bug: Incorrect value substitution in executeSet causes text corruption (manual escaping instead of parameter binding)
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 48/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Estancado
- Stack tecnológico
- android, java, sqlite, typescript
- Área
- databases, mobile-dev
Línea de trabajo
Comienza en android/src/main/java/com/getcapacitor/community/database/sqlite/SQLite/Database.java, centrándote en multipleRowsStatement y en su llamada a prepareSQL(). Reproduce executeSet con el texto de calendario proporcionado y, a continuación, sigue el recorrido de los valores hasta SQLite. Se considera terminado cuando las cadenas insertadas y recuperadas conservan los retornos de carro byte por byte, con el comportamiento relevante cubierto por las pruebas existentes del proyecto si están disponibles.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Plugin version:
7.0.2
Platform(s):
Android, Web
Current behavior:
Currently, the values sent in an executeSet statement are replaced by the library after manually escaping the values using DatabaseUtils.sqlEscapeString. This makes it so the inserted string is not the same as the one retrieved, potentially damaging data.
Expected behavior:
Inserted strings are byte-by-byte identical when inserted in the SQLite database.
Steps to reproduce:
Use the executeSet method with query and values like the following:
const statement = "INSERT INTO calendars (year, content) VALUES (?, ?);";
const values = [
[2020, "BEGIN:VCALENDAR\r\nVERSION:2.0...END:VCALENDAR\r\n"],
[2021, "BEGIN:VCALENDAR\r\nVERSION:2.0...END:VCALENDAR\r\n"]
];
const set = [{ statement, values }];
const res = await this.sqlitePlugin!.executeSet({
database: dbName,
set,
returnMode,
transaction: true,
readonly: false
});
The statement will be executed without hinting at any issues, but the values written and returned (either from this query when using returnMode = "all" and adding "RETURNING *" to the statement, or by a select at a later moment) will lack the carriage returns, making the calendar text out of spec and impossible to parse and recover.
Related code:
The method "multipleRowsStatement" performs the substitution: android\src\main\java\com\getcapacitor\community\database\sqlite\SQLite\Database.java
public JSObject multipleRowsStatement(String statement, JSONArray valuesJson, String returnMode) throws Exception {
StringBuilder sqlBuilder = new StringBuilder();
try {
for (int j = 0; j < valuesJson.length(); j++) {
JSONArray innerArray = valuesJson.getJSONArray(j);
StringBuilder innerSqlBuilder = new StringBuilder();
for (int k = 0; k < innerArray.length(); k++) {
Object innerElement = innerArray.get(k);
String elementValue = "";
if (innerElement instanceof String) {
elementValue = DatabaseUtils.sqlEscapeString((String) innerElement);
} else {
elementValue = String.valueOf(innerElement);
}
innerSqlBuilder.append(elementValue);
if (k < innerArray.length() - 1) {
innerSqlBuilder.append(",");
}
}
sqlBuilder.append("(").append(innerSqlBuilder.toString()).append(")");
if (j < valuesJson.length() - 1) {
sqlBuilder.append(",");
}
}
String finalSql = replacePlaceholders(statement, sqlBuilder.toString());
JSObject respSet = prepareSQL(finalSql, new ArrayList<>(), false, returnMode);
return respSet;
} catch (Exception e) {
throw new Exception(e.getMessage());
}
}
Other information:
I have reproduced and debugged the issue in Android Studio.
A proposed fix will be provided in an associated Draft PR.
The recommended approach is to pass the parameter values as an ArrayList to prepareSQL() and let SQLite handle binding, rather than manually constructing SQL strings.
Capacitor doctor:
Capacitor Doctor
Latest Dependencies:
@capacitor/cli: 7.4.4
@capacitor/core: 7.4.4
@capacitor/android: 7.4.4
@capacitor/ios: 7.4.4
Installed Dependencies:
@capacitor/core: 7.4.3
@capacitor/android: 7.4.3
@capacitor/ios: 7.4.3
@capacitor/cli: 7.4.3
[success] Android looking great! 👌
[error] Xcode is not installed
- Lenguaje dominante
- Swift
- Estrellas
- 661
- Forks
- 158
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de capacitor-community/sqlite
-
Dificultad 3/5 1-2 días Aptitud para principiantes 72/100
capacitor-community/sqlite#700 · 1 comentario · 1 reacción ·
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
capacitor-community/sqlite#693 · 7 reacciones ·
-
bug/fix needs: triage
Dificultad 3/5 1-2 días Aptitud para principiantes 68/100
capacitor-community/sqlite#690 ·
-
feature needs: triage
Dificultad 3/5 1-2 días Aptitud para principiantes 55/100
capacitor-community/sqlite#689 ·
-
bug/fix needs: triage
Dificultad 3/5 1-2 días Aptitud para principiantes 45/100
capacitor-community/sqlite#685 ·
Todos los issues de capacitor-community/sqlite
Issues similares
-
auth type: bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
googleapis/google-cloud-swift#1260 ·
Los mantenedores suelen responder en 1 día
-
Catalog audit: broken entriesAbiertocatalog-audit
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
0. Needs triage bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
clawsweeper:linked-pr-open clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:ux-friction issue-rating: 🦞 diamond lobster P2
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
steipete/RepoBar#140 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
area:dictation bug P2
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
uttrflow/uttrflow-swift#2551 ·
Los mantenedores suelen responder en 1 día