bug: Incorrect value substitution in executeSet causes text corruption (manual escaping instead of parameter binding)
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 48/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- android, java, sqlite, typescript
- Lĩnh vực
- databases, mobile-dev
Hướng nghiên cứu
Bắt đầu trong android/src/main/java/com/getcapacitor/community/database/sqlite/SQLite/Database.java, tập trung vào multipleRowsStatement và lệnh gọi prepareSQL() của nó. Tái hiện executeSet với phần văn bản lịch được cung cấp, sau đó theo dõi cách các giá trị đến SQLite. Hoàn tất khi các chuỗi được chèn và truy xuất vẫn giữ nguyên các ký tự xuống dòng theo từng byte, với hành vi liên quan được các bài kiểm thử hiện có của dự án bao phủ nếu có.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Plugin version:
7.0.2
Platform(s):
Android, Web
Current behavior:
Currently, the values sent in an executeSet statement are replaced by the library after manually escaping the values using DatabaseUtils.sqlEscapeString. This makes it so the inserted string is not the same as the one retrieved, potentially damaging data.
Expected behavior:
Inserted strings are byte-by-byte identical when inserted in the SQLite database.
Steps to reproduce:
Use the executeSet method with query and values like the following:
const statement = "INSERT INTO calendars (year, content) VALUES (?, ?);";
const values = [
[2020, "BEGIN:VCALENDAR\r\nVERSION:2.0...END:VCALENDAR\r\n"],
[2021, "BEGIN:VCALENDAR\r\nVERSION:2.0...END:VCALENDAR\r\n"]
];
const set = [{ statement, values }];
const res = await this.sqlitePlugin!.executeSet({
database: dbName,
set,
returnMode,
transaction: true,
readonly: false
});
The statement will be executed without hinting at any issues, but the values written and returned (either from this query when using returnMode = "all" and adding "RETURNING *" to the statement, or by a select at a later moment) will lack the carriage returns, making the calendar text out of spec and impossible to parse and recover.
Related code:
The method "multipleRowsStatement" performs the substitution: android\src\main\java\com\getcapacitor\community\database\sqlite\SQLite\Database.java
public JSObject multipleRowsStatement(String statement, JSONArray valuesJson, String returnMode) throws Exception {
StringBuilder sqlBuilder = new StringBuilder();
try {
for (int j = 0; j < valuesJson.length(); j++) {
JSONArray innerArray = valuesJson.getJSONArray(j);
StringBuilder innerSqlBuilder = new StringBuilder();
for (int k = 0; k < innerArray.length(); k++) {
Object innerElement = innerArray.get(k);
String elementValue = "";
if (innerElement instanceof String) {
elementValue = DatabaseUtils.sqlEscapeString((String) innerElement);
} else {
elementValue = String.valueOf(innerElement);
}
innerSqlBuilder.append(elementValue);
if (k < innerArray.length() - 1) {
innerSqlBuilder.append(",");
}
}
sqlBuilder.append("(").append(innerSqlBuilder.toString()).append(")");
if (j < valuesJson.length() - 1) {
sqlBuilder.append(",");
}
}
String finalSql = replacePlaceholders(statement, sqlBuilder.toString());
JSObject respSet = prepareSQL(finalSql, new ArrayList<>(), false, returnMode);
return respSet;
} catch (Exception e) {
throw new Exception(e.getMessage());
}
}
Other information:
I have reproduced and debugged the issue in Android Studio.
A proposed fix will be provided in an associated Draft PR.
The recommended approach is to pass the parameter values as an ArrayList to prepareSQL() and let SQLite handle binding, rather than manually constructing SQL strings.
Capacitor doctor:
Capacitor Doctor
Latest Dependencies:
@capacitor/cli: 7.4.4
@capacitor/core: 7.4.4
@capacitor/android: 7.4.4
@capacitor/ios: 7.4.4
Installed Dependencies:
@capacitor/core: 7.4.3
@capacitor/android: 7.4.3
@capacitor/ios: 7.4.3
@capacitor/cli: 7.4.3
[success] Android looking great! 👌
[error] Xcode is not installed
- Ngôn ngữ chính
- Swift
- Star
- 663
- Fork
- 159
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của capacitor-community/sqlite
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 72/100
capacitor-community/sqlite#700 · 1 bình luận · 1 reaction ·
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
capacitor-community/sqlite#693 · 7 reaction ·
-
bug/fix needs: triage
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100
capacitor-community/sqlite#690 ·
-
feature needs: triage
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 55/100
capacitor-community/sqlite#689 ·
-
bug/fix needs: triage
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
capacitor-community/sqlite#685 ·
Tất cả issue của capacitor-community/sqlite
Issue tương tự
-
area: agents area: cli bug difficulty:2 help wanted S3: minor
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
manaflow-ai/cmux#15718 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
mozilla-mobile/firefox-ios#35850 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
appandflow/stim#1941 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
product / avatars product / self-hosted product / storage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
appwrite/appwrite#13985 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
Maintainer thường phản hồi trong vòng 1 ngày