github-advanced-security[bot] commented on code in PR #3673:
URL: https://github.com/apache/tinkerpop/pull/3673#discussion_r4099448213
##########
gremlin-js/gremlin-javascript/lib/language/translator/GoTranslateVisitor.ts:
##########
@@ -257,8 +257,23 @@
this.sb.push(')');
}
- visitCharacterLiteral(_ctx: any): void {
- throw new TranslatorException('Character literals are not supported in
Go');
+ visitCharacterLiteral(ctx: any): void {
+ const text: string = ctx.getText();
+ const withoutSuffix = text.substring(0, text.length - 1);
+ const quoteChar = withoutSuffix[0];
+ // Extract the content between quotes
+ let inner = withoutSuffix.substring(1, withoutSuffix.length - 1);
+ // Unescape the appropriate quote character for the Gremlin source
+ if (quoteChar === '"') {
+ inner = inner.replace(/\\"/g, '"');
+ } else if (quoteChar === "'") {
+ inner = inner.replace(/\\'/g, "'");
+ }
+ inner = inner.replace(/'/g, "\\'");
Review Comment:
## CodeQL / Incomplete string escaping or encoding
This does not escape backslash characters in the input.
[Show more
details](https://github.com/apache/tinkerpop/security/code-scanning/21)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]