Improve URI/query strings sanitization
This commit is contained in:
committed by
Juergen Hoeller
parent
b077e4cd85
commit
0015fd6734
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2002-2019 the original author or authors.
|
||||
* Copyright 2002-2020 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -83,7 +83,7 @@ public abstract class NamedParameterUtils {
|
||||
Assert.notNull(sql, "SQL must not be null");
|
||||
|
||||
Set<String> namedParameters = new HashSet<>();
|
||||
String sqlToUse = sql;
|
||||
StringBuilder sqlToUse = new StringBuilder(sql);
|
||||
List<ParameterHolder> parameterList = new ArrayList<>();
|
||||
|
||||
char[] statement = sql.toCharArray();
|
||||
@@ -155,7 +155,7 @@ public abstract class NamedParameterUtils {
|
||||
int j = i + 1;
|
||||
if (j < statement.length && statement[j] == ':') {
|
||||
// escaped ":" should be skipped
|
||||
sqlToUse = sqlToUse.substring(0, i - escapes) + sqlToUse.substring(i - escapes + 1);
|
||||
sqlToUse.deleteCharAt(i - escapes);
|
||||
escapes++;
|
||||
i = i + 2;
|
||||
continue;
|
||||
@@ -174,7 +174,7 @@ public abstract class NamedParameterUtils {
|
||||
}
|
||||
i++;
|
||||
}
|
||||
ParsedSql parsedSql = new ParsedSql(sqlToUse);
|
||||
ParsedSql parsedSql = new ParsedSql(sqlToUse.toString());
|
||||
for (ParameterHolder ph : parameterList) {
|
||||
parsedSql.addNamedParameter(ph.getParameterName(), ph.getStartIndex(), ph.getEndIndex());
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user