allthingssecurity opened a new pull request, #27528:
URL: https://github.com/apache/camel/pull/27528

   # Description
   
   [CAMEL-25353](https://issues.apache.org/jira/browse/CAMEL-25353)
   
   `DefaultSqlPrepareStatementStrategy.prepareQuery` found each `:?in:<name>` 
and then replaced every match of the regular expression `":?in:" + name` in the 
whole query. With `:#in:project` before `:#in:projectLicense`, the first 
replacement also replaced the start of the second parameter, which became `in 
(?,?License)` (a syntax error); and `:#in:${body[names]}` was not replaced at 
all, since `[` and `]` were not escaped.
   
   This change replaces each match where it is, in one pass 
(`Matcher.appendReplacement`), with as many placeholders as its own parameter 
has values. Queries that worked are prepared as before (also a name used more 
than once, which was replaced everywhere by its first match and is now replaced 
at each match with the same values), so there is no upgrade-guide note. It also 
no longer compiles a regular expression per `:#in:` parameter on each exchange.
   
   Tests: new `SqlProducerInParameterNamesTest`, both tests fail without the 
change with a `BadSqlGrammarException` (H2 sees `license in (?,?License)` and 
`project in (?:$ body[names] )`). camel-sql: 301 tests pass except the 2 of 
`SqlFunctionDataSourceTest`, whose embedded MariaDB cannot start on my machine 
(missing `libpcre2`), unrelated to this change.
   
   Found with a Lean 4 model of the `replaceAll` loop and of the one-pass 
replacement: "each IN list has the number of values of its own parameter" fails 
on main whenever the first name is a prefix of the second, and the fix gives 
the same SQL as main exactly when it is not (checked exhaustively on a small 
domain of names and value counts).
   
   # Target
   
   - [x] I checked that the commit is targeting the correct branch (Camel 4 
uses the `main` branch)
   
   # Tracking
   - [x] If this is a large change, bug fix, or code improvement, I checked 
there is a [JIRA issue](https://issues.apache.org/jira/browse/CAMEL) filed for 
the change (usually before you start working on it).
   
   # Apache Camel coding standards and style
   
   - [x] I checked that each commit in the pull request has a meaningful 
subject line and body.
   - [ ] I have run `mvn clean install -DskipTests` locally from root folder 
and I have committed all auto-generated changes.
     (I built and tested the affected module, including the formatter and 
import-sort plugins. I did not run the full root build.)
   
   # AI-assisted contributions
   
   - [x] If this PR includes AI-generated code, commits have proper 
co-authorship attribution (e.g., `Co-authored-by` trailers) and the PR 
description identifies the AI tool used.
     This PR was prepared with Claude Code (Claude Opus 5.5). The commit 
carries a `Co-Authored-By` trailer.
   
   _Claude Code on behalf of allthingssecurity_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to