File tree Expand file tree Collapse file tree 2 files changed +5
-11
lines changed
javascript/ql/test/query-tests/Security/CWE-020/IncompleteUrlSchemeCheck Expand file tree Collapse file tree 2 files changed +5
-11
lines changed Original file line number Diff line number Diff line change 1- #select
21| IncompleteUrlSchemeCheck.js:5:9:5:35 | u.start ... ript:") | This check does not consider data: and vbscript:. |
32| IncompleteUrlSchemeCheck.js:16:9:16:39 | badProt ... otocol) | This check does not consider vbscript:. |
43| IncompleteUrlSchemeCheck.js:23:9:23:43 | badProt ... scheme) | This check does not consider vbscript:. |
1211| IncompleteUrlSchemeCheck.js:87:7:87:40 | /^(java ... scheme) | This check does not consider vbscript:. |
1312| IncompleteUrlSchemeCheck.js:94:10:94:15 | scheme | This check does not consider vbscript:. |
1413| IncompleteUrlSchemeCheck.js:104:6:104:39 | /^(java ... scheme) | This check does not consider vbscript:. |
15- | IncompleteUrlSchemeCheck.js:110:12:112:29 | url // ... :/, "") | This check does not consider vbscript:. |
14+ | IncompleteUrlSchemeCheck.js:110:12:112:29 | url\\n ... :/, "") | This check does not consider vbscript:. |
1615| IncompleteUrlSchemeCheck.js:124:11:124:34 | url.rep ... :/, "") | This check does not consider vbscript:. |
17- testFailures
18- | IncompleteUrlSchemeCheck.js:94:10:94:15 | This check does not consider vbscript:. | Unexpected result: Alert |
19- | IncompleteUrlSchemeCheck.js:95:25:95:34 | // $ Alert | Missing result: Alert |
20- | IncompleteUrlSchemeCheck.js:110:12:112:29 | This check does not consider vbscript:. | Unexpected result: Alert |
21- | IncompleteUrlSchemeCheck.js:110:17:110:26 | // $ Alert | Missing result: Alert |
Original file line number Diff line number Diff line change @@ -91,8 +91,8 @@ function test12(url) {
9191
9292function test13 ( url ) {
9393 let scheme = goog . uri . utils . getScheme ( url ) ;
94- switch ( scheme ) {
95- case "javascript" : // $ Alert
94+ switch ( scheme ) { // $ Alert
95+ case "javascript" :
9696 case "data" :
9797 return "about:blank" ;
9898 default :
@@ -107,9 +107,9 @@ function test14(url) {
107107}
108108
109109function chain1 ( url ) {
110- return url // $ Alert
110+ return url
111111 . replace ( / j a v a s c r i p t : / , "" )
112- . replace ( / d a t a : / , "" ) ;
112+ . replace ( / d a t a : / , "" ) ; // $ Alert
113113}
114114
115115function chain2 ( url ) {
You can’t perform that action at this time.
0 commit comments