diff --git a/java/ql/lib/change-notes/2026-06-22-various-mad-additions.md b/java/ql/lib/change-notes/2026-06-22-various-mad-additions.md new file mode 100644 index 000000000000..726102dc66f7 --- /dev/null +++ b/java/ql/lib/change-notes/2026-06-22-various-mad-additions.md @@ -0,0 +1,6 @@ +--- +category: majorAnalysis +--- +* Added sink model for `sql-injection` for: `com.google.cloud.bigquery` and `org.apache.commons.dbutils`. +* Added a source model for: `spark` and `io.javalin.http`. +* Added a taint summary model for: `spark`. \ No newline at end of file diff --git a/java/ql/lib/ext/com.google.cloud.bigquery.model.yml b/java/ql/lib/ext/com.google.cloud.bigquery.model.yml new file mode 100644 index 000000000000..f14efa17fa37 --- /dev/null +++ b/java/ql/lib/ext/com.google.cloud.bigquery.model.yml @@ -0,0 +1,9 @@ +extensions: + - addsTo: + pack: codeql/java-all + extensible: sinkModel + data: + - ["com.google.cloud.bigquery", "QueryJobConfiguration", true, "newBuilder", "", "", "Argument[0]", "sql-injection", "manual"] + - ["com.google.cloud.bigquery", "QueryJobConfiguration", true, "of", "", "", "Argument[0]", "sql-injection", "manual"] + - ["com.google.cloud.bigquery", "QueryJobConfiguration$Builder", true, "setQuery", "", "", "Argument[0]", "sql-injection", "manual"] + diff --git a/java/ql/lib/ext/io.javalin.http.model.yml b/java/ql/lib/ext/io.javalin.http.model.yml new file mode 100644 index 000000000000..2d827072010f --- /dev/null +++ b/java/ql/lib/ext/io.javalin.http.model.yml @@ -0,0 +1,44 @@ +extensions: + - addsTo: + pack: codeql/java-all + extensible: sourceModel + data: + - ["io.javalin.http", "Context", true, "basicAuthCredentials", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "body", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "bodyAsBytes", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "bodyAsClass", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "bodyInputStream", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "bodyStreamAsClass", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "cookie", "(String)", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "cookieMap", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "header", "(String)", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "headerMap", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "formParam", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "formParams", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "formParamMap", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "formParamAsClass", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "formParamsAsClass", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "pathParam", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "pathParamAsClass", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "pathParamMap", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "queryParam", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "queryParams", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "queryParamAsClass", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "queryParamsAsClass", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "queryParamMap", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "queryString", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "uploadedFile", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "uploadedFiles", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "uploadedFileMap", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "url", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "fullUrl", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "contentType", "", "", "ReturnValue", "remote", "manual"] + - ["io.javalin.http", "Context", true, "userAgent", "", "", "ReturnValue", "remote", "manual"] + - addsTo: + pack: codeql/java-all + extensible: summaryModel + data: + - ["io.javalin.http", "UploadedFile", True, "content", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] + - ["io.javalin.http", "UploadedFile", True, "contentType", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] + - ["io.javalin.http", "UploadedFile", True, "extension", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] + - ["io.javalin.http", "UploadedFile", True, "filename", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] \ No newline at end of file diff --git a/java/ql/lib/ext/io.javalin.security.model.yml b/java/ql/lib/ext/io.javalin.security.model.yml new file mode 100644 index 000000000000..b5145814ae20 --- /dev/null +++ b/java/ql/lib/ext/io.javalin.security.model.yml @@ -0,0 +1,7 @@ +extensions: + - addsTo: + pack: codeql/java-all + extensible: summaryModel + data: + - ["io.javalin.security", "BasicAuthCredentials", True, "getPassword", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] + - ["io.javalin.security", "BasicAuthCredentials", True, "getUsername", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] \ No newline at end of file diff --git a/java/ql/lib/ext/io.javalin.validation.model.yml b/java/ql/lib/ext/io.javalin.validation.model.yml new file mode 100644 index 000000000000..120b3573c364 --- /dev/null +++ b/java/ql/lib/ext/io.javalin.validation.model.yml @@ -0,0 +1,9 @@ +extensions: + - addsTo: + pack: codeql/java-all + extensible: summaryModel + data: + - ["io.javalin.validation", "Validator", True, "get", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] + - ["io.javalin.validation", "Validator", True, "getOrDefault", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] + - ["io.javalin.validation", "Validator", True, "getOrNull", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] + - ["io.javalin.validation", "Validator", True, "getOrThrow", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] \ No newline at end of file diff --git a/java/ql/lib/ext/org.apache.commons.dbutils.model.yml b/java/ql/lib/ext/org.apache.commons.dbutils.model.yml new file mode 100644 index 000000000000..4b95bda7d8c0 --- /dev/null +++ b/java/ql/lib/ext/org.apache.commons.dbutils.model.yml @@ -0,0 +1,33 @@ +extensions: + - addsTo: + pack: codeql/java-all + extensible: sinkModel + data: + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "insert", "(Connection,String,ResultSetHandler)", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "insert", "(Connection,String,ResultSetHandler,Object[])", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "insert", "(String,ResultSetHandler)", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "insert", "(String,ResultSetHandler,Object[])", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "query", "(Connection,String,ResultSetHandler)", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "query", "(Connection,String,ResultSetHandler,Object[])", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "query", "(String,ResultSetHandler)", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "query", "(String,ResultSetHandler,Object[])", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "update", "(Connection,String)", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "update", "(Connection,String,Object[])", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "update", "(Connection,String,Object)", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "update", "(String)", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "update", "(String,Object[])", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "AsyncQueryRunner", true, "update", "(String,Object)", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "insert", "(Connection,String,ResultSetHandler)", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "insert", "(Connection,String,ResultSetHandler,Object[])", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "insert", "(String,ResultSetHandler)", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "insert", "(String,ResultSetHandler,Object[])", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "query", "(Connection,String,ResultSetHandler)", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "query", "(Connection,String,ResultSetHandler,Object[])", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "query", "(String,ResultSetHandler)", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "query", "(String,ResultSetHandler,Object[])", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "update", "(Connection,String)", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "update", "(Connection,String,Object[])", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "update", "(Connection,String,Object)", "", "Argument[1]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "update", "(String)", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "update", "(String,Object[])", "", "Argument[0]", "sql-injection", "manual"] + - ["org.apache.commons.dbutils", "QueryRunner", true, "update", "(String,Object)", "", "Argument[0]", "sql-injection", "manual"] \ No newline at end of file diff --git a/java/ql/lib/ext/spark.model.yml b/java/ql/lib/ext/spark.model.yml new file mode 100644 index 000000000000..602f0c8e2197 --- /dev/null +++ b/java/ql/lib/ext/spark.model.yml @@ -0,0 +1,27 @@ +extensions: + - addsTo: + pack: codeql/java-all + extensible: sourceModel + data: + - ["spark", "Request", true, "body", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "bodyAsBytes", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "cookie", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "cookies", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "headers", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "params", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "queryMap", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "queryParams", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "queryParamsSafe", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "queryParamOrDefault", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "queryParamsValues", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "queryString", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "uri", "", "", "ReturnValue", "remote", "manual"] + - ["spark", "Request", true, "url", "", "", "ReturnValue", "remote", "manual"] + - addsTo: + pack: codeql/java-all + extensible: summaryModel + data: + - ["spark", "QueryParamsMap", True, "get", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] + - ["spark", "QueryParamsMap", True, "toMap", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] + - ["spark", "QueryParamsMap", True, "value", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] + - ["spark", "QueryParamsMap", True, "values", "", "", "Argument[this]", "ReturnValue", "taint", "manual"] \ No newline at end of file diff --git a/java/ql/test/library-tests/frameworks/apache-commons-dbutils/Test.java b/java/ql/test/library-tests/frameworks/apache-commons-dbutils/Test.java new file mode 100644 index 000000000000..70cb2943d36a --- /dev/null +++ b/java/ql/test/library-tests/frameworks/apache-commons-dbutils/Test.java @@ -0,0 +1,80 @@ +package generatedtest; + +import java.sql.Connection; +import org.apache.commons.dbutils.AsyncQueryRunner; +import org.apache.commons.dbutils.QueryRunner; +import org.apache.commons.dbutils.ResultSetHandler; + +public class Test { + Object source() { return null; } + + public void testQueryRunnerSinks( + QueryRunner runner, Connection connection, ResultSetHandler handler) + throws Exception { + // "org.apache.commons.dbutils;QueryRunner;true;insert;(Connection,String,ResultSetHandler);;Argument[1];sql-injection;manual" + runner.insert(connection, (String) source(), handler); // $ hasValueFlow + // "org.apache.commons.dbutils;QueryRunner;true;insert;(Connection,String,ResultSetHandler,Object[]);;Argument[1];sql-injection;manual" + runner.insert(connection, (String) source(), handler, (Object[]) null); // $ hasValueFlow + // "org.apache.commons.dbutils;QueryRunner;true;insert;(String,ResultSetHandler);;Argument[0];sql-injection;manual" + runner.insert((String) source(), handler); // $ hasValueFlow + // "org.apache.commons.dbutils;QueryRunner;true;insert;(String,ResultSetHandler,Object[]);;Argument[0];sql-injection;manual" + runner.insert((String) source(), handler, (Object[]) null); // $ hasValueFlow + + // "org.apache.commons.dbutils;QueryRunner;true;query;(Connection,String,ResultSetHandler);;Argument[1];sql-injection;manual" + runner.query(connection, (String) source(), handler); // $ hasValueFlow + // "org.apache.commons.dbutils;QueryRunner;true;query;(Connection,String,ResultSetHandler,Object[]);;Argument[1];sql-injection;manual" + runner.query(connection, (String) source(), handler, (Object[]) null); // $ hasValueFlow + // "org.apache.commons.dbutils;QueryRunner;true;query;(String,ResultSetHandler);;Argument[0];sql-injection;manual" + runner.query((String) source(), handler); // $ hasValueFlow + // "org.apache.commons.dbutils;QueryRunner;true;query;(String,ResultSetHandler,Object[]);;Argument[0];sql-injection;manual" + runner.query((String) source(), handler, (Object[]) null); // $ hasValueFlow + + // "org.apache.commons.dbutils;QueryRunner;true;update;(Connection,String);;Argument[1];sql-injection;manual" + runner.update(connection, (String) source()); // $ hasValueFlow + // "org.apache.commons.dbutils;QueryRunner;true;update;(Connection,String,Object[]);;Argument[1];sql-injection;manual" + runner.update(connection, (String) source(), (Object[]) null); // $ hasValueFlow + // "org.apache.commons.dbutils;QueryRunner;true;update;(Connection,String,Object);;Argument[1];sql-injection;manual" + runner.update(connection, (String) source(), (Object) null); // $ hasValueFlow + // "org.apache.commons.dbutils;QueryRunner;true;update;(String);;Argument[0];sql-injection;manual" + runner.update((String) source()); // $ hasValueFlow + // "org.apache.commons.dbutils;QueryRunner;true;update;(String,Object[]);;Argument[0];sql-injection;manual" + runner.update((String) source(), (Object[]) null); // $ hasValueFlow + // "org.apache.commons.dbutils;QueryRunner;true;update;(String,Object);;Argument[0];sql-injection;manual" + runner.update((String) source(), (Object) null); // $ hasValueFlow + } + + public void testAsyncQueryRunnerSinks( + AsyncQueryRunner runner, Connection connection, ResultSetHandler handler) + throws Exception { + // "org.apache.commons.dbutils;AsyncQueryRunner;true;insert;(Connection,String,ResultSetHandler);;Argument[1];sql-injection;manual" + runner.insert(connection, (String) source(), handler); // $ hasValueFlow + // "org.apache.commons.dbutils;AsyncQueryRunner;true;insert;(Connection,String,ResultSetHandler,Object[]);;Argument[1];sql-injection;manual" + runner.insert(connection, (String) source(), handler, (Object[]) null); // $ hasValueFlow + // "org.apache.commons.dbutils;AsyncQueryRunner;true;insert;(String,ResultSetHandler);;Argument[0];sql-injection;manual" + runner.insert((String) source(), handler); // $ hasValueFlow + // "org.apache.commons.dbutils;AsyncQueryRunner;true;insert;(String,ResultSetHandler,Object[]);;Argument[0];sql-injection;manual" + runner.insert((String) source(), handler, (Object[]) null); // $ hasValueFlow + + // "org.apache.commons.dbutils;AsyncQueryRunner;true;query;(Connection,String,ResultSetHandler);;Argument[1];sql-injection;manual" + runner.query(connection, (String) source(), handler); // $ hasValueFlow + // "org.apache.commons.dbutils;AsyncQueryRunner;true;query;(Connection,String,ResultSetHandler,Object[]);;Argument[1];sql-injection;manual" + runner.query(connection, (String) source(), handler, (Object[]) null); // $ hasValueFlow + // "org.apache.commons.dbutils;AsyncQueryRunner;true;query;(String,ResultSetHandler);;Argument[0];sql-injection;manual" + runner.query((String) source(), handler); // $ hasValueFlow + // "org.apache.commons.dbutils;AsyncQueryRunner;true;query;(String,ResultSetHandler,Object[]);;Argument[0];sql-injection;manual" + runner.query((String) source(), handler, (Object[]) null); // $ hasValueFlow + + // "org.apache.commons.dbutils;AsyncQueryRunner;true;update;(Connection,String);;Argument[1];sql-injection;manual" + runner.update(connection, (String) source()); // $ hasValueFlow + // "org.apache.commons.dbutils;AsyncQueryRunner;true;update;(Connection,String,Object[]);;Argument[1];sql-injection;manual" + runner.update(connection, (String) source(), (Object[]) null); // $ hasValueFlow + // "org.apache.commons.dbutils;AsyncQueryRunner;true;update;(Connection,String,Object);;Argument[1];sql-injection;manual" + runner.update(connection, (String) source(), (Object) null); // $ hasValueFlow + // "org.apache.commons.dbutils;AsyncQueryRunner;true;update;(String);;Argument[0];sql-injection;manual" + runner.update((String) source()); // $ hasValueFlow + // "org.apache.commons.dbutils;AsyncQueryRunner;true;update;(String,Object[]);;Argument[0];sql-injection;manual" + runner.update((String) source(), (Object[]) null); // $ hasValueFlow + // "org.apache.commons.dbutils;AsyncQueryRunner;true;update;(String,Object);;Argument[0];sql-injection;manual" + runner.update((String) source(), (Object) null); // $ hasValueFlow + } +} \ No newline at end of file diff --git a/java/ql/test/library-tests/frameworks/apache-commons-dbutils/options b/java/ql/test/library-tests/frameworks/apache-commons-dbutils/options new file mode 100644 index 000000000000..5df2c1deaac4 --- /dev/null +++ b/java/ql/test/library-tests/frameworks/apache-commons-dbutils/options @@ -0,0 +1 @@ +//semmle-extractor-options: --javac-args -cp ${testdir}/../../../stubs/apache-commons-dbutils \ No newline at end of file diff --git a/java/ql/test/library-tests/frameworks/apache-commons-dbutils/test.expected b/java/ql/test/library-tests/frameworks/apache-commons-dbutils/test.expected new file mode 100644 index 000000000000..2fb182161170 --- /dev/null +++ b/java/ql/test/library-tests/frameworks/apache-commons-dbutils/test.expected @@ -0,0 +1,33 @@ +models +edges +nodes +subpaths +testFailures +| Test.java:15:58:15:74 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:17:75:17:91 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:19:46:19:62 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:21:63:21:79 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:24:57:24:73 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:26:74:26:90 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:28:45:28:61 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:30:62:30:78 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:33:49:33:65 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:35:66:35:82 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:37:64:37:80 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:39:37:39:53 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:41:54:41:70 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:43:52:43:68 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:50:58:50:74 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:52:75:52:91 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:54:46:54:62 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:56:63:56:79 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:59:57:59:73 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:61:74:61:90 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:63:45:63:61 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:65:62:65:78 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:68:49:68:65 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:70:66:70:82 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:72:64:72:80 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:74:37:74:53 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:76:54:76:70 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:78:52:78:68 | // $ hasValueFlow | Missing result: hasValueFlow | diff --git a/java/ql/test/library-tests/frameworks/apache-commons-dbutils/test.ql b/java/ql/test/library-tests/frameworks/apache-commons-dbutils/test.ql new file mode 100644 index 000000000000..de0d4722737b --- /dev/null +++ b/java/ql/test/library-tests/frameworks/apache-commons-dbutils/test.ql @@ -0,0 +1,4 @@ +import java +import utils.test.InlineFlowTest +import DefaultFlowTest +import TaintFlow::PathGraph diff --git a/java/ql/test/library-tests/frameworks/bigquery/Test.java b/java/ql/test/library-tests/frameworks/bigquery/Test.java new file mode 100644 index 000000000000..acba3a5095e9 --- /dev/null +++ b/java/ql/test/library-tests/frameworks/bigquery/Test.java @@ -0,0 +1,19 @@ +package generatedtest; + +import com.google.cloud.bigquery.QueryJobConfiguration; + +public class Test { + Object source() { return null; } + + public void testSinks() { + // "com.google.cloud.bigquery;QueryJobConfiguration;true;newBuilder;;;Argument[0];sql-injection;manual" + QueryJobConfiguration.newBuilder((String) source()); // $ hasValueFlow + + // "com.google.cloud.bigquery;QueryJobConfiguration;true;of;;;Argument[0];sql-injection;manual" + QueryJobConfiguration.of((String) source()); // $ hasValueFlow + + QueryJobConfiguration.Builder builder = QueryJobConfiguration.newBuilder("SELECT 1"); + // "com.google.cloud.bigquery;QueryJobConfiguration$Builder;true;setQuery;;;Argument[0];sql-injection;manual" + builder.setQuery((String) source()); // $ hasValueFlow + } +} \ No newline at end of file diff --git a/java/ql/test/library-tests/frameworks/bigquery/options b/java/ql/test/library-tests/frameworks/bigquery/options new file mode 100644 index 000000000000..490e5d2ca6b1 --- /dev/null +++ b/java/ql/test/library-tests/frameworks/bigquery/options @@ -0,0 +1 @@ +//semmle-extractor-options: --javac-args -cp ${testdir}/../../../stubs/bigquery \ No newline at end of file diff --git a/java/ql/test/library-tests/frameworks/bigquery/test.expected b/java/ql/test/library-tests/frameworks/bigquery/test.expected new file