davsclaus opened a new pull request, #26916:
URL: https://github.com/apache/camel/pull/26916

   A named parameter in the `sql` component is written `:#name`, or 
`:#${simple}` for an expression. A query that spells one the way other tools do 
— `:name`, or `:${body.name}` — has no named parameter in it as far as the 
component is concerned: `DefaultSqlPrepareStatementStrategy.prepareQuery` finds 
nothing to replace and returns the query unchanged, so it reaches the database 
as it stands and comes back as the database's own complaint:
   
   ```
   Syntax error in SQL statement "INSERT INTO customers (id, country, orders) 
VALUES ([*]:$ body[customer] , :$ body[country] , 1) ..."
   ```
   
   That names neither Camel nor the query as it was written. (The braces are 
blanked by H2's own JDBC-escape handling, which makes it harder still to 
connect back to what was saved.)
   
   The component now warns when the endpoint is created, naming the offending 
text and the supported form:
   
   ```
   The query of sql://insert into customers (id) values (:customer) has 
:customer which is not a named parameter,
   so it is sent to the database as it stands. A named parameter is written 
:#name, or :#${...} for a Simple
   expression, and its value is taken from a Simple expression, the message 
body when that is a Map, a message
   header, or an exchange variable. Query: insert into customers (id) values 
(:customer)
   ```
   
   **It stays a warning and never rejects the query.** A colon appears 
legitimately in SQL, and a query Camel does not understand may still be one the 
database does.
   
   **Avoiding false positives** is most of the work, since a colon is common in 
SQL. `SqlHelper.findParameterMissingPlaceholder`:
   
   - takes the correctly written parameters out of the query first — one of 
them ends in a name after a colon (`:#in:myList`), which would otherwise look 
like the mistake;
   - blanks the contents of single-quoted literals, so `':customer not known'` 
is data rather than SQL (a doubled quote escapes, as in SQL);
   - requires the character after the colon to start a name or a `$` 
expression, so a time literal `12:30` is not one;
   - rejects a colon preceded by a colon, so a Postgres `::text` cast is not 
one;
   - builds its patterns from the endpoint's own `placeholder` option rather 
than assuming `#`.
   
   It looks for the shapes people actually write — `:name`, `:${...}`, 
`:$simple{...}`, `:$name` — and not for a colon followed by arbitrary 
punctuation, which would catch SQL more often than a mistake. The javadoc says 
so, and the consequence is stated in a test: with `placeholder` set to 
something other than the default, a query using `:#name` is not reported.
   
   Tests: `SqlNamedParameterWithoutPlaceholderTest` (11) covers each of those 
cases; `SqlNamedParameterWarnTest` (2) creates a real endpoint and asserts the 
warning fires, names the supported form, and leaves the query untouched — and 
that a correct `:#customer` does not warn and *is* substituted.
   
   **Across the 300 existing camel-sql tests the warning does not fire once**, 
which is the check that matters for a change like this. Full camel-sql suite 
green, plus a full reactor build (which regenerated the catalog copy of the 
component doc, included here).
   
   Found while measuring how well a local model writes Camel routes through the 
camel-jbang-mcp server: a step that registers a row with named parameters was 
failed by all 20 attempts across two 10-pass runs, and the attempts were 
`:customer` and `:${body[customer]}` — both missing the `#`. CAMEL-25040 is the 
other half: the catalog documentation the model consulted never shows `:#` at 
all.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   
   https://claude.ai/code/session_01Bp3538HRBPMQkb5ta9xRaj
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to