Conversation
a107b89 to
aea5fed
Compare
… as a source but isn't
Contributor
There was a problem hiding this comment.
PR Overview
This pull request adds support for the react-relay library by introducing a new model that classifies specific react-relay hook return values as a "response" threat and extends test coverage for DOM-based XSS scenarios.
- Introduces a YAML file to model response threats for various react-relay hooks
- Adds corresponding test cases in a React component to validate DOM-based XSS alerts
- Updates change notes to document the new support for react-relay
Reviewed Changes
| File | Description |
|---|---|
| javascript/ql/lib/ext/react-relay-threat.model.yml | Adds model definitions for marking react-relay hook return values as "response" threats |
| javascript/ql/test/query-tests/Security/CWE-079/DomBasedXssWithResponseThreat/testReactRelay.tsx | Provides test cases for new response threat scenarios using react-relay hooks |
| javascript/ql/lib/change-notes/2025-02-25-react-relay.md | Notes the addition of react-relay support |
Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.
Tip: Leave feedback on Copilot's review comments with the 👎 and 👍 buttons to help improve review quality. Learn more
asgerf
reviewed
Mar 10, 2025
...script/ql/test/query-tests/Security/CWE-079/DomBasedXssWithResponseThreat/testReactRelay.tsx
Show resolved
Hide resolved
Co-authored-by: Asgerf <asgerf@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request introduces a library model for
react-relay's, categorizing it's new sources as aresponsethreat.Closes #465