[BUG][code-analyzer] sfge: Database.query() on a string that is empty on any path aborts the entry point ("Query should have fields")
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 72/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- java, typescript
- Área
- devtools, testing-qa
Línea de trabajo
Start with SoqlParserUtil.java, especially extractFields and the existing handling of IllegalStateException; compare what happens when the field-pattern match fails. Run the sfge rule against the QueryEmptyOnOnePath reproducer and check that an empty query path no longer aborts analysis, while a real query path still reports the ApexFlsViolation for Account.Name.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Have you tried to resolve this issue yourself first?
- I confirm I have gone through the above steps and still have an issue to report.
Bug Description
Engine: sfge (Salesforce Graph Engine) · Rule: ApexFlsViolation (DevPreview) · Selector: --rule-selector sfge
sfge parses the string passed to Database.query() with SoqlParserUtil.parseQuery. When the field pattern finds no match, extractFields throws:
// SoqlParserUtil.java:330-334
final Matcher fieldMatcher = FIELD_PATTERN.matcher(query);
if (!fieldMatcher.find()) {
throw new UnexpectedException("Query should have fields: " + query);
}
A common way to build a dynamic query is to start from '' and assign the query in branches. sfge expands every path, including the one where no branch ran, and the string there is still ''. The throw on that one path abandons the whole entry point, so the paths with a real query are never checked for FLS either.
String query = '';
if (mode == 'all') {
query = 'SELECT Id, Name FROM Account';
}
return Database.query(query);
Output / Logs
UnexpectedException: Query should have fields: :
com.salesforce.graph.ops.SoqlParserUtil.extractFields(SoqlParserUtil.java:333);
com.salesforce.graph.ops.SoqlParserUtil.parseFields(SoqlParserUtil.java:356);
com.salesforce.graph.ops.SoqlParserUtil.getSoqlQueryInfo(SoqlParserUtil.java:211);
com.salesforce.graph.ops.SoqlParserUtil.getInnerQueries(SoqlParserUtil.java:194);
com.salesforce.graph.ops.SoqlParserUtil.parseQuery(SoqlParserUtil.java:144);
com.salesforce.graph.symbols.apex.ApexSoqlValue.setObjectProperties(ApexSoqlValue.java:135)
The query after Query should have fields: is empty.
Steps To Reproduce
- Create an empty SFDX project (
sfdx-project.jsonwith a singleforce-apppackage directory). - Add
force-app/main/default/classes/QueryEmptyOnOnePath.clswith the class shown below, plus a standardQueryEmptyOnOnePath.cls-meta.xml(apiVersion 62.0). - Add
code-analyzer.yml:engines: sfge: java_thread_timeout: 900000 java_thread_count: 4 - Run:
sf code-analyzer run --rule-selector sfge --workspace . --config-file code-analyzer.yml - The run reports an
InternalExecutionErrorfor the entry point instead of analysing it. TheREADonAccount.Namegoes unreported, and nothing in the summary indicates coverage was lost.
public with sharing class QueryEmptyOnOnePath {
@AuraEnabled
public static List<Account> run(String mode) {
String query = '';
if (mode == 'all') {
query = 'SELECT Id, Name FROM Account';
}
return Database.query(query);
}
}
Expected Behavior
A query string that does not parse should leave that one path's query unresolved, the way sfge already reports "couldn't resolve the parameter passed to [READ] operation". It should not throw. extractFields already degrades to an empty field list on IllegalStateException, and a failed match could take the same route.
Operating System
macOS 26.7.1
Salesforce CLI Version
@salesforce/cli/2.147.7 darwin-arm64 node-v24.5.0
Code Analyzer Plugin (code-analyzer) Version
code-analyzer 5.15.0
Node Version
v24.5.0
Java Version
openjdk version "11.0.32" 2026-07-21
Python Version
N/A
Additional Context (Screenshots, Files, etc)
Also fails on code-analyzer 5.16.0 (sfge 0.25.0) under OpenJDK 21 on ubuntu-latest, with the same stack. In our codebase it abandons 1 @AuraEnabled entry point.
A control in the same workspace, with a non-empty query on every path (String query = 'SELECT Id, Name FROM Account';, overwritten in the branch), was analysed normally and reports the expected ApexFlsViolation for the READ on Account.Name.
#1224, closed in the 2026-06-30 pre-v5 sweep, failed at the same line with a different input: an inner query in a WHERE clause (Id NOT IN (INNER_QUERY) AND ...), which matches the TODO: Handle contents within brackets in getInnerQueries. We have not re-tested that input. A fix that degrades instead of throwing would cover both.
Workaround
Initialise the query string to a valid query, or return before Database.query() on the path that builds none.
Urgency
Moderate
- Lenguaje dominante
- TypeScript
- Estrellas
- 241
- Forks
- 51
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de forcedotcom/code-analyzer
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
forcedotcom/code-analyzer#2094 ·
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
forcedotcom/code-analyzer#2093 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
forcedotcom/code-analyzer#2091 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
forcedotcom/code-analyzer#2090 ·
-
Dificultad 3/5 1-2 días Aptitud para principiantes 63/100
forcedotcom/code-analyzer#2103 ·
Todos los issues de forcedotcom/code-analyzer
Issues similares
-
Add: CanalPlusActionEurope.nlAbiertocheck:passed streams:add
Dificultad 1/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 2 días
-
beta technical-medium ui
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
walletbeat/walletbeat#1625 ·
Los mantenedores suelen responder en 1 día
-
[Good First Issue]: Add unit tests for NetworkVersionInfoPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. AbiertoGood First Issue hacktoberfest
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
hiero-ledger/hiero-sdk-js#4489 ·
Los mantenedores suelen responder en 1 día
-
[Bug] The clients language filter cannot select the rows the page labels as unknownPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
apache/rocketmq-dashboard#6103 ·
Los mantenedores suelen responder en 4 días
-
Bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
payloadcms/payload#18652 ·
Los mantenedores suelen responder en 1 día