31 | userInput | This code execution depends on a $@. | fastify.js:106:21:106:38 | request.query.code | user-provided value |
6262
| fastify.js:108:28:108:50 | reply.l ... tedCode | fastify.js:94:29:94:41 | request.query | fastify.js:108:28:108:50 | reply.l ... tedCode | This code execution depends on a $@. | fastify.js:94:29:94:41 | request.query | user-provided value |
6363
| fastify.js:108:28:108:50 | reply.l ... tedCode | fastify.js:94:29:94:51 | request ... plyCode | fastify.js:108:28:108:50 | reply.l ... tedCode | This code execution depends on a $@. | fastify.js:94:29:94:51 | request ... plyCode | user-provided value |
64+
| graph-ql.js:20:19:20:22 | expr | graph-ql.js:28:32:28:39 | req.body | graph-ql.js:20:19:20:22 | expr | This code execution depends on a $@. | graph-ql.js:28:32:28:39 | req.body | user-provided value |
6465
| module.js:9:16:9:29 | req.query.code | module.js:9:16:9:29 | req.query.code | module.js:9:16:9:29 | req.query.code | This code execution depends on a $@. | module.js:9:16:9:29 | req.query.code | user-provided value |
6566
| module.js:11:17:11:30 | req.query.code | module.js:11:17:11:30 | req.query.code | module.js:11:17:11:30 | req.query.code | This code execution depends on a $@. | module.js:11:17:11:30 | req.query.code | user-provided value |
6667
| react-native.js:8:32:8:38 | tainted | react-native.js:7:17:7:33 | req.param("code") | react-native.js:8:32:8:38 | tainted | This code execution depends on a $@. | react-native.js:7:17:7:33 | req.param("code") | user-provided value |
@@ -154,6 +155,12 @@ edges
154155
| fastify.js:106:9:106:17 | userInput | fastify.js:107:23:107:31 | userInput | provenance | |
155156
| fastify.js:106:21:106:33 | request.query | fastify.js:106:9:106:17 | userInput | provenance | |
156157
| fastify.js:106:21:106:38 | request.query.code | fastify.js:106:9:106:17 | userInput | provenance | |
158+
| graph-ql.js:18:12:18:15 | expr | graph-ql.js:18:12:18:15 | expr | provenance | |
159+
| graph-ql.js:18:12:18:15 | expr | graph-ql.js:20:19:20:22 | expr | provenance | |
160+
| graph-ql.js:28:9:28:28 | { query, variables } | graph-ql.js:28:11:28:15 | query | provenance | |
161+
| graph-ql.js:28:11:28:15 | query | graph-ql.js:31:13:31:17 | query | provenance | |
162+
| graph-ql.js:28:32:28:39 | req.body | graph-ql.js:28:9:28:28 | { query, variables } | provenance | |
163+
| graph-ql.js:31:13:31:17 | query | graph-ql.js:18:12:18:15 | expr | provenance | |
157164
| react-native.js:7:7:7:13 | tainted | react-native.js:8:32:8:38 | tainted | provenance | |
158165
| react-native.js:7:7:7:13 | tainted | react-native.js:10:23:10:29 | tainted | provenance | |
159166
| react-native.js:7:17:7:33 | req.param("code") | react-native.js:7:7:7:13 | tainted | provenance | |
@@ -288,6 +295,13 @@ nodes
288295
| fastify.js:106:21:106:38 | request.query.code | semmle.label | request.query.code |
289296
| fastify.js:107:23:107:31 | userInput | semmle.label | userInput |
290297
| fastify.js:108:28:108:50 | reply.l ... tedCode | semmle.label | reply.l ... tedCode |
298+
| graph-ql.js:18:12:18:15 | expr | semmle.label | expr |
299+
| graph-ql.js:18:12:18:15 | expr | semmle.label | expr |
300+
| graph-ql.js:20:19:20:22 | expr | semmle.label | expr |
301+
| graph-ql.js:28:9:28:28 | { query, variables } | semmle.label | { query, variables } |
302+
| graph-ql.js:28:11:28:15 | query | semmle.label | query |
303+
| graph-ql.js:28:32:28:39 | req.body | semmle.label | req.body |
304+
| graph-ql.js:31:13:31:17 | query | semmle.label | query |
291305
| module.js:9:16:9:29 | req.query.code | semmle.label | req.query.code |
292306
| module.js:11:17:11:30 | req.query.code | semmle.label | req.query.code |
293307
| react-native.js:7:7:7:13 | tainted | semmle.label | tainted |

javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/HeuristicSourceCodeInjection.expected

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,12 @@ edges
5555
| fastify.js:106:9:106:17 | userInput | fastify.js:107:23:107:31 | userInput | provenance | |
5656
| fastify.js:106:21:106:33 | request.query | fastify.js:106:9:106:17 | userInput | provenance | |
5757
| fastify.js:106:21:106:38 | request.query.code | fastify.js:106:9:106:17 | userInput | provenance | |
58+
| graph-ql.js:18:12:18:15 | expr | graph-ql.js:18:12:18:15 | expr | provenance | |
59+
| graph-ql.js:18:12:18:15 | expr | graph-ql.js:20:19:20:22 | expr | provenance | |
60+
| graph-ql.js:28:9:28:28 | { query, variables } | graph-ql.js:28:11:28:15 | query | provenance | |
61+
| graph-ql.js:28:11:28:15 | query | graph-ql.js:31:13:31:17 | query | provenance | |
62+
| graph-ql.js:28:32:28:39 | req.body | graph-ql.js:28:9:28:28 | { query, variables } | provenance | |
63+
| graph-ql.js:31:13:31:17 | query | graph-ql.js:18:12:18:15 | expr | provenance | |
5864
| react-native.js:7:7:7:13 | tainted | react-native.js:8:32:8:38 | tainted | provenance | |
5965
| react-native.js:7:7:7:13 | tainted | react-native.js:10:23:10:29 | tainted | provenance | |
6066
| react-native.js:7:17:7:33 | req.param("code") | react-native.js:7:7:7:13 | tainted | provenance | |
@@ -191,6 +197,13 @@ nodes
191197
| fastify.js:106:21:106:38 | request.query.code | semmle.label | request.query.code |
192198
| fastify.js:107:23:107:31 | userInput | semmle.label | userInput |
193199
| fastify.js:108:28:108:50 | reply.l ... tedCode | semmle.label | reply.l ... tedCode |
200+
| graph-ql.js:18:12:18:15 | expr | semmle.label | expr |
201+
| graph-ql.js:18:12:18:15 | expr | semmle.label | expr |
202+
| graph-ql.js:20:19:20:22 | expr | semmle.label | expr |
203+
| graph-ql.js:28:9:28:28 | { query, variables } | semmle.label | { query, variables } |
204+
| graph-ql.js:28:11:28:15 | query | semmle.label | query |
205+
| graph-ql.js:28:32:28:39 | req.body | semmle.label | req.body |
206+
| graph-ql.js:31:13:31:17 | query | semmle.label | query |
194207
| module.js:9:16:9:29 | req.query.code | semmle.label | req.query.code |
195208
| module.js:11:17:11:30 | req.query.code | semmle.label | req.query.code |
196209
| react-native.js:7:7:7:13 | tainted | semmle.label | tainted |

javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,15 +17,15 @@ const root = {
1717
},
1818
calc: ({ expr }) => {
1919
try {
20-
return eval(expr).toString(); // $ MISSING: Alert[js/code-injection]
20+
return eval(expr).toString(); // $ Alert[js/code-injection]
2121
} catch (e) {
2222
return `Error: ${e.message}`;
2323
}
2424
}
2525
};
2626

2727
app.post('/graphql', async (req, res) => {
28-
const { query, variables } = req.body; // $ MISSING: Source[js/code-injection]
28+
const { query, variables } = req.body; // $ Source[js/code-injection]
2929
const result = await graphql({
3030
schema,
3131
source: query,

0 commit comments

Comments
 (0)