[ 
https://issues.apache.org/jira/browse/AVRO-4311?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Ismaël Mejía reassigned AVRO-4311:
----------------------------------

    Assignee: Ismaël Mejía

> [java] Neutralize backslashes when escaping schema docs into generated Javadoc
> ------------------------------------------------------------------------------
>
>                 Key: AVRO-4311
>                 URL: https://issues.apache.org/jira/browse/AVRO-4311
>             Project: Apache Avro
>          Issue Type: Bug
>          Components: java
>            Reporter: Ismaël Mejía
>            Assignee: Ismaël Mejía
>            Priority: Major
>
> The Java code generator (avro-compiler / avro-maven-plugin) writes schema 
> documentation strings into the Javadoc comments of generated Java sources. 
> The `escapeForJavadoc` helper escapes the comment terminator (`*/`) and HTML 
> metacharacters, but it does not neutralize backslashes.
> The Java compiler translates Unicode escapes (`\uXXXX`) across the whole 
> source file, including inside comments, before comments are recognized (JLS 
> 3.3). As a result, a documentation string that contains backslash sequences 
> can be reinterpreted by the compiler and change the generated source in 
> unintended ways.
> Fix: update `escapeForJavadoc` to also neutralize backslashes by encoding 
> them as the HTML entity `\`, so documentation content is always emitted 
> as inert text in the generated Javadoc. A regression test covering several 
> escape forms is added.
> The string-literal path (`escapeForJavaString`, used for the embedded schema) 
> already doubles backslashes and is unaffected.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to