SqlIdentifierParameterSource now sanitizes identifier names.

Closes #1405
See #1406
Original pull request #1415
This commit is contained in:
Jens Schauder
2023-01-23 15:49:28 +01:00
committed by Mark Paluch
parent e2422c2a83
commit eff0c72126
6 changed files with 70 additions and 6 deletions

View File

@@ -38,6 +38,7 @@ import org.springframework.data.convert.WritingConverter;
import org.springframework.data.jdbc.core.mapping.JdbcMappingContext;
import org.springframework.data.relational.core.conversion.IdValueSource;
import org.springframework.data.relational.core.dialect.AnsiDialect;
import org.springframework.data.relational.core.mapping.Column;
import org.springframework.data.relational.core.mapping.RelationalMappingContext;
import org.springframework.data.relational.core.sql.SqlIdentifier;
import org.springframework.jdbc.core.JdbcOperations;
@@ -147,6 +148,21 @@ class SqlParametersFactoryTest {
assertThat(sqlParameterSource.getValue("value")).isEqualTo(value);
}
@Test // GH-1405
void parameterNamesGetSanitized() {
WithIllegalCharacters entity = new WithIllegalCharacters(23L,"aValue");
SqlIdentifierParameterSource sqlParameterSource = sqlParametersFactory.forInsert(entity, WithIllegalCharacters.class,
Identifier.empty(), IdValueSource.PROVIDED);
assertThat(sqlParameterSource.getValue("id")).isEqualTo(23L);
assertThat(sqlParameterSource.getValue("value")).isEqualTo("aValue");
assertThat(sqlParameterSource.getValue("i.d")).isNull();
assertThat(sqlParameterSource.getValue("val&ue")).isNull();
}
@WritingConverter
enum IdValueToStringConverter implements Converter<IdValue, String> {
@@ -212,6 +228,16 @@ class SqlParametersFactoryTest {
@Id private final Long id;
}
@AllArgsConstructor
private static class WithIllegalCharacters {
@Column("i.d")
@Id Long id;
@Column("val&ue")
String value;
}
private SqlParametersFactory createSqlParametersFactoryWithConverters(List<?> converters) {
BasicJdbcConverter converter = new BasicJdbcConverter(context, relationResolver,

View File

@@ -104,6 +104,7 @@ import lombok.Data;
* @author Chirag Tailor
* @author Diego Krupitza
* @author Christopher Klein
* @author Mikhail Polivakha
*/
@Transactional
@TestExecutionListeners(value = AssumeFeatureTestExecutionListener.class, mergeMode = MERGE_WITH_DEFAULTS)
@@ -1242,8 +1243,9 @@ public class JdbcRepositoryIntegrationTests {
assertThat(match.get().getName()).contains(two.getName());
}
@Test
@Test // GH-1405
void withDelimitedColumnTest() {
WithDelimitedColumn withDelimitedColumn = new WithDelimitedColumn();
withDelimitedColumn.setType("TYPICAL");
withDelimitedColumn.setIdentifier("UR-123");