gnodet-bot commented on code in PR #26939:
URL: https://github.com/apache/camel/pull/26939#discussion_r4129566240
##########
core/camel-base-engine/src/main/java/org/apache/camel/impl/debugger/DefaultBacklogTracerEventMessage.java:
##########
@@ -372,34 +372,39 @@ public String toXml(int indent) {
sb.append(prefix).append("
<done>").append(isDone()).append("</done>\n");
sb.append(prefix).append("
<failed>").append(isFailed()).append("</failed>\n");
if (getLocation() != null) {
- sb.append(prefix).append("
<location>").append(getLocation()).append("</location>\n");
+ sb.append(prefix).append("
<location>").append(StringHelper.xmlEncode(getLocation())).append("</location>\n");
}
// route id is optional and we then use an empty value for no route id
- sb.append(prefix).append(" <routeId>").append(routeId != null ?
routeId : "").append("</routeId>\n");
- sb.append(prefix).append(" <fromRouteId>").append(fromRouteId != null
? fromRouteId : "").append("</fromRouteId>\n");
+ sb.append(prefix).append(" <routeId>").append(routeId != null ?
StringHelper.xmlEncode(routeId) : "")
+ .append("</routeId>\n");
+ sb.append(prefix).append(" <fromRouteId>").append(fromRouteId != null
? StringHelper.xmlEncode(fromRouteId) : "")
+ .append("</fromRouteId>\n");
if (endpointUri != null) {
- sb.append(prefix).append("
<endpointUri>").append(endpointUri).append("</endpointUri>\n");
+ sb.append(prefix).append("
<endpointUri>").append(StringHelper.xmlEncode(endpointUri)).append("</endpointUri>\n");
sb.append(prefix).append("
<remoteEndpoint>").append(remoteEndpoint).append("</remoteEndpoint>\n");
sb.append(prefix).append("
<stubEndpoint>").append(stubEndpoint).append("</stubEndpoint>\n");
}
if (toNode != null) {
- sb.append(prefix).append("
<toNode>").append(toNode).append("</toNode>\n");
+ sb.append(prefix).append("
<toNode>").append(StringHelper.xmlEncode(toNode)).append("</toNode>\n");
} else {
// if first message the use routeId as toNode
- sb.append(prefix).append("
<toNode>").append(routeId).append("</toNode>\n");
+ sb.append(prefix).append(" <toNode>").append(routeId != null ?
StringHelper.xmlEncode(routeId) : "")
+ .append("</toNode>\n");
}
sb.append(prefix).append("
<exchangeId>").append(exchangeId).append("</exchangeId>\n");
if (endpointServiceUrl != null) {
sb.append(prefix).append(" <endpointService>\n");
- sb.append(prefix).append("
<serviceUrl>").append(endpointServiceUrl).append("</serviceUrl>\n");
+ sb.append(prefix).append("
<serviceUrl>").append(StringHelper.xmlEncode(endpointServiceUrl))
+ .append("</serviceUrl>\n");
if (endpointServiceProtocol != null) {
- sb.append(prefix).append("
<serviceProtocol>").append(endpointServiceProtocol)
+ sb.append(prefix).append("
<serviceProtocol>").append(StringHelper.xmlEncode(endpointServiceProtocol))
.append("</serviceProtocol>\n");
}
if (endpointServiceMetadata != null) {
sb.append(prefix).append(" <serviceMetadata>\n");
endpointServiceMetadata.forEach((k, v) -> {
- sb.append(prefix).append("
<").append(k).append(">").append(v).append("</").append(k).append(">\n");
+ sb.append(prefix).append("
<").append(k).append(">").append(StringHelper.xmlEncode(v)).append("</")
+ .append(k).append(">\n");
Review Comment:
💡 **Nit:** The value `v` is XML-encoded but the key `k` — used as an XML
element name — is not. If a metadata key ever contained `&` or `<`, the XML
output would be malformed. In practice these keys are programmatic constants
from Camel endpoint metadata, so the risk is negligible, but for consistency
with the rest of this encoding work you could `xmlEncode(k)` too (or at least
the closing tag).
Non-blocking — the existing code had the same gap and the keys are safe in
practice.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]