jdaugherty opened a new pull request, #16463:
URL: https://github.com/apache/grails-core/pull/16463

   The GormUnsafeQueryString check flagged every GString coerced to a String
   before reaching a GORM query method, including the common pattern of
   assembling query text from fixed HQL fragments chosen at runtime:
   
       String restriction = shouldIncludeTitle ? " and b.title = :title" : ""
       String query = "from Book b where 1 = 1 ${restriction}"
       Book.executeQuery(query, queryParams)
   
   The documented fix - keep the query a GString - does not apply there: GORM
   binds every interpolation as a parameter, so the fragment would be bound as
   a value and the query would stop working.
   
   The check now tells query text from values. An interpolation that is
   constant text (a literal, a static final field initialised from constant
   text, a ternary or Elvis over constant text, a +/GString/cast/toString of
   constant text, or a local that only ever held constant text on every path)
   cannot carry user input and is no longer a finding. Compound assignment
   with += is tracked like x = x + y, so a constant query stays constant when
   constant text is appended, and a live GString or already-flattened operand
   anywhere in a + concatenation makes the result flattened (an error) rather
   than the lower-confidence concatenation warning.
   
   @SuppressWarnings("GormUnsafeQueryString") can now also go on a local
   variable or field declaration. It marks that one variable as reviewed for
   the rest of the method, whatever it is later assigned, treats it as
   constant text wherever it is interpolated, and leaves every other variable
   checked.
   
   The error and warning messages, the security guide and the Grails 8
   upgrade notes explain the query-text case and no longer recommend a GString
   for fragments.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to