221 Commits

Author SHA1 Message Date
Sergey
229a4d7269 Review fixes 2017-03-03 12:46:14 -08:00
Juan Martín Sotuyo Dodero
b3992a6799 Merge branch 'master' into CSRFInVisualForce 2017-03-03 16:02:41 -03:00
Juan Martín Sotuyo Dodero
57a3cdd4a2 Fix since in VF Security rules 2017-03-03 15:32:26 -03:00
Sergey
309d2d1011 Style fix 2017-03-03 09:13:55 -08:00
Sergey
d12c1f7fe4 Iterative DotExpression evaluation instead of checking the first one 2017-03-02 17:47:56 -08:00
Sergey
caf27adbc2 deleted unused file 2017-03-02 17:36:33 -08:00
Sergey
b38642ab1a Merged 2017-03-02 17:31:05 -08:00
Sergey
81c67a5df2 Fallback for JS arrays and defs 2017-03-02 17:28:54 -08:00
Sergey
1942e94cec Bug fix 2017-03-02 15:57:26 -08:00
Sergey
6137baf615 More test coverage 2017-03-02 15:51:57 -08:00
Sergey
32762c48d1 fix for unbalanced quotes 2017-03-02 15:47:47 -08:00
Sergey
b7946ba4d1 fix for special tags 2017-03-02 15:44:05 -08:00
Sergey
799614ee8e CSRF in VF controller pages 2017-03-02 08:50:20 -08:00
Sergey
c4497d54e2 Logic bug fix 2017-03-01 15:54:22 -08:00
Sergey
2106e99dac Revert quoted context 2017-03-01 15:44:55 -08:00
Sergey
a987c77805 Added support for quoted context 2017-03-01 13:51:07 -08:00
Sergey
34b707225c Script EL support added 2017-03-01 13:09:35 -08:00
Sergey
2e073a196a Initial 2017-03-01 10:54:35 -08:00
Juan Martín Sotuyo Dodero
6e1bfe4027 Minor adjustments 2017-03-01 01:13:14 -03:00
Sergey
2a41668101 Improving detection of safe resources 2017-03-01 01:13:14 -03:00
Sergey
24d84fe57c Renamed Escaping 2017-03-01 01:13:14 -03:00
Sergey
51058cccfa Moving Pattern to final static 2017-03-01 01:13:14 -03:00
Sergey
4c748d961f Using EnumSet 2017-03-01 01:13:14 -03:00
Sergey
eb3fe1ed08 Adding a unit test and bug fix 2017-03-01 01:13:14 -03:00
Sergey
595f398525 Small refactoring 2017-03-01 01:13:14 -03:00
Sergey
18a2480dc9 Whitelisting ObjectType 2017-03-01 01:13:14 -03:00
Sergey
f3c6d15561 Literal starting with http 2017-03-01 01:13:14 -03:00
Sergey
eba729c953 Whitelisting Labels 2017-03-01 01:13:14 -03:00
Sergey
8db5464583 any case http 2017-03-01 01:13:14 -03:00
Sergey
0a8870a169 Whitelisting of http 2017-03-01 01:13:14 -03:00
Sergey
9abb780da7 Additional negative test 2017-03-01 01:13:14 -03:00
Sergey
382c8ca928 Typo fix and tests 2017-03-01 01:13:14 -03:00
Sergey
49b2fb2e6a Refactoring 2017-03-01 01:13:14 -03:00
Sergey
c6cebde365 Fixing tests 2017-03-01 01:13:14 -03:00
Sergey
758a131454 Parser fix for EL in no quote context 2017-03-01 01:13:14 -03:00
Sergey
a29e77fe29 Fixing unit test order 2017-03-01 01:13:14 -03:00
Sergey
bbcb4684b1 Reduced FPs with id and size 2017-03-01 01:13:14 -03:00
Sergey
3d110b9634 small comment 2017-03-01 01:13:14 -03:00
Sergey
f093132e4e Reducing FPs with URLFor 2017-03-01 01:13:14 -03:00
Sergey
84f5c6a723 Proper node reporting 2017-03-01 01:13:14 -03:00
Sergey
0e52b1542e Style check fixes 2017-03-01 01:13:14 -03:00
Sergey
93f82fbd20 Context aware escaping 2017-03-01 01:13:14 -03:00
Sergey
18d9c12467 Style fixes 2017-03-01 01:13:14 -03:00
Sergey
59429b7124 Support for optional args in EL 2017-03-01 01:13:14 -03:00
Sergey
83294540af Support for EL with no quotes 2017-03-01 01:13:14 -03:00
Sergey
6ab090d798 Improved dot notation and empty EL 2017-03-01 01:13:14 -03:00
Sergey
d3b284805d Revert 2017-03-01 01:13:14 -03:00
Sergey
a3898ad707 Cleanup 2017-03-01 01:13:14 -03:00
Sergey
5b3172aa28 Fixed floats support 2017-03-01 01:13:14 -03:00
Sergey
2a078e8c48 Small renaming 2017-03-01 01:13:14 -03:00