Escape schema and function name patterns if necessary

The JDBC API that retrieves a proedure or a function allows to specify
patterns for the schema and the procedure name. So far, we've called
this API with the value as is, which does not work if either contains
a wildcard characters that need to be escaped.

This commit updates GenericCallMetadataProvider to escape, if necessary,
the schema or procedure name using the search string escape from the
database metadata.

Closes gh-22725
This commit is contained in:
Stéphane Nicoll 2023-11-24 15:49:41 +01:00
parent b2757d9a21
commit 34031ebea9
3 changed files with 107 additions and 15 deletions

View File

@ -22,6 +22,7 @@ import java.sql.SQLException;
import java.sql.Types; import java.sql.Types;
import java.util.ArrayList; import java.util.ArrayList;
import java.util.List; import java.util.List;
import java.util.Objects;
import org.apache.commons.logging.Log; import org.apache.commons.logging.Log;
import org.apache.commons.logging.LogFactory; import org.apache.commons.logging.LogFactory;
@ -41,6 +42,7 @@ import org.springframework.util.StringUtils;
* @author Thomas Risberg * @author Thomas Risberg
* @author Juergen Hoeller * @author Juergen Hoeller
* @author Sam Brannen * @author Sam Brannen
* @author Stephane Nicoll
* @since 2.5 * @since 2.5
*/ */
public class GenericCallMetaDataProvider implements CallMetaDataProvider { public class GenericCallMetaDataProvider implements CallMetaDataProvider {
@ -298,17 +300,24 @@ public class GenericCallMetaDataProvider implements CallMetaDataProvider {
String metaDataCatalogName = metaDataCatalogNameToUse(catalogName); String metaDataCatalogName = metaDataCatalogNameToUse(catalogName);
String metaDataSchemaName = metaDataSchemaNameToUse(schemaName); String metaDataSchemaName = metaDataSchemaNameToUse(schemaName);
String metaDataProcedureName = procedureNameToUse(procedureName); String metaDataProcedureName = procedureNameToUse(procedureName);
try {
String searchStringEscape = databaseMetaData.getSearchStringEscape();
String escapedSchemaName = escapeNamePattern(metaDataSchemaName, searchStringEscape);
String escapedProcedureName = escapeNamePattern(metaDataProcedureName, searchStringEscape);
if (logger.isDebugEnabled()) { if (logger.isDebugEnabled()) {
String schemaInfo = (Objects.equals(escapedSchemaName, metaDataSchemaName)
? metaDataSchemaName : metaDataCatalogName + "(" + escapedSchemaName + ")");
String procedureInfo = (Objects.equals(escapedProcedureName, metaDataProcedureName)
? metaDataProcedureName : metaDataProcedureName + "(" + escapedProcedureName + ")");
logger.debug("Retrieving meta-data for " + metaDataCatalogName + '/' + logger.debug("Retrieving meta-data for " + metaDataCatalogName + '/' +
metaDataSchemaName + '/' + metaDataProcedureName); schemaInfo + '/' + procedureInfo);
} }
try {
List<String> found = new ArrayList<>(); List<String> found = new ArrayList<>();
boolean function = false; boolean function = false;
try (ResultSet procedures = databaseMetaData.getProcedures( try (ResultSet procedures = databaseMetaData.getProcedures(
metaDataCatalogName, metaDataSchemaName, metaDataProcedureName)) { metaDataCatalogName, escapedSchemaName, escapedProcedureName)) {
while (procedures.next()) { while (procedures.next()) {
found.add(procedures.getString("PROCEDURE_CAT") + '.' + procedures.getString("PROCEDURE_SCHEM") + found.add(procedures.getString("PROCEDURE_CAT") + '.' + procedures.getString("PROCEDURE_SCHEM") +
'.' + procedures.getString("PROCEDURE_NAME")); '.' + procedures.getString("PROCEDURE_NAME"));
@ -318,7 +327,7 @@ public class GenericCallMetaDataProvider implements CallMetaDataProvider {
if (found.isEmpty()) { if (found.isEmpty()) {
// Functions not exposed as procedures anymore on PostgreSQL driver 42.2.11 // Functions not exposed as procedures anymore on PostgreSQL driver 42.2.11
try (ResultSet functions = databaseMetaData.getFunctions( try (ResultSet functions = databaseMetaData.getFunctions(
metaDataCatalogName, metaDataSchemaName, metaDataProcedureName)) { metaDataCatalogName, escapedSchemaName, escapedProcedureName)) {
while (functions.next()) { while (functions.next()) {
found.add(functions.getString("FUNCTION_CAT") + '.' + functions.getString("FUNCTION_SCHEM") + found.add(functions.getString("FUNCTION_CAT") + '.' + functions.getString("FUNCTION_SCHEM") +
'.' + functions.getString("FUNCTION_NAME")); '.' + functions.getString("FUNCTION_NAME"));
@ -359,8 +368,8 @@ public class GenericCallMetaDataProvider implements CallMetaDataProvider {
metaDataCatalogName + '/' + metaDataSchemaName + '/' + metaDataProcedureName); metaDataCatalogName + '/' + metaDataSchemaName + '/' + metaDataProcedureName);
} }
try (ResultSet columns = function ? try (ResultSet columns = function ?
databaseMetaData.getFunctionColumns(metaDataCatalogName, metaDataSchemaName, metaDataProcedureName, null) : databaseMetaData.getFunctionColumns(metaDataCatalogName, escapedSchemaName, escapedProcedureName, null) :
databaseMetaData.getProcedureColumns(metaDataCatalogName, metaDataSchemaName, metaDataProcedureName, null)) { databaseMetaData.getProcedureColumns(metaDataCatalogName, escapedSchemaName, escapedProcedureName, null)) {
while (columns.next()) { while (columns.next()) {
String columnName = columns.getString("COLUMN_NAME"); String columnName = columns.getString("COLUMN_NAME");
int columnType = columns.getInt("COLUMN_TYPE"); int columnType = columns.getInt("COLUMN_TYPE");
@ -400,6 +409,16 @@ public class GenericCallMetaDataProvider implements CallMetaDataProvider {
} }
} }
@Nullable
private static String escapeNamePattern(@Nullable String name, @Nullable String escape) {
if (name == null || escape == null) {
return name;
}
return name.replace(escape, escape + escape)
.replace("_", escape + "_")
.replace("%", escape + "%");
}
private static boolean isInOrOutColumn(int columnType, boolean function) { private static boolean isInOrOutColumn(int columnType, boolean function) {
if (function) { if (function) {
return (columnType == DatabaseMetaData.functionColumnIn || return (columnType == DatabaseMetaData.functionColumnIn ||

View File

@ -0,0 +1,71 @@
/*
* Copyright 2002-2023 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.jdbc.core.metadata;
import java.sql.DatabaseMetaData;
import java.sql.SQLException;
import org.junit.jupiter.api.Test;
import static org.assertj.core.api.Assertions.assertThatIllegalStateException;
import static org.mockito.BDDMockito.given;
import static org.mockito.Mockito.mock;
import static org.mockito.Mockito.verify;
/**
* Tests for {@link GenericCallMetaDataProvider}.
*
* @author Stephane Nicoll
*/
class GenericCallMetaDataProviderTests {
private final DatabaseMetaData databaseMetaData = mock(DatabaseMetaData.class);
@Test
void procedureNameWithPatternIsEscape() throws SQLException {
given(this.databaseMetaData.getSearchStringEscape()).willReturn("@");
GenericCallMetaDataProvider provider = new GenericCallMetaDataProvider(this.databaseMetaData);
given(this.databaseMetaData.getProcedures(null, null, "MY@_PROCEDURE"))
.willThrow(new IllegalStateException("Expected"));
assertThatIllegalStateException().isThrownBy(() -> provider.initializeWithProcedureColumnMetaData(
this.databaseMetaData, null, null, "my_procedure"));
verify(this.databaseMetaData).getProcedures(null, null, "MY@_PROCEDURE");
}
@Test
void schemaNameWithPatternIsEscape() throws SQLException {
given(this.databaseMetaData.getSearchStringEscape()).willReturn("@");
GenericCallMetaDataProvider provider = new GenericCallMetaDataProvider(this.databaseMetaData);
given(this.databaseMetaData.getProcedures(null, "MY@_SCHEMA", "TEST"))
.willThrow(new IllegalStateException("Expected"));
assertThatIllegalStateException().isThrownBy(() -> provider.initializeWithProcedureColumnMetaData(
this.databaseMetaData, null, "my_schema", "test"));
verify(this.databaseMetaData).getProcedures(null, "MY@_SCHEMA", "TEST");
}
@Test
void nameIsNotEscapedIfEscapeCharacterIsNotAvailable() throws SQLException {
given(this.databaseMetaData.getSearchStringEscape()).willReturn(null);
GenericCallMetaDataProvider provider = new GenericCallMetaDataProvider(this.databaseMetaData);
given(this.databaseMetaData.getProcedures(null, "MY_SCHEMA", "MY_TEST"))
.willThrow(new IllegalStateException("Expected"));
assertThatIllegalStateException().isThrownBy(() -> provider.initializeWithProcedureColumnMetaData(
this.databaseMetaData, null, "my_schema", "my_test"));
verify(this.databaseMetaData).getProcedures(null, "MY_SCHEMA", "MY_TEST");
}
}

View File

@ -239,8 +239,9 @@ class SimpleJdbcCallTests {
given(databaseMetaData.getDatabaseProductName()).willReturn("Oracle"); given(databaseMetaData.getDatabaseProductName()).willReturn("Oracle");
given(databaseMetaData.getUserName()).willReturn("ME"); given(databaseMetaData.getUserName()).willReturn("ME");
given(databaseMetaData.storesUpperCaseIdentifiers()).willReturn(true); given(databaseMetaData.storesUpperCaseIdentifiers()).willReturn(true);
given(databaseMetaData.getProcedures("", "ME", "ADD_INVOICE")).willReturn(proceduresResultSet); given(databaseMetaData.getSearchStringEscