sahvx655-wq opened a new pull request, #439:
URL: https://github.com/apache/commons-validator/pull/439
ISBNValidator's Javadoc says the ISBN-10 and ISBN-13 groups are separated by
a dash or a space, but the SEP fragment shared by ISBN10_REGEX and ISBN13_REGEX
is `(?:\-|\s)`, and `\s` in a Java regex also covers tab, line feed, carriage
return, vertical tab and form feed. I found it while sweeping the routines
package for separator patterns: isValidISBN10("1\n930110\n99\n5") and
isValidISBN13("978\t1\t930110\t99\t1") both return true, and isValid and
validate agree with them, so a value with embedded line breaks passes as a
correctly formatted ISBN. The check digit does not catch it because the
separators are stripped before it runs. Any caller that stores, logs or echoes
the raw value on the strength of isValid ends up with a multi-line token the
validator vouched for.
Narrow SEP to a character class of the two documented separators, which
corrects both regexes in one place and lines up with the existing "Invalid
Separator" fixtures for '.', '=' and '_'. The regex is the only layer that can
do this: CodeValidator trims only the ends of the input and the check digit
never sees the separators, so nothing further down the chain has the
information. The invalid-format fixtures gain the five control-character
separators for ISBN-10 and ISBN-13; they fail on master and pass with the
change, and the default build with -Ddoclint=all is green.
- [x] Read the [contribution guidelines](CONTRIBUTING.md) for this project.
- [x] Read the [ASF Generative Tooling
Guidance](https://www.apache.org/legal/generative-tooling.html) if you use
Artificial Intelligence (AI).
- [x] I used AI to create any part of, or all of, this pull request. Which
AI tool was used to create this pull request, and to what extent did it
contribute? Claude Code (Anthropic) was used to survey the validators, draft
the change and this description; I reviewed the fix and the fixtures and ran
the build locally.
- [x] Run a successful build using the default
[Maven](https://maven.apache.org/) goal with `mvn`; that's `mvn` on the command
line by itself.
- [x] Write unit tests that match behavioral changes, where the tests fail
if the changes to the runtime are not applied. This may not always be possible,
but it is a best practice.
- [x] Write a pull request description that is detailed enough to understand
what the pull request does, how, and why.
- [x] Each commit in the pull request should have a meaningful subject line
and body. Note that a maintainer may squash commits during the merge process.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]