mode 100644 index 000000000000..83f841a28ea5 --- /dev/null +++ b/java/ql/test/library-tests/frameworks/bigquery/test.expected @@ -0,0 +1,3 @@ +| Test.java:10:56:10:72 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:13:48:13:64 | // $ hasValueFlow | Missing result: hasValueFlow | +| Test.java:17:40:17:56 | // $ hasValueFlow | Missing result: hasValueFlow | diff --git a/java/ql/test/library-tests/frameworks/bigquery/test.ql b/java/ql/test/library-tests/frameworks/bigquery/test.ql new file mode 100644 index 000000000000..de0d4722737b --- /dev/null +++ b/java/ql/test/library-tests/frameworks/bigquery/test.ql @@ -0,0 +1,4 @@ +import java +import utils.test.InlineFlowTest +import DefaultFlowTest +import TaintFlow::PathGraph diff --git a/java/ql/test/library-tests/frameworks/javalin/Test.java b/java/ql/test/library-tests/frameworks/javalin/Test.java new file mode 100644 index 000000000000..6811bfbd4dab --- /dev/null +++ b/java/ql/test/library-tests/frameworks/javalin/Test.java @@ -0,0 +1,127 @@ +package generatedtest; + +import io.javalin.http.Context; +import io.javalin.http.UploadedFile; +import io.javalin.security.BasicAuthCredentials; +import io.javalin.validation.Validator; +import java.lang.reflect.Type; + +public class Test { + Object source() { return null; } + void sink(Object value) { } + + public void testSources(Context context) { + // "io.javalin.http;Context;true;basicAuthCredentials;;;ReturnValue;remote;manual" + sink(context.basicAuthCredentials()); // $ hasTaintFlow + // "io.javalin.http;Context;true;body;;;ReturnValue;remote;manual" + sink(context.body()); // $ hasTaintFlow + // "io.javalin.http;Context;true;bodyAsBytes;;;ReturnValue;remote;manual" + sink(context.bodyAsBytes()); // $ hasTaintFlow + // "io.javalin.http;Context;true;bodyAsClass;;;ReturnValue;remote;manual" + sink(context.bodyAsClass((Type) null)); // $ hasTaintFlow + // "io.javalin.http;Context;true;bodyAsClass;;;ReturnValue;remote;manual" + sink(context.bodyAsClass((Class) null)); // $ hasTaintFlow + // "io.javalin.http;Context;true;bodyInputStream;;;ReturnValue;remote;manual" + sink(context.bodyInputStream()); // $ hasTaintFlow + // "io.javalin.http;Context;true;bodyStreamAsClass;;;ReturnValue;remote;manual" + sink(context.bodyStreamAsClass((Type) null)); // $ hasTaintFlow + // "io.javalin.http;Context;true;cookie;(String);;ReturnValue;remote;manual" + sink(context.cookie("name")); // $ hasTaintFlow + // "io.javalin.http;Context;true;cookieMap;;;ReturnValue;remote;manual" + sink(context.cookieMap()); // $ hasTaintFlow + // "io.javalin.http;Context;true;header;(String);;ReturnValue;remote;manual" + sink(context.header("name")); // $ hasTaintFlow + // "io.javalin.http;Context;true;headerMap;;;ReturnValue;remote;manual" + sink(context.headerMap()); // $ hasTaintFlow + // "io.javalin.http;Context;true;formParam;;;ReturnValue;remote;manual" + sink(context.formParam("name")); // $ hasTaintFlow + // "io.javalin.http;Context;true;formParams;;;ReturnValue;remote;manual" + sink(context.formParams("name")); // $ hasTaintFlow + // "io.javalin.http;Context;true;formParamMap;;;ReturnValue;remote;manual" + sink(context.formParamMap()); // $ hasTaintFlow + // "io.javalin.http;Context;true;formParamAsClass;;;ReturnValue;remote;manual" + sink(context.formParamAsClass("name", String.class)); // $ hasTaintFlow + // "io.javalin.http;Context;true;formParamsAsClass;;;ReturnValue;remote;manual" + sink(context.formParamsAsClass("name", String.class)); // $ hasTaintFlow + // "io.javalin.http;Context;true;pathParam;;;ReturnValue;remote;manual" + sink(context.pathParam("name")); // $ hasTaintFlow + // "io.javalin.http;Context;true;pathParamAsClass;;;ReturnValue;remote;manual" + sink(context.pathParamAsClass("name", String.class)); // $ hasTaintFlow + // "io.javalin.http;Context;true;pathParamMap;;;ReturnValue;remote;manual" + sink(context.pathParamMap()); // $ hasTaintFlow + // "io.javalin.http;Context;true;queryParam;;;ReturnValue;remote;manual" + sink(context.queryParam("name")); // $ hasTaintFlow + // "io.javalin.http;Context;true;queryParams;;;ReturnValue;remote;manual" + sink(context.queryParams("name")); // $ hasTaintFlow + // "io.javalin.http;Context;true;queryParamAsClass;;;ReturnValue;remote;manual" + sink(context.queryParamAsClass("name", String.class)); // $ hasTaintFlow + // "io.javalin.http;Context;true;queryParamsAsClass;;;ReturnValue;remote;manual" + sink(context.queryParamsAsClass("name", String.class)); // $ hasTaintFlow + // "io.javalin.http;Context;true;queryParamMap;;;ReturnValue;remote;manual" + sink(context.queryParamMap()); // $ hasTaintFlow + // "io.javalin.http;Context;true;queryString;;;ReturnValue;remote;manual" + sink(context.queryString()); // $ hasTaintFlow + // "io.javalin.http;Context;true;uploadedFile;;;ReturnValue;remote;manual" + sink(context.uploadedFile("name")); // $ hasTaintFlow + // "io.javalin.http;Context;true;uploadedFiles;;;ReturnValue;remote;manual" + sink(context.uploadedFiles("name")); // $ hasTaintFlow + // "io.javalin.http;Context;true;uploadedFiles;;;ReturnValue;remote;manual" + sink(context.uploadedFiles()); // $ hasTaintFlow + // "io.javalin.http;Context;true;uploadedFileMap;;;ReturnValue;remote;manual" + sink(context.uploadedFileMap()); // $ hasTaintFlow + // "io.javalin.http;Context;true;url;;;ReturnValue;remote;manual" + sink(context.url()); // $ hasTaintFlow + // "io.javalin.http;Context;true;fullUrl;;;ReturnValue;remote;manual" + sink(context.fullUrl()); // $ hasTaintFlow + // "io.javalin.http;Context;true;contentType;;;ReturnValue;remote;manual" + sink(context.contentType()); // $ hasTaintFlow + // "io.javalin.http;Context;true;userAgent;;;ReturnValue;remote;manual" + sink(context.userAgent()); // $ hasTaintFlow + } + + public void testUploadedFileAdditionalFlowSteps() { + // "io.javalin.http;UploadedFile;true;content;;;Argument[this];ReturnValue;taint;manual" + UploadedFile file = (UploadedFile) source(); + sink(file.content()); // $ hasTaintFlow + + // "io.javalin.http;UploadedFile;true;contentType;;;Argument[this];ReturnValue;taint;manual" + file = (UploadedFile) source(); + sink(file.contentType()); // $ hasTaintFlow + + // "io.javalin.http;UploadedFile;true;extension;;;Argument[this];ReturnValue;taint;manual" + file = (UploadedFile) source(); + sink(file.extension()); // $ hasTaintFlow + + // "io.javalin.http;UploadedFile;true;filename;;;Argument[this];ReturnValue;taint;manual" + file = (UploadedFile) source(); + sink(file.filename()); // $ hasTaintFlow + } + + public void testBasicAuthCredentialsAdditionalFlowSteps() { + // "io.javalin.security;BasicAuthCredentials;true;getPassword;;;Argument[this];ReturnValue;taint;manual" + BasicAuthCredentials credentials = (BasicAuthCredentials) source(); + sink(credentials.getPassword()); // $ hasTaintFlow + + // "io.javalin.security;BasicAuthCredentials;true;getUsername;;;Argument[this];ReturnValue;taint;manual" + credentials = (BasicAuthCredentials) source(); + sink(credentials.getUsername()); // $ hasTaintFlow + } + + public void testValidatorAdditionalFlowSteps() { + // "io.javalin.validation;Validator;true;get;;;Argument[this];ReturnValue;taint;manual" + Validator validator = (Validator) source(); + sink(validator.get()); // $ hasTaintFlow + + // "io.javalin.validation;Validator;true;getOrDefault;;;Argument[this];ReturnValue;taint;manual" + validator = (Validator) source(); + sink(validator.getOrDefault(null)); // $ hasTaintFlow + + // "io.javalin.validation;Validator;true;getOrNull;;;Argument[this];ReturnValue;taint;manual" + validator = (Validator) source(); + sink(validator.getOrNull()); // $ hasTaintFlow + + // "io.javalin.validation;Validator;true;getOrThrow;;;Argument[this];ReturnValue;taint;manual" + validator = (Validator) source(); + sink(validator.getOrThrow(null)); // $ hasTaintFlow + } +} \ No newline at end of file diff --git a/java/ql/test/library-tests/frameworks/javalin/options b/java/ql/test/library-tests/frameworks/javalin/options new file mode 100644 index 000000000000..bd0b64cd5d53 --- /dev/null +++ b/java/ql/test/library-tests/frameworks/javalin/options @@ -0,0 +1 @@ +//semmle-extractor-options: --javac-args -cp ${testdir}/../../../stubs/javalin \ No newline at end of file diff --git a/java/ql/test/library-tests/frameworks/javalin/test.expected b/java/ql/test/library-tests/frameworks/javalin/test.expected new file mode 100644 index 000000000000..e3dd178d4c25 --- /dev/null +++ b/java/ql/test/library-tests/frameworks/javalin/test.expected @@ -0,0 +1,118 @@ +models +| 1 | Summary: io.javalin.http; UploadedFile; true; content; ; ; Argument[this]; ReturnValue; taint; manual | +| 2 | Summary: io.javalin.http; UploadedFile; true; contentType; ; ; Argument[this]; ReturnValue; taint; manual | +| 3 | Summary: io.javalin.http; UploadedFile; true; extension; ; ; Argument[this]; ReturnValue; taint; manual | +| 4 | Summary: io.javalin.http; UploadedFile; true; filename; ; ; Argument[this]; ReturnValue; taint; manual | +| 5 | Summary: io.javalin.security; BasicAuthCredentials; true; getPassword; ; ; Argument[this]; ReturnValue; taint; manual | +| 6 | Summary: io.javalin.security; BasicAuthCredentials; true; getUsername; ; ; Argument[this]; ReturnValue; taint; manual | +| 7 | Summary: io.javalin.validation; Validator; true; get; ; ; Argument[this]; ReturnValue; taint; manual | +| 8 | Summary: io.javalin.validation; Validator; true; getOrDefault; ; ; Argument[this]; ReturnValue; taint; manual | +| 9 | Summary: io.javalin.validation; Validator; true; getOrNull; ; ; Argument[this]; ReturnValue; taint; manual | +| 10 | Summary: io.javalin.validation; Validator; true; getOrThrow; ; ; Argument[this]; ReturnValue; taint; manual | +edges +| Test.java:84:23:84:45 | (...)... : UploadedFile | Test.java:85:8:85:11 | file : UploadedFile | provenance | | +| Test.java:84:38:84:45 | source(...) : Object | Test.java:84:23:84:45 | (...)... : UploadedFile | provenance | | +| Test.java:85:8:85:11 | file : UploadedFile | Test.java:85:8:85:21 | content(...) | provenance | MaD:1 | +| Test.java:88:10:88:32 | (...)... : UploadedFile | Test.java:89:8:89:11 | file : UploadedFile | provenance | | +| Test.java:88:25:88:32 | source(...) : Object | Test.java:88:10:88:32 | (...)... : UploadedFile | provenance | | +| Test.java:89:8:89:11 | file : UploadedFile | Test.java:89:8:89:25 | contentType(...) | provenance | MaD:2 | +| Test.java:92:10:92:32 | (...)... : UploadedFile | Test.java:93:8:93:11 | file : UploadedFile | provenance | | +| Test.java:92:25:92:32 | source(...) : Object | Test.java:92:10:92:32 | (...)... : UploadedFile | provenance | | +| Test.java:93:8:93:11 | file : UploadedFile | Test.java:93:8:93:23 | extension(...) | provenance | MaD:3 | +| Test.java:96:10:96:32 | (...)... : UploadedFile | Test.java:97:8:97:11 | file : UploadedFile | provenance | | +| Test.java:96:25:96:32 | source(...) : Object | Test.java:96:10:96:32 | (...)... : UploadedFile | provenance | | +| Test.java:97:8:97:11 | file : UploadedFile | Test.java:97:8:97:22 | filename(...) | provenance | MaD:4 | +| Test.java:102:38:102:68 | (...)... : BasicAuthCredentials | Test.java:103:8:103:18 | credentials : BasicAuthCredentials | provenance | | +| Test.java:102:61:102:68 | source(...) : Object | Test.java:102:38:102:68 | (...)... : BasicAuthCredentials | provenance | | +| Test.java:103:8:103:18 | credentials : BasicAuthCredentials | Test.java:103:8:103:32 | getPassword(...) | provenance | MaD:5 | +| Test.java:106:17:106:47 | (...)... : BasicAuthCredentials | Test.java:107:8:107:18 | credentials : BasicAuthCredentials | provenance | | +| Test.java:106:40:106:47 | source(...) : Object | Test.java:106:17:106:47 | (...)... : BasicAuthCredentials | provenance | | +| Test.java:107:8:107:18 | credentials : BasicAuthCredentials | Test.java:107:8:107:32 | getUsername(...) | provenance | MaD:6 | +| Test.java:112:33:112:60 | (...)... : Validator | Test.java:113:8:113:16 | validator : Validator | provenance | | +| Test.java:112:53:112:60 | source(...) : Object | Test.java:112:33:112:60 | (...)... : Validator | provenance | | +| Test.java:113:8:113:16 | validator : Validator | Test.java:113:8:113:22 | get(...) | provenance | MaD:7 | +| Test.java:116:15:116:42 | (...)... : Validator | Test.java:117:8:117:16 | validator : Validator | provenance | | +| Test.java:116:35:116:42 | source(...) : Object | Test.java:116:15:116:42 | (...)... : Validator | provenance | | +| Test.java:117:8:117:16 | validator : Validator | Test.java:117:8:117:35 | getOrDefault(...) | provenance | MaD:8 | +| Test.java:120:15:120:42 | (...)... : Validator | Test.java:121:8:121:16 | validator : Validator | provenance | | +| Test.java:120:35:120:42 | source(...) : Object | Test.java:120:15:120:42 | (...)... : Validator | provenance | | +| Test.java:121:8:121:16 | validator : Validator | Test.java:121:8:121:28 | getOrNull(...) | provenance | MaD:9 | +| Test.java:124:15:124:42 | (...)... : Validator | Test.java:125:8:125:16 | validator : Validator | provenance | | +| Test.java:124:35:124:42 | source(...) : Object | Test.java:124:15:124:42 | (...)... : Validator | provenance | | +| Test.java:125:8:125:16 | validator : Validator | Test.java:125:8:125:33 | getOrThrow(...) | provenance | MaD:10 | +nodes +| Test.java:84:23:84:45 | (...)... : UploadedFile | semmle.label | (...)... : UploadedFile | +| Test.java:84:38:84:45 | source(...) : Object | semmle.label | source(...) : Object | +| Test.java:85:8:85:11 | file : UploadedFile | semmle.label | file : UploadedFile | +| Test.java:85:8:85:21 | content(...) | semmle.label | content(...) | +| Test.java:88:10:88:32 | (...)... : UploadedFile | semmle.label | (...)... : UploadedFile | +| Test.java:88:25:88:32 | source(...) : Object | semmle.label | source(...) : Object | +| Test.java:89:8:89:11 | file : UploadedFile | semmle.label | file : UploadedFile | +| Test.java:89:8:89:25 | contentType(...) | semmle.label | contentType(...) | +| Test.java:92:10:92:32 | (...)... : UploadedFile | semmle.label | (...)... : UploadedFile | +| Test.java:92:25:92:32 | source(...) : Object | semmle.label | source(...) : Object | +| Test.java:93:8:93:11 | file : UploadedFile | semmle.label | file : UploadedFile | +| Test.java:93:8:93:23 | extension(...) | semmle.label | extension(...) | +| Test.java:96:10:96:32 | (...)... : UploadedFile | semmle.label | (...)... : UploadedFile | +| Test.java:96:25:96:32 | source(...) : Object | semmle.label | source(...) : Object | +| Test.java:97:8:97:11 | file : UploadedFile | semmle.label | file : UploadedFile | +| Test.java:97:8:97:22 | filename(...) | semmle.label | filename(...) | +| Test.java:102:38:102:68 | (...)