apache / apache/logging-log4j2

KeyValuePair - no validation on required "key" / KeyValuePairComponentBuilder NPEs on generated XML

Open
#3,472 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
Java
Stars
3.6k
Forks
1.7k
Avg merge
21h 30m
Merged PRs (30d)
27

Description

Log4j 2.24.3
--------
A `KeyValuePair` without a key is useless (since it cannot be referenced). A `null` key will also cause problems in multiple locations when added to Map implementations.

Theoretically the same is true of the value but the null cases seem to all be handled when working with KVPs.

The `KeyValuePair` provides no validation / required on the `@PluginAttribute` or in the builder.

In addition, the `DefaultKeyValuePairComponentBuilder` sets the atttributes on the component builder without validating whether they are null.

If the builder is used to generate XML this results in null attributes which will break parsing that XML.

```
public DefaultKeyValuePairComponentBuilder(
final DefaultConfigurationBuilder builder, final String key, final String value) {
super(builder, "KeyValuePair");
addAttribute("key", key);
addAttribute("value", value);
}
```

This constructor should probably throw an NPE or IllegalArgumentException if the key is `null` and only add the value attribute if it is *not* `null`.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.