[ 
https://issues.apache.org/jira/browse/SOLR-18345?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18106485#comment-18106485
 ] 

ASF subversion and git services commented on SOLR-18345:
--------------------------------------------------------

Commit 9d4717b54651d51de7b06706238887d042384b9f in solr's branch 
refs/heads/branch_10x from David Smiley
[ https://gitbox.apache.org/repos/asf?p=solr.git;h=9d4717b5465 ]

SOLR-18345: ClientUtils.encodeLocalParamVal fix for \, ', " (#4729)

SolrJ ClientUtils.encodeLocalParamVal() can produce lossy/invalid encodings 
with a backslash or leading quotes.
Affects faceting with a custom facet response key.
Affects the SQL module for LIKE queries.

(cherry picked from commit f6872652966b1d8b52c376f4a08cd21f622123ab)


> ClientUtils.encodeLocalParamVal() can produces lossy/invalid encodings
> ----------------------------------------------------------------------
>
>                 Key: SOLR-18345
>                 URL: https://issues.apache.org/jira/browse/SOLR-18345
>             Project: Solr
>          Issue Type: Bug
>            Reporter: David Smiley
>            Assignee: David Smiley
>            Priority: Major
>              Labels: pull-request-available
>          Time Spent: 0.5h
>  Remaining Estimate: 0h
>
> ClientUtils.encodeLocalParamVal(String) safely embeds an arbitrary literal
> value into a Solr local-params string (e.g. \{!key=<value>\}, for consumption
> by QueryParsing#parseLocalParams / StrParser. It had two related bugs:
> 1. It escaped an embedded single quote (') but not an embedded backslash (\).
>    Since StrParser#getQuotedString treats '\' as the start of an escape
>    sequence, an unescaped backslash in the value is misinterpreted on
>    decode (e.g. a literal "\n" in the value becomes an actual newline).
> 2. It failed to quote a value whose first character is itself a quote
>    character ('or "), even when no other quoting trigger (whitespace or '}')
>    was present. QueryParsing#parseLocalParams treats a quote character
>    immediately after '=' as the start of a quoted value, so such values were
>    misparsed (e.g. "''" round-tripped to "").
> Both cause encoded values to not round-trip correctly, so callers building
> local-params strings from arbitrary field values/keys could produce
> corrupted or unparseable queries.
> Fix: escape backslashes in addition to single quotes, and force quoting
> whenever the value starts with a quote character.
> _(written by AI)_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to