Skip to content

Refactor CWE-319/UseOfHttp.ql for performance - #22748

Merged
mbaluda merged 2 commits into
github:mainfrom
mbaluda:mbaluda/useofhttp-perf
Oct 6, 2026
Merged

mbaluda merged 2 commits into
github:mainfrom
mbaluda:mbaluda/useofhttp-perf

Conversation

@mbaluda

@mbaluda mbaluda commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Materialize HTTP string candidates before computing recursive parent relations, allowing the RA plan to restrict getParent*() and the subsequent private-host antijoin to the filtered candidate set.

Materialize HTTP string candidates before computing recursive parent relations, allowing the RA plan to restrict getParent*() and the subsequent private-host antijoin to the filtered candidate set.
Copilot AI balanced review requested due to automatic review settings October 3, 2026 17:00
@mbaluda
mbaluda requested a review from a team as a code owner October 3, 2026 17:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The refactor preserves query semantics; only a minor QLDoc placement issue remains.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Refactors HTTP literal filtering to narrow candidates before recursive parent analysis, improving query performance without changing detection logic.

Changes:

  • Introduces a private HTTP string candidate class.
  • Applies private-host flow filtering only to prefiltered candidates.
File Description
cpp/​ql/​src/​Security/​CWE/​CWE-319/​UseOfHttp.ql Splits candidate selection from recursive private-host filtering.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql
@github-actions github-actions Bot added the C++ label Oct 3, 2026
@mbaluda mbaluda changed the title Refactor HttpStringLiteral for performance Refactor CWE-319/UseOfHttp.ql for performance Oct 5, 2026
@geoffw0 geoffw0 added the no-change-note-required This PR does not need a change note label Oct 5, 2026
@mbaluda
mbaluda requested a review from geoffw0 October 5, 2026 16:36

@geoffw0 geoffw0 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks for addressing this problem.

@mbaluda
mbaluda merged commit 6647e5f into github:main Oct 6, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

C++ no-change-note-required This PR does not need a change note

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants