[automerger] DO NOT MERGE. Execute "strict" queries with extra parentheses. am: 286fd5652a am: 8ecd22c0a4
Change-Id: Ia9f489c55def0f592383ac2a10f5bd0b34c2663d
This commit is contained in:
@@ -376,6 +376,11 @@ public class SQLiteQueryBuilder
|
|||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
final String sql;
|
||||||
|
final String unwrappedSql = buildQuery(
|
||||||
|
projectionIn, selection, groupBy, having,
|
||||||
|
sortOrder, limit);
|
||||||
|
|
||||||
if (mStrict && selection != null && selection.length() > 0) {
|
if (mStrict && selection != null && selection.length() > 0) {
|
||||||
// Validate the user-supplied selection to detect syntactic anomalies
|
// Validate the user-supplied selection to detect syntactic anomalies
|
||||||
// in the selection string that could indicate a SQL injection attempt.
|
// in the selection string that could indicate a SQL injection attempt.
|
||||||
@@ -384,14 +389,22 @@ public class SQLiteQueryBuilder
|
|||||||
// originally specified. An attacker cannot create an expression that
|
// originally specified. An attacker cannot create an expression that
|
||||||
// would escape the SQL expression while maintaining balanced parentheses
|
// would escape the SQL expression while maintaining balanced parentheses
|
||||||
// in both the wrapped and original forms.
|
// in both the wrapped and original forms.
|
||||||
String sqlForValidation = buildQuery(projectionIn, "(" + selection + ")", groupBy,
|
|
||||||
having, sortOrder, limit);
|
|
||||||
db.validateSql(sqlForValidation, cancellationSignal); // will throw if query is invalid
|
|
||||||
}
|
|
||||||
|
|
||||||
String sql = buildQuery(
|
// NOTE: The ordering of the below operations is important; we must
|
||||||
projectionIn, selection, groupBy, having,
|
// execute the wrapped query to ensure the untrusted clause has been
|
||||||
sortOrder, limit);
|
// fully isolated.
|
||||||
|
|
||||||
|
// Validate the unwrapped query
|
||||||
|
db.validateSql(unwrappedSql, cancellationSignal); // will throw if query is invalid
|
||||||
|
|
||||||
|
// Execute wrapped query for extra protection
|
||||||
|
final String wrappedSql = buildQuery(projectionIn, "(" + selection + ")", groupBy,
|
||||||
|
having, sortOrder, limit);
|
||||||
|
sql = wrappedSql;
|
||||||
|
} else {
|
||||||
|
// Execute unwrapped query
|
||||||
|
sql = unwrappedSql;
|
||||||
|
}
|
||||||
|
|
||||||
if (Log.isLoggable(TAG, Log.DEBUG)) {
|
if (Log.isLoggable(TAG, Log.DEBUG)) {
|
||||||
Log.d(TAG, "Performing query: " + sql);
|
Log.d(TAG, "Performing query: " + sql);
|
||||||
|
|||||||
Reference in New Issue
Block a user