[
https://issues.apache.org/jira/browse/FINERACT-682?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16739153#comment-16739153
]
Shruthi M R commented on FINERACT-682:
---------------------------------------
[~vishwasbabu],
Thanks for highlighting issues. Yes, if I rename those parameters it will
definitely hit the existing hardcoded parameters containing DDL, DML keywords.
-> parameter names (which are replaced with their corresponding queries by
fineract and not passed to the database) should only be validated against an
alphanumeric regex. Is there a need to validate them for containing DDL or DML
keywords ?
- Agreed. And yes I shouldn't have put an extra validation to check
against DDL and DML keywords against above mentioned cases. I will remove the
extra validation.
> Renaming stretchy_report parameters conflicting with sql injection
> ------------------------------------------------------------------
>
> Key: FINERACT-682
> URL: https://issues.apache.org/jira/browse/FINERACT-682
> Project: Apache Fineract
> Issue Type: Bug
> Reporter: Shruthi M R
> Assignee: Shruthi M R
> Priority: Major
> Fix For: 1.3.0
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)