Skip to content

Refactor CWE-319/UseOfHttp.ql for performance - #22748

Open
mbaluda wants to merge 2 commits into
github:mainfrom
mbaluda:mbaluda/useofhttp-perf
Open

mbaluda wants to merge 2 commits into
github:mainfrom
mbaluda:mbaluda/useofhttp-perf

Conversation

@mbaluda

@mbaluda mbaluda commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Materialize HTTP string candidates before computing recursive parent relations, allowing the RA plan to restrict getParent*() and the subsequent private-host antijoin to the filtered candidate set.

Materialize HTTP string candidates before computing recursive parent relations, allowing the RA plan to restrict getParent*() and the subsequent private-host antijoin to the filtered candidate set.
Copilot AI balanced review requested due to automatic review settings October 3, 2026 17:00
@mbaluda
mbaluda requested a review from a team as a code owner October 3, 2026 17:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The refactor preserves query semantics; only a minor QLDoc placement issue remains.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Refactors HTTP literal filtering to narrow candidates before recursive parent analysis, improving query performance without changing detection logic.

Changes:

  • Introduces a private HTTP string candidate class.
  • Applies private-host flow filtering only to prefiltered candidates.
File Description
cpp/​ql/​src/​Security/​CWE/​CWE-319/​UseOfHttp.ql Splits candidate selection from recursive private-host filtering.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql
@github-actions github-actions Bot added the C++ label Oct 3, 2026
@mbaluda mbaluda changed the title Refactor HttpStringLiteral for performance Refactor CWE-319/UseOfHttp.ql for performance Oct 5, 2026
@geoffw0 geoffw0 added the no-change-note-required This PR does not need a change note label Oct 5, 2026
@mbaluda
mbaluda requested a review from geoffw0 October 5, 2026 16:36

@geoffw0 geoffw0 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks for addressing this problem.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

C++ no-change-note-required This PR does not need a change note

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants