Conversation
Replaced vulnerable string concatenation in `getSelectedItems` with a parameterized query. Also fixed an operator precedence bug in the `OR` conditions and explicitly enforced upper-casing logic using the JPQL `upper()` function. Co-authored-by: manupawickramasinghe <73810867+manupawickramasinghe@users.noreply.github.com>
|
π Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a π emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
π¨ Severity: CRITICAL
π‘ Vulnerability: JPQL Injection via un-sanitized user input concatenation in
RoomChangeController.getSelectedItems().π― Impact: Malicious users could bypass search logic, extract unauthorized patient admission data, or inject malicious SQL commands.
π§ Fix: Replaced direct string concatenation with parameterized query map using
findByJpql(). Wrapped theORstatements in grouping parentheses to correctly mimic the intent and usedupper()to maintain case-insensitive search logic.β Verification: Tested locally via manual code compilation (offline mode due to maven central throttling). Code logic verified against standard Sentinel conventions.
PR created automatically by Jules for task 4324315215235687672 started by @manupawickramasinghe