bug: Incorrect value substitution in executeSet causes text corruption (manual escaping instead of parameter binding)
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Ferma
- Stack tecnologico
- android, java, sqlite, typescript
- Ambito
- databases, mobile-dev
Direzione di ricerca
Inizia in android/src/main/java/com/getcapacitor/community/database/sqlite/SQLite/Database.java, concentrandoti su multipleRowsStatement e sulla sua chiamata a prepareSQL(). Riproduci executeSet con il testo del calendario fornito, quindi traccia il percorso dei valori fino a SQLite. Il lavoro è completato quando le stringhe inserite e recuperate preservano i ritorni a capo byte per byte, con il comportamento pertinente coperto dai test esistenti del progetto, se disponibili.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Plugin version:
7.0.2
Platform(s):
Android, Web
Current behavior:
Currently, the values sent in an executeSet statement are replaced by the library after manually escaping the values using DatabaseUtils.sqlEscapeString. This makes it so the inserted string is not the same as the one retrieved, potentially damaging data.
Expected behavior:
Inserted strings are byte-by-byte identical when inserted in the SQLite database.
Steps to reproduce:
Use the executeSet method with query and values like the following:
const statement = "INSERT INTO calendars (year, content) VALUES (?, ?);";
const values = [
[2020, "BEGIN:VCALENDAR\r\nVERSION:2.0...END:VCALENDAR\r\n"],
[2021, "BEGIN:VCALENDAR\r\nVERSION:2.0...END:VCALENDAR\r\n"]
];
const set = [{ statement, values }];
const res = await this.sqlitePlugin!.executeSet({
database: dbName,
set,
returnMode,
transaction: true,
readonly: false
});
The statement will be executed without hinting at any issues, but the values written and returned (either from this query when using returnMode = "all" and adding "RETURNING *" to the statement, or by a select at a later moment) will lack the carriage returns, making the calendar text out of spec and impossible to parse and recover.
Related code:
The method "multipleRowsStatement" performs the substitution: android\src\main\java\com\getcapacitor\community\database\sqlite\SQLite\Database.java
public JSObject multipleRowsStatement(String statement, JSONArray valuesJson, String returnMode) throws Exception {
StringBuilder sqlBuilder = new StringBuilder();
try {
for (int j = 0; j < valuesJson.length(); j++) {
JSONArray innerArray = valuesJson.getJSONArray(j);
StringBuilder innerSqlBuilder = new StringBuilder();
for (int k = 0; k < innerArray.length(); k++) {
Object innerElement = innerArray.get(k);
String elementValue = "";
if (innerElement instanceof String) {
elementValue = DatabaseUtils.sqlEscapeString((String) innerElement);
} else {
elementValue = String.valueOf(innerElement);
}
innerSqlBuilder.append(elementValue);
if (k < innerArray.length() - 1) {
innerSqlBuilder.append(",");
}
}
sqlBuilder.append("(").append(innerSqlBuilder.toString()).append(")");
if (j < valuesJson.length() - 1) {
sqlBuilder.append(",");
}
}
String finalSql = replacePlaceholders(statement, sqlBuilder.toString());
JSObject respSet = prepareSQL(finalSql, new ArrayList<>(), false, returnMode);
return respSet;
} catch (Exception e) {
throw new Exception(e.getMessage());
}
}
Other information:
I have reproduced and debugged the issue in Android Studio.
A proposed fix will be provided in an associated Draft PR.
The recommended approach is to pass the parameter values as an ArrayList to prepareSQL() and let SQLite handle binding, rather than manually constructing SQL strings.
Capacitor doctor:
Capacitor Doctor
Latest Dependencies:
@capacitor/cli: 7.4.4
@capacitor/core: 7.4.4
@capacitor/android: 7.4.4
@capacitor/ios: 7.4.4
Installed Dependencies:
@capacitor/core: 7.4.3
@capacitor/android: 7.4.3
@capacitor/ios: 7.4.3
@capacitor/cli: 7.4.3
[success] Android looking great! 👌
[error] Xcode is not installed
- Lingua principale
- Swift
- Stelle
- 661
- Fork
- 158
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di capacitor-community/sqlite
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 72/100
capacitor-community/sqlite#700 · 1 commento · 1 reazione ·
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
capacitor-community/sqlite#693 · 7 reazioni ·
-
bug/fix needs: triage
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
capacitor-community/sqlite#690 ·
-
feature needs: triage
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
capacitor-community/sqlite#689 ·
-
bug/fix needs: triage
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
capacitor-community/sqlite#685 ·
Tutte le issue di capacitor-community/sqlite
Issue simili
-
clawsweeper:needs-maintainer-review clawsweeper:needs-product-decision clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:other issue-rating: 🦞 diamond lobster P2
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
steipete/CodexBar#4071 · 1 commento · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
I maintainer di solito rispondono entro 1 giorno
-
Nextcloud Desktop 34.0.4 fails TestLocalDiscovery::testFileOpenedAsDirectoryCompletesDiscoveryJob()Aperta0. Needs triage bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
I maintainer di solito rispondono entro 1 giorno
-
bot file conflict
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
termux/termux-packages#32026 ·
I maintainer di solito rispondono entro 1 giorno
-
Dictated bullet lists keep the recogniser's commas at the end of every line ("- Milk," "- Eggs,")Apertaarea:dictation bug good first issue P2
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
uttrflow/uttrflow-swift#1958 ·
I maintainer di solito rispondono entro 1 giorno