Skip to content

Refactor HttpStringLiteral for performance - #22748

Open
mbaluda wants to merge 1 commit into
github:mainfrom
mbaluda:mbaluda/useofhttp-perf
Open

mbaluda wants to merge 1 commit into
github:mainfrom
mbaluda:mbaluda/useofhttp-perf

Conversation

@mbaluda

@mbaluda mbaluda commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Materialize HTTP string candidates before computing recursive parent relations, allowing the RA plan to restrict getParent*() and the subsequent private-host antijoin to the filtered candidate set.

Materialize HTTP string candidates before computing recursive parent relations, allowing the RA plan to restrict getParent*() and the subsequent private-host antijoin to the filtered candidate set.
Copilot AI balanced review requested due to automatic review settings October 3, 2026 17:00
@mbaluda
mbaluda requested a review from a team as a code owner October 3, 2026 17:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The refactor preserves query semantics; only a minor QLDoc placement issue remains.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Refactors HTTP literal filtering to narrow candidates before recursive parent analysis, improving query performance without changing detection logic.

Changes:

  • Introduces a private HTTP string candidate class.
  • Applies private-host flow filtering only to prefiltered candidates.
File Description
cpp/​ql/​src/​Security/​CWE/​CWE-319/​UseOfHttp.ql Splits candidate selection from recursive private-host filtering.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

*/
class HttpStringLiteral extends StringLiteral {
HttpStringLiteral() {
private class HttpStringLiteralCandidate extends StringLiteral {
@github-actions github-actions Bot added the C++ label Oct 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants