Repository navigation
escape ampersand entity prefixes in pointer paths - #292
Open
SABITHSAHEB wants to merge 1 commit into
Open
SABITHSAHEB wants to merge 1 commit into
SABITHSAHEB wants to merge 1 commit into
Conversation
A dynamic property name containing the literal text ' produced the same asPath() as a name containing a real quote, so re-evaluating the stored path resolved to the wrong entry. escape() now emits & for an ampersand that starts an entity sequence and the parser's unescape() decodes it in a single pass. Lone ampersands are unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
mvn; that'smvnon the command line by itself.NodePointer.escapewrites'and"as'/"but leaves&alone, so a dynamic property name containing the literal text'yields the sameasPath()as a name containing a real quote: a map with the keysKey'1andKey'1prints/map[@name='Key'1']for both entries.getValue,setValueorremovePaththen resolves to the wrong entry, so a name chosen to contain an entity sequence silently aliases a sibling entry's pointer path.escapenow also emits&for an ampersand that starts an',"or&sequence, and the parser'sunescape(XPath.jjand the checked-inXPathParser.java) decodes&in a single left-to-right pass, so escaped output decodes to exactly the original name.A lone
&still needs no escaping and&only decodes where it appears literally, so existing stored paths and hand-written literals like'Tom & Jerry'parse as before; the only changed input is a literal containing the exact sequence&, which previously could not be produced byasPath()at all. The new test inDynamicPropertiesModelTestfails before the change and passes after.