Skip to content

Commit dbd1148

Browse files
committed
apply range pattern patch to javascript
1 parent afc7867 commit dbd1148

File tree

5 files changed

+34
-57
lines changed

5 files changed

+34
-57
lines changed

javascript/ql/lib/semmle/javascript/DOM.qll

Lines changed: 12 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -63,29 +63,25 @@ module DOM {
6363
/**
6464
* An HTML element, viewed as an `ElementDefinition`.
6565
*/
66-
private class HtmlElementDefinition extends ElementDefinition, @xmlelement {
67-
HtmlElementDefinition() { this instanceof HTML::Element }
68-
69-
override string getName() { result = this.(HTML::Element).getName() }
66+
private class HtmlElementDefinition extends ElementDefinition, @xmlelement instanceof HTML::Element {
67+
override string getName() { result = HTML::Element.super.getName() }
7068

7169
override AttributeDefinition getAttribute(int i) {
72-
result = this.(HTML::Element).getAttribute(i)
70+
result = HTML::Element.super.getAttribute(i)
7371
}
7472

75-
override ElementDefinition getParent() { result = this.(HTML::Element).getParent() }
73+
override ElementDefinition getParent() { result = HTML::Element.super.getParent() }
7674
}
7775

7876
/**
7977
* A JSX element, viewed as an `ElementDefinition`.
8078
*/
81-
private class JsxElementDefinition extends ElementDefinition, @jsx_element {
82-
JsxElementDefinition() { this instanceof JSXElement }
83-
84-
override string getName() { result = this.(JSXElement).getName() }
79+
private class JsxElementDefinition extends ElementDefinition, @jsx_element instanceof JSXElement {
80+
override string getName() { result = JSXElement.super.getName() }
8581

86-
override AttributeDefinition getAttribute(int i) { result = this.(JSXElement).getAttribute(i) }
82+
override AttributeDefinition getAttribute(int i) { result = JSXElement.super.getAttribute(i) }
8783

88-
override ElementDefinition getParent() { result = this.(JSXElement).getJsxParent() }
84+
override ElementDefinition getParent() { result = super.getJsxParent() }
8985
}
9086

9187
/**
@@ -131,14 +127,12 @@ module DOM {
131127
/**
132128
* An HTML attribute, viewed as an `AttributeDefinition`.
133129
*/
134-
private class HtmlAttributeDefinition extends AttributeDefinition, @xmlattribute {
135-
HtmlAttributeDefinition() { this instanceof HTML::Attribute }
136-
137-
override string getName() { result = this.(HTML::Attribute).getName() }
130+
private class HtmlAttributeDefinition extends AttributeDefinition, @xmlattribute instanceof HTML::Attribute {
131+
override string getName() { result = HTML::Attribute.super.getName() }
138132

139-
override string getStringValue() { result = this.(HTML::Attribute).getValue() }
133+
override string getStringValue() { result = super.getValue() }
140134

141-
override ElementDefinition getElement() { result = this.(HTML::Attribute).getElement() }
135+
override ElementDefinition getElement() { result = HTML::Attribute.super.getElement() }
142136
}
143137

144138
/**

javascript/ql/lib/semmle/javascript/dataflow/Nodes.qll

Lines changed: 12 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -61,17 +61,15 @@ class ParameterNode extends DataFlow::SourceNode {
6161
* new Array(16)
6262
* ```
6363
*/
64-
class InvokeNode extends DataFlow::SourceNode {
65-
InvokeNode() { this instanceof DataFlow::Impl::InvokeNodeDef }
66-
64+
class InvokeNode extends DataFlow::SourceNode instanceof DataFlow::Impl::InvokeNodeDef {
6765
/** Gets the syntactic invoke expression underlying this function invocation. */
68-
InvokeExpr getInvokeExpr() { result = this.(DataFlow::Impl::InvokeNodeDef).getInvokeExpr() }
66+
InvokeExpr getInvokeExpr() { result = super.getInvokeExpr() }
6967

7068
/** Gets the name of the function or method being invoked, if it can be determined. */
71-
string getCalleeName() { result = this.(DataFlow::Impl::InvokeNodeDef).getCalleeName() }
69+
string getCalleeName() { result = super.getCalleeName() }
7270

7371
/** Gets the data flow node specifying the function to be called. */
74-
DataFlow::Node getCalleeNode() { result = this.(DataFlow::Impl::InvokeNodeDef).getCalleeNode() }
72+
DataFlow::Node getCalleeNode() { result = super.getCalleeNode() }
7573

7674
/**
7775
* Gets the data flow node corresponding to the `i`th argument of this invocation.
@@ -92,10 +90,10 @@ class InvokeNode extends DataFlow::SourceNode {
9290
* but the position of `z` cannot be determined, hence there are no first and second
9391
* argument nodes.
9492
*/
95-
DataFlow::Node getArgument(int i) { result = this.(DataFlow::Impl::InvokeNodeDef).getArgument(i) }
93+
DataFlow::Node getArgument(int i) { result = super.getArgument(i) }
9694

9795
/** Gets the data flow node corresponding to an argument of this invocation. */
98-
DataFlow::Node getAnArgument() { result = this.(DataFlow::Impl::InvokeNodeDef).getAnArgument() }
96+
DataFlow::Node getAnArgument() { result = super.getAnArgument() }
9997

10098
/** Gets the data flow node corresponding to the last argument of this invocation. */
10199
DataFlow::Node getLastArgument() { result = getArgument(getNumArgument() - 1) }
@@ -112,12 +110,10 @@ class InvokeNode extends DataFlow::SourceNode {
112110
* ```
113111
* .
114112
*/
115-
DataFlow::Node getASpreadArgument() {
116-
result = this.(DataFlow::Impl::InvokeNodeDef).getASpreadArgument()
117-
}
113+
DataFlow::Node getASpreadArgument() { result = super.getASpreadArgument() }
118114

