Sergey
|
799614ee8e
|
CSRF in VF controller pages
|
2017-03-02 08:50:20 -08:00 |
|
Juan Martín Sotuyo Dodero
|
6e1bfe4027
|
Minor adjustments
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
2a41668101
|
Improving detection of safe resources
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
24d84fe57c
|
Renamed Escaping
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
51058cccfa
|
Moving Pattern to final static
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
4c748d961f
|
Using EnumSet
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
eb3fe1ed08
|
Adding a unit test and bug fix
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
595f398525
|
Small refactoring
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
18a2480dc9
|
Whitelisting ObjectType
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
f3c6d15561
|
Literal starting with http
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
eba729c953
|
Whitelisting Labels
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
8db5464583
|
any case http
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
0a8870a169
|
Whitelisting of http
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
9abb780da7
|
Additional negative test
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
382c8ca928
|
Typo fix and tests
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
49b2fb2e6a
|
Refactoring
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
c6cebde365
|
Fixing tests
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
758a131454
|
Parser fix for EL in no quote context
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
a29e77fe29
|
Fixing unit test order
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
bbcb4684b1
|
Reduced FPs with id and size
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
3d110b9634
|
small comment
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
f093132e4e
|
Reducing FPs with URLFor
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
84f5c6a723
|
Proper node reporting
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
0e52b1542e
|
Style check fixes
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
93f82fbd20
|
Context aware escaping
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
18d9c12467
|
Style fixes
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
59429b7124
|
Support for optional args in EL
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
83294540af
|
Support for EL with no quotes
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
6ab090d798
|
Improved dot notation and empty EL
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
d3b284805d
|
Revert
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
a3898ad707
|
Cleanup
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
5b3172aa28
|
Fixed floats support
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
2a078e8c48
|
Small renaming
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
6a3cb82b83
|
Adding support for Content
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
dc0e2e3bb3
|
Improved the rule to catch escaped values
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
7d9cd70e55
|
Added support for DotExpression and Arguments list
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
72122470c7
|
Small fixes
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
a942459225
|
Grammar with support for VFEL methods
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
f5d382951d
|
Get rid of last reference to #$
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
31ad724404
|
Fixed BOM and random spacing
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
cdf29e8b86
|
Adding support for html style tag
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
c345b67f0f
|
Cleanup
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
8a6f8c2110
|
One more unit test
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
fc5c440190
|
Code style cleanup
|
2017-03-01 01:13:14 -03:00 |
|
Sergey
|
f799cf2e5b
|
Renaming rules to security, fixing leading whitespaces
|
2017-03-01 01:12:42 -03:00 |
|
Sergey
|
1218cd5c5b
|
Fixed up parser unit tests
|
2017-03-01 01:12:42 -03:00 |
|
Sergey
|
b7974d0486
|
XSS in apex:outputText
|
2017-03-01 01:12:42 -03:00 |
|
Sergey
|
63f6e618f9
|
Support for mixed merge fields
|
2017-03-01 01:12:42 -03:00 |
|
Sergey
|
2f396cf44e
|
Cleanup
|
2017-03-01 01:12:42 -03:00 |
|
Sergey
|
a0b1ca00b9
|
First rule
|
2017-03-01 01:12:42 -03:00 |
|