Swift: Taint through interpolated strings#9972
Merged
MathiasVP merged 9 commits intogithub:mainfrom Aug 5, 2022
Merged
Conversation
54d7a3f to
74dd20a
Compare
…t all the calls inside the interpolated string computations are 'CallExpr's.
…compiler during string interpolation, and (2) out of the internal 'TapExpr' and into the interpolated string result.
74dd20a to
05e6dd8
Compare
swift/ql/lib/codeql/swift/controlflow/internal/ControlFlowGraphImpl.qll
Outdated
Show resolved
Hide resolved
…hImpl.qll Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
geoffw0
reviewed
Aug 5, 2022
Contributor
geoffw0
left a comment
There was a problem hiding this comment.
Results in the tests look good, but I'm struggling to give this any deeper review at the moment.
|
|
||
| webview.loadHTMLString("<html>\(localStringFragment)</html>", baseURL: nil) // GOOD: the HTML data is local | ||
| webview.loadHTMLString("<html>\(remoteString)</html>", baseURL: nil) // BAD [NOT DETECTED] | ||
| webview.loadHTMLString("<html>\(remoteString)</html>", baseURL: nil) // BAD |
geoffw0
approved these changes
Aug 5, 2022
Contributor
geoffw0
left a comment
There was a problem hiding this comment.
I'm happy with this, I think, but I'd like to give others a little longer to comment.
rdmarsh2
approved these changes
Aug 5, 2022
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR adds control-flow and taint-flow through interpolated string literals in Swift.
Note: Don't merge this before we've merged #9964 as it (semantically) conflicts with that PR.That PR has been merged now 🎉Commit-by-commit review strongly encouraged!