... : BasicAuthCredentials | semmle.label | (...)... : BasicAuthCredentials | +| Test.java:102:61:102:68 | source(...) : Object | semmle.label | source(...) : Object | +| Test.java:103:8:103:18 | credentials : BasicAuthCredentials | semmle.label | credentials : BasicAuthCredentials | +| Test.java:103:8:103:32 | getPassword(...) | semmle.label | getPassword(...) | +| Test.java:106:17:106:47 | (...)... : BasicAuthCredentials | semmle.label | (...)... : BasicAuthCredentials | +| Test.java:106:40:106:47 | source(...) : Object | semmle.label | source(...) : Object | +| Test.java:107:8:107:18 | credentials : BasicAuthCredentials | semmle.label | credentials : BasicAuthCredentials | +| Test.java:107:8:107:32 | getUsername(...) | semmle.label | getUsername(...) | +| Test.java:112:33:112:60 | (...)... : Validator | semmle.label | (...)... : Validator | +| Test.java:112:53:112:60 | source(...) : Object | semmle.label | source(...) : Object | +| Test.java:113:8:113:16 | validator : Validator | semmle.label | validator : Validator | +| Test.java:113:8:113:22 | get(...) | semmle.label | get(...) | +| Test.java:116:15:116:42 | (...)... : Validator | semmle.label | (...)... : Validator | +| Test.java:116:35:116:42 | source(...) : Object | semmle.label | source(...) : Object | +| Test.java:117:8:117:16 | validator : Validator | semmle.label | validator : Validator | +| Test.java:117:8:117:35 | getOrDefault(...) | semmle.label | getOrDefault(...) | +| Test.java:120:15:120:42 | (...)... : Validator | semmle.label | (...)... : Validator | +| Test.java:120:35:120:42 | source(...) : Object | semmle.label | source(...) : Object | +| Test.java:121:8:121:16 | validator : Validator | semmle.label | validator : Validator | +| Test.java:121:8:121:28 | getOrNull(...) | semmle.label | getOrNull(...) | +| Test.java:124:15:124:42 | (...)... : Validator | semmle.label | (...)... : Validator | +| Test.java:124:35:124:42 | source(...) : Object | semmle.label | source(...) : Object | +| Test.java:125:8:125:16 | validator : Validator | semmle.label | validator : Validator | +| Test.java:125:8:125:33 | getOrThrow(...) | semmle.label | getOrThrow(...) | +subpaths +testFailures +| Test.java:15:41:15:57 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:17:25:17:41 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:19:32:19:48 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:21:43:21:59 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:23:47:23:63 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:25:36:25:52 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:27:49:27:65 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:29:33:29:49 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:31:30:31:46 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:33:33:33:49 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:35:30:35:46 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:37:36:37:52 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:39:37:39:53 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:41:33:41:49 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:43:57:43:73 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:45:58:45:74 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:47:36:47:52 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:49:57:49:73 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:51:33:51:49 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:53:37:53:53 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:55:38:55:54 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:57:58:57:74 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:59:59:59:75 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:61:34:61:50 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:63:32:63:48 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:65:39:65:55 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:67:40:67:56 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:69:34:69:50 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:71:36:71:52 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:73:24:73:40 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:75:28:75:44 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:77:32:77:48 | // $ hasTaintFlow | Missing result: hasTaintFlow | +| Test.java:79:30:79:46 | // $ hasTaintFlow | Missing result: hasTaintFlow | diff --git a/java/ql/test/library-tests/frameworks/javalin/test.ql b/java/ql/test/library-tests/frameworks/javalin/test.ql new file mode 100644 index 000000000000..de0d4722737b --- /dev/null +++ b/java/ql/test/library-tests/frameworks/javalin/test.ql @@ -0,0 +1,4 @@ +import java +import utils.test.InlineFlowTest +import DefaultFlowTest +import TaintFlow::PathGraph diff --git a/java/ql/test/library-tests/frameworks/spark/Test.java b/java/ql/test/library-tests/frameworks/spark/Test.java new file mode 100644 index 000000000000..fd63e2aec94f --- /dev/null +++ b/java/ql/test/library-tests/frameworks/spark/Test.java @@ -0,0 +1,70 @@ +package generatedtest; + +import spark.QueryParamsMap; +import spark.Request; + +public class Test { + Object source() { return null; } + void sink(Object value) { } + + public void testSources(Request request) { + // "spark;Request;true;body;;;ReturnValue;remote;manual" + sink(request.body()); // $ hasTaintFlow + // "spark;Request;true;bodyAsBytes;;;ReturnValue;remote;manual" + sink(request.bodyAsBytes()); // $ hasTaintFlow + // "spark;Request;true;cookie;;;ReturnValue;remote;manual" + sink(request.cookie("name")); // $ hasTaintFlow + // "spark;Request;true;cookies;;;ReturnValue;remote;manual" + sink(request.cookies()); // $ hasTaintFlow + // "spark;Request;true;headers;;;ReturnValue;remote;manual" + sink(request.headers()); // $ hasTaintFlow + // "spark;Request;true;headers;;;ReturnValue;remote;manual" + sink(request.headers("name")); // $ hasTaintFlow + // "spark;Request;true;params;;;ReturnValue;remote;manual" + sink(request.params()); // $ hasTaintFlow + // "spark;Request;true;params;;;ReturnValue;remote;manual" + sink(request.params("name")); // $ hasTaintFlow + // "spark;Request;true;queryMap;;;ReturnValue;remote;manual" + sink(request.queryMap()); // $ hasTaintFlow + // "spark;Request;true;queryMap;;;ReturnValue;remote;manual" + sink(request.queryMap("name")); // $ hasTaintFlow + // "spark;Request;true;queryParams;;;ReturnValue;remote;manual" + sink(request.queryParams()); // $ hasTaintFlow + // "spark;Request;true;queryParams;;;ReturnValue;remote;manual" + sink(request.queryParams("name")); // $ hasTaintFlow + // "spark;Request;true;queryParamsSafe;;;ReturnValue;remote;manual" + sink(request.queryParamsSafe("name")); // $ hasTaintFlow + // "spark;Request;true;queryParamOrDefault;;;ReturnValue;remote;manual" + sink(request.queryParamOrDefault("name", "default")); // $ hasTaintFlow + // "spark;Request;true;queryParamsValues;;;ReturnValue;remote;manual" + sink(request.queryParamsValues("name")); // $ hasTaintFlow + // "spark;Request;true;queryString;;;ReturnValue;remote;manual" + sink(request.queryString()); // $ hasTaintFlow + // "spark;Request;true;uri;;;ReturnValue;remote;manual" + sink(request.uri()); // $ hasTaintFlow + // "spark;Request;true;url;;;ReturnValue;remote;manual" + sink(request.url()); // $ hasTaintFlow + } + + public void testAdditionalFlowSteps() { + // "spark;QueryParamsMap;true;get;;;Argument[this];ReturnValue;taint;manual" + QueryParamsMap queryParams = (QueryParamsMap) source(); + sink(queryParams.get("first", "second")); // $ hasTaintFlow + + // "spark;QueryParamsMap;true;toMap;;;Argument[this];ReturnValue;taint;manual" + queryParams = (QueryParamsMap) source(); + sink(queryParams.toMap()); // $ hasTaintFlow + + // "spark;QueryParamsMap;true;value;;;Argument[this];ReturnValue;taint;manual" + queryParams = (QueryParamsMap) source(); + sink(queryParams.value()); // $ hasTaintFlow + + // "spark;QueryParamsMap;true;value;;;Argument[this];ReturnValue;taint;manual" + queryParams = (QueryParamsMap) source(); + sink(queryParams.value("first", "second")); // $ hasTaintFlow + + // "spark;QueryParamsMap;true;values;;;Argument[this];ReturnValue;taint;manual" + queryParams = (QueryParamsMap) source(); + sink(queryParams.values()); // $ hasTaintFlow + } +} \ No newline at end of file diff --git a/java/ql/test/library-tests/frameworks/spark/options b/java/ql/test/library-tests/frameworks/spark/options new file mode 100644 index 000000000000..ea57c1e09e06 --- /dev/null +++ b/java/ql/test/library-tests/frameworks/spark/options @@ -0,0 +1 @@ +//semmle-extractor-options: --javac-args -cp ${testdir}/../../../stubs/spark \ No newline at end of file diff --git a/java/ql/test/library-tests/frameworks/spark/test.expected b/java/ql/test/library-tests/frameworks/spark/test.expected new file mode 100644 index 000000000000..e69de29bb2d1 diff --git a/java/ql/test/library-tests/frameworks/spark/test.ql b/java/ql/test/library-tests/frameworks/spark/test.ql new file mode 100644 index 000000000000..d9dafb0e7846 --- /dev/null +++ b/java/ql/test/library-tests/frameworks/spark/test.ql @@ -0,0 +1,3 @@ +import java +import utils.test.InlineFlowTest +import DefaultFlowTest diff --git a/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/LICENSE.txt b/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/LICENSE.txt new file mode 100644 index 000000000000..c6b4a3bbcf58 --- /dev/null +++ b/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/LICENSE.txt @@ -0,0 +1,202 @@ + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + https://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. \ No newline at end of file diff --git a/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/dbutils/AsyncQueryRunner.java b/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/dbutils/AsyncQueryRunner.java new file mode 100644 index 000000000000..72eb928fa084 --- /dev/null +++ b/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/dbutils/AsyncQueryRunner.java @@ -0,0 +1,26 @@ +// Generated automatically from org.apache.commons.dbutils.AsyncQueryRunner for testing purposes + +package org.apache.commons.dbutils; + +import java.sql.Connection; +import java.sql.SQLException; +import java.util.concurrent.Future; + +public class AsyncQueryRunner { + public Future insert(Connection conn, String sql, ResultSetHandler rsh) throws SQLException { return null; } + public Future insert(Connection conn, String sql, ResultSetHandler rsh, Object... params) throws SQLException { return null; } + public Future insert(String sql, ResultSetHandler rsh) throws SQLException { return null; } + public Future insert(String sql, ResultSetHandler rsh, Object... params) throws SQLException { return null; } + + public Future query(Connection conn, String sql, ResultSetHandler rsh) throws SQLException { return null; } + public Future query(Connection conn, String sql, ResultSetHandler rsh, Object... params) throws SQLException { return null; } + public Future query(String sql, ResultSetHandler rsh) throws SQLException { return null; } + public Future query(String sql, ResultSetHandler rsh, Object... params) throws SQLException { return null; } + + public Future update(Connection conn, String sql) throws SQLException { return null; } + public Future update(Connection conn, String sql, Object param) throws SQLException { return null; } + public Future update(Connection conn, String sql, Object... params) throws SQLException { return null; } + public Future update(String sql) throws SQLException { return null; } + public Future update(String sql, Object param) throws SQLException { return null; } + public Future update(String sql, Object... params) throws SQLException { return null; } +} diff --git a/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/dbutils/QueryRunner.java b/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/dbutils/QueryRunner.java new file mode 100644 index 000000000000..91491e7b9cf6 --- /dev/null +++ b/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/dbutils/QueryRunner.java @@ -0,0 +1,25 @@ +// Generated automatically from org.apache.commons.dbutils.QueryRunner for testing purposes + +package org.apache.commons.dbutils; + +import java.sql.Connection; +import java.sql.SQLException; + +public class QueryRunner { + public T insert(Connection conn, String sql, ResultSetHandler rsh) throws SQLException { return null; } + public T insert(Connection conn, String sql, ResultSetHandler rsh, Object... params) throws SQLException { return null; } + public T insert(String sql, ResultSetHandler rsh) throws SQLException { return null; } + public T insert(String sql, ResultSetHandler rsh, Object... params) throws SQLException { return null; } + + public T query(Connection conn, String sql, ResultSetHandler rsh) throws SQLException { return null; } + public T query(Connection conn, String sql, ResultSetHandler rsh, Object... params) throws SQLException { return null; } + public T query(String sql, ResultSetHandler rsh) throws SQLException { return null; } + public T query(String sql, ResultSetHandler rsh, Object... params) throws SQLException { return null; } + + public int update(Connection conn, String sql) throws SQLException { return 0; } + public int update(Connection conn, String sql, Object param) throws SQLException { return 0; } + public int update(Connection conn, String sql, Object... params) throws SQLException { return 0; } + public int update(String sql) throws SQLException { return 0; } + public int update(String sql, Object param) throws SQLException { return 0; } + public int update(String sql, Object... params) throws SQLException { return 0; } +} diff --git a/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/dbutils/ResultSetHandler.java b/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/dbutils/ResultSetHandler.java new file mode 100644 index 000000000000..20abb0383ca5 --- /dev/null +++ b/java/ql/test/stubs/apache-commons-dbutils/org/apache/commons/dbutils/ResultSetHandler.java @@ -0,0 +1,10 @@ +// Generated automatically from org.apache.commons.dbutils.ResultSetHandler for testing purposes + +package org.apache.commons.dbutils; + +import java.sql.ResultSet; +import java.sql.SQLException; + +public interface ResultSetHandler { + T handle(ResultSet resultSet) throws SQLException; +} diff --git a/java/ql/test/stubs/bigquery/LICENSE.txt b/java/ql/test/stubs/bigquery/LICENSE.txt new file mode 100644 index 000000000000..f49a4e16e68b --- /dev/null +++ b/java/ql/test/stubs/bigquery/LICENSE.txt @@ -0,0 +1,201 @@ + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. \ No newline at end of file diff --git a/java/ql/test/stubs/bigquery/com/google/cloud/bigquery/QueryJobConfiguration.java b/java/ql/test/stubs/bigquery/com/google/cloud/bigquery/QueryJobConfiguration.java new file mode 100644 index 000000000000..64dd96fc6b3d --- /dev/null +++ b/java/ql/test/stubs/bigquery/com/google/cloud/bigquery/QueryJobConfiguration.java @@ -0,0 +1,16 @@ +// Generated automatically from com.google.cloud.bigquery.QueryJobConfiguration for testing purposes + +package com.google.cloud.bigquery; + +public final class QueryJobConfiguration { + private QueryJobConfiguration() { } + + public static Builder newBuilder(String query) { return null; } + public static QueryJobConfiguration of(String query) { return null; } + + public static final class Builder { + private Builder() { } + + public Builder setQuery(String query) { return null; } + } +} diff --git a/java/ql/test/stubs/javalin/LICENSE.txt b/java/ql/test/stubs/javalin/LICENSE.txt new file mode 100644 index 000000000000..a8d4715ed93e --- /dev/null +++ b/java/ql/test/stubs/javalin/LICENSE.txt @@ -0,0 +1,201 @@ + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "{}" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright 2017 David Åse + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. \ No newline at end of file diff --git a/java/ql/test/stubs/javalin/io/javalin/http/Context.java b/java/ql/test/stubs/javalin/io/javalin/http/Context.java new file mode 100644 index 000000000000..02841bcd586e --- /dev/null +++ b/java/ql/test/stubs/javalin/io/javalin/http/Context.java @@ -0,0 +1,46 @@ +// Generated automatically from io.javalin.http.Context for testing purposes + +package io.javalin.http; + +import io.javalin.security.BasicAuthCredentials; +import io.javalin.validation.Validator; +import java.io.InputStream; +import java.lang.reflect.Type; +import java.util.List; +import java.util.Map; + +public interface Context { + BasicAuthCredentials basicAuthCredentials(); + String body(); + byte[] bodyAsBytes(); + T bodyAsClass(Type type); + T bodyAsClass(Class clazz); + InputStream bodyInputStream(); + T bodyStreamAsClass(Type type); + String cookie(String name); + Map cookieMap(); + String header(String header); + Map headerMap(); + String formParam(String key); + List formParams(String key); + Map> formParamMap(); + Validator formParamAsClass(String key, Class clazz); + Validator> formParamsAsClass(String key, Class clazz); + String pathParam(String key); + Validator pathParamAsClass(String key, Class clazz); + Map pathParamMap(); + String queryParam(String key); + List queryParams(String key); + Validator queryParamAsClass(String key, Class clazz); + Validator> queryParamsAsClass(String key, Class clazz); + Map> queryParamMap(); + String queryString(); + UploadedFile uploadedFile(String fileName); + List uploadedFiles(String fileName); + List uploadedFiles(); + Map> uploadedFileMap(); + String url(); + String fullUrl(); + String contentType(); + String userAgent(); +} diff --git a/java/ql/test/stubs/javalin/io/javalin/http/UploadedFile.java b/java/ql/test/stubs/javalin/io/javalin/http/UploadedFile.java new file mode 100644 index 000000000000..95f768e97c93 --- /dev/null +++ b/java/ql/test/stubs/javalin/io/javalin/http/UploadedFile.java @@ -0,0 +1,12 @@ +// Generated automatically from io.javalin.http.UploadedFile for testing purposes + +package io.javalin.http; + +import java.io.InputStream; + +public final class UploadedFile { + public InputStream content() { return null; } + public String contentType() { return null; } + public String extension() { return null; } + public String filename() { return null; } +} diff --git a/java/ql/test/stubs/javalin/io/javalin/security/BasicAuthCredentials.java b/java/ql/test/stubs/javalin/io/javalin/security/BasicAuthCredentials.java new file mode 100644 index 000000000000..202aebb95775 --- /dev/null +++ b/java/ql/test/stubs/javalin/io/javalin/security/BasicAuthCredentials.java @@ -0,0 +1,8 @@ +// Generated automatically from io.javalin.security.BasicAuthCredentials for testing purposes + +package io.javalin.security; + +public final class BasicAuthCredentials { + public String getPassword() { return null; } + public String getUsername() { return null; } +} diff --git a/java/ql/test/stubs/javalin/io/javalin/validation/Validator.java b/java/ql/test/stubs/javalin/io/javalin/validation/Validator.java new file mode 100644 index 000000000000..d4ecc043edfe --- /dev/null +++ b/java/ql/test/stubs/javalin/io/javalin/validation/Validator.java @@ -0,0 +1,10 @@ +// Generated automatically from io.javalin.validation.Validator for testing purposes + +package io.javalin.validation; + +public class Validator { + public T get() { return null; } + public T getOrDefault(T defaultValue) { return null; } + public T getOrNull() { return null; } + public T getOrThrow(Object exceptionFunction) { return null; } +} diff --git a/java/ql/test/stubs/spark/LICENSE.txt b/java/ql/test/stubs/spark/LICENSE.txt new file mode 100644 index 000000000000..7a4a3ea2424c --- /dev/null +++ b/java/ql/test/stubs/spark/LICENSE.txt @@ -0,0 +1,202 @@ + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. \ No newline at end of file diff --git a/java/ql/test/stubs/spark/QueryParamsMap.java b/java/ql/test/stubs/spark/QueryParamsMap.java new file mode 100644 index 000000000000..34cc903ee50c --- /dev/null +++ b/java/ql/test/stubs/spark/QueryParamsMap.java @@ -0,0 +1,13 @@ +// Generated automatically from spark.QueryParamsMap for testing purposes + +package spark; + +import java.util.Map; + +public class QueryParamsMap { + public QueryParamsMap get(String... keys) { return null; } + public Map toMap() { return null; } + public String value() { return null; } + public String value(String... keys) { return null; } + public String[] values() { return null; } +} diff --git a/java/ql/test/stubs/spark/Request.java b/java/ql/test/stubs/spark/Request.java new file mode 100644 index 000000000000..0387987eaf43 --- /dev/null +++ b/java/ql/test/stubs/spark/Request.java @@ -0,0 +1,27 @@ +// Generated automatically from spark.Request for testing purposes + +package spark; + +import java.util.Map; +import java.util.Set; + +public class Request { + public String body() { return null; } + public byte[] bodyAsBytes() { return null; } + public String cookie(String name) { return null; } + public Map cookies() { return null; } + public Set headers() { return null; } + public String headers(String header) { return null; } + public Map params() { return null; } + public String params(String param) { return null; } + public QueryParamsMap queryMap() { return null; } + public QueryParamsMap queryMap(String key) { return null; } + public Set queryParams() { return null; } + public String queryParams(String queryParam) { return null; } + public String queryParamsSafe(String queryParam) { return null; } + public String queryParamOrDefault(String queryParam, String defaultValue) { return null; } + public String[] queryParamsValues(String queryParam) { return null; } + public String queryString() { return null; } + public String uri() { return null; } + public String url() { return null; } +}