swagger-api / swagger-api/swagger-codegen

Wrong usage of replaceAll when path is constructed

Open
#9,863 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Mustache
Stars
17.8k
Forks
6k
PR merge metrics
No merged PRs in 30d

Description

Tested in context of : "library" set to "okhttp-gson".

There are two possible issue:

  • in path parameter name can for some strange reason contains that matches to RegExp
  • in path parameter value can contains other parameter name that could lead to replacement of wrong thing

Suggested to go throw the string to look up '{' replace part and continue for another one.
Maybe there is need for some extra escaping if some strange reason is needed in-path-parameter with "{", but all in all that should be cross-check by codegen generation in path and also in parameter name itself.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Inspect the generated okhttp-gson client's path construction and locate the replaceAll usage. Reproduce the case with path parameter names or values containing regex-like text or another parameter name, then verify generated paths replace only the intended placeholders.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
tooling
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.