jdaugherty opened a new pull request, #16463:
URL: https://github.com/apache/grails-core/pull/16463
The GormUnsafeQueryString check flagged every GString coerced to a String
before reaching a GORM query method, including the common pattern of
assembling query text from fixed HQL fragments chosen at runtime:
String restriction = shouldIncludeTitle ? " and b.title = :title" : ""
String query = "from Book b where 1 = 1 ${restriction}"
Book.executeQuery(query, queryParams)
The documented fix - keep the query a GString - does not apply there: GORM
binds every interpolation as a parameter, so the fragment would be bound as
a value and the query would stop working.
The check now tells query text from values. An interpolation that is
constant text (a literal, a static final field initialised from constant
text, a ternary or Elvis over constant text, a +/GString/cast/toString of
constant text, or a local that only ever held constant text on every path)
cannot carry user input and is no longer a finding. Compound assignment
with += is tracked like x = x + y, so a constant query stays constant when
constant text is appended, and a live GString or already-flattened operand
anywhere in a + concatenation makes the result flattened (an error) rather
than the lower-confidence concatenation warning.
@SuppressWarnings("GormUnsafeQueryString") can now also go on a local
variable or field declaration. It marks that one variable as reviewed for
the rest of the method, whatever it is later assigned, treats it as
constant text wherever it is interpolated, and leaves every other variable
checked.
The error and warning messages, the security guide and the Grails 8
upgrade notes explain the query-text case and no longer recommend a GString
for fragments.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]