119115
/** Gets the number of arguments of this invocation, if it can be determined. */
120-
int getNumArgument() { result = this.(DataFlow::Impl::InvokeNodeDef).getNumArgument() }
116+
int getNumArgument() { result = super.getNumArgument() }
121117

122118
Function getEnclosingFunction() { result = getBasicBlock().getContainer() }
123119

@@ -258,15 +254,13 @@ class InvokeNode extends DataFlow::SourceNode {
258254
* Math.abs(x)
259255
* ```
260256
*/
261-
class CallNode extends InvokeNode {
262-
CallNode() { this instanceof DataFlow::Impl::CallNodeDef }
263-
257+
class CallNode extends InvokeNode instanceof DataFlow::Impl::CallNodeDef {
264258
/**
265259
* Gets the data flow node corresponding to the receiver expression of this method call.
266260
*
267261
* For example, the receiver of `x.m()` is `x`.
268262
*/
269-
DataFlow::Node getReceiver() { result = this.(DataFlow::Impl::CallNodeDef).getReceiver() }
263+
DataFlow::Node getReceiver() { result = super.getReceiver() }
270264
}
271265

272266
/**
@@ -279,11 +273,9 @@ class CallNode extends InvokeNode {
279273
* Math.abs(x)
280274
* ```
281275
*/
282-
class MethodCallNode extends CallNode {
283-
MethodCallNode() { this instanceof DataFlow::Impl::MethodCallNodeDef }
284-
276+
class MethodCallNode extends CallNode instanceof DataFlow::Impl::MethodCallNodeDef {
285277
/** Gets the name of the invoked method, if it can be determined. */
286-
string getMethodName() { result = this.(DataFlow::Impl::MethodCallNodeDef).getMethodName() }
278+
string getMethodName() { result = super.getMethodName() }
287279

288280
/**
289281
* Holds if this data flow node calls method `methodName` on receiver node `receiver`.

javascript/ql/lib/semmle/javascript/dataflow/Refinements.qll

Lines changed: 4 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -53,21 +53,18 @@ abstract class RefinementCandidate extends Expr {
5353
* A refinement candidate that references at most one variable, and hence
5454
* can be used to refine the abstract values inferred for that variable.
5555
*/
56-
class Refinement extends Expr {
57-
Refinement() {
58-
this instanceof RefinementCandidate and
59-
count(this.(RefinementCandidate).getARefinedVar()) <= 1
60-
}
56+
class Refinement extends Expr instanceof RefinementCandidate {
57+
Refinement() { count(this.(RefinementCandidate).getARefinedVar()) <= 1 }
6158

6259
/**
6360
* Gets the variable refined by this expression, if any.
6461
*/
65-
SsaSourceVariable getRefinedVar() { result = this.(RefinementCandidate).getARefinedVar() }
62+
SsaSourceVariable getRefinedVar() { result = super.getARefinedVar() }
6663

6764
/**
6865
* Gets a refinement value inferred for this expression in context `ctxt`.
6966
*/
70-
RefinementValue eval(RefinementContext ctxt) { result = this.(RefinementCandidate).eval(ctxt) }
67+
RefinementValue eval(RefinementContext ctxt) { result = super.eval(ctxt) }
7168
}
7269

7370
/** A literal, viewed as a refinement expression. */

javascript/ql/lib/semmle/javascript/security/performance/PolynomialReDoSCustomizations.qll

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -47,10 +47,8 @@ module PolynomialReDoS {
4747
* A remote input to a server, seen as a source for polynomial
4848
* regular expression denial-of-service vulnerabilities.
4949
*/
50-
class RequestInputAccessAsSource extends Source {
51-
RequestInputAccessAsSource() { this instanceof HTTP::RequestInputAccess }
52-
53-
override string getKind() { result = this.(HTTP::RequestInputAccess).getKind() }
50+
class RequestInputAccessAsSource extends Source instanceof HTTP::RequestInputAccess {
51+
override string getKind() { result = HTTP::RequestInputAccess.super.getKind() }
5452
}
5553

5654
/**

javascript/ql/src/experimental/Security/CWE-090/LdapInjectionCustomizations.qll

Lines changed: 4 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -39,21 +39,17 @@ module LdapInjection {
3939
/**
4040
* An LDAP filter for an API call that executes an operation against the LDAP server.
4141
*/
42-
class LdapjsSearchFilterAsSink extends Sink {
43-
LdapjsSearchFilterAsSink() { this instanceof LdapjsSearchFilter }
44-
42+
class LdapjsSearchFilterAsSink extends Sink instanceof LdapjsSearchFilter {
4543
override DataFlow::InvokeNode getQueryCall() {
46-
result = this.(LdapjsSearchFilter).getQueryCall()
44+
result = LdapjsSearchFilter.super.getQueryCall()
4745
}
4846
}
4947

5048
/**
5149
* An LDAP DN argument for an API call that executes an operation against the LDAP server.
5250
*/
53-
class LdapjsDNArgumentAsSink extends Sink {
54-
LdapjsDNArgumentAsSink() { this instanceof LdapjsDNArgument }
55-
56-
override DataFlow::InvokeNode getQueryCall() { result = this.(LdapjsDNArgument).getQueryCall() }
51+
class LdapjsDNArgumentAsSink extends Sink instanceof LdapjsDNArgument {
52+
override DataFlow::InvokeNode getQueryCall() { result = LdapjsDNArgument.super.getQueryCall() }
5753
}
5854

5955
/**

0 commit comments

Comments
 (0)