There is 1 comment.
 
 
XWiki Platform / cid:jira-generated-image-avatar-3aa1474a-31e5-419a-ba81-6f4629271232 XWIKI-22726 Open

Allow customizing the validation of HQL queries through configuration

 
View issue   ยท   Add comment
 

1 comment

 
cid:jira-generated-image-avatar-b4831c98-484f-4012-acbf-bae743acbbd7 Thomas Mortagne on 11/Dec/24 13:48
 
bq. Could you provide an example of where this is needed?

I'm not going to give an example of the standard validator being not strict enough, since that would be a security vulnerability. The idea is that at least you have a workaround to block this vulnerability if this happens (for example, we could simply indicate in the advisory a regex to put in that configuration as a workaround).

For the too strict aspect, a simple example is something the validator cannot know: you introduce some custom table, and you consider it's safe to let users without programming right select
it some of its columns in it .