There is 1 comment.
 
 
XWiki Platform / cid:jira-generated-image-avatar-f95f12c4-6dd0-48ff-bc3c-61f0653608e7 XWIKI-22726 Open

Allow customizing the validation of HQL queries through configuration

 
View issue   ยท   Add comment
 

1 comment

 
cid:jira-generated-image-avatar-7cfdc8da-e302-4f18-99ac-cb6defed9322 Thomas Mortagne on 11/Dec/24 13:30
 

Could you provide an example of where this is needed?

I'm not going to give an example of the standard validator being not strict enough, since that would be a security vulnerability. The idea is that at least you have a workaround to block this vulnerability if this happens (for example, we could simply indicate in the advisory a regex to put in that configuration as a workaround).

For the too strict aspect, a simple example is something the validator cannot know: you introduce some custom table, and you consider it's safe to let users without programming right select it some columns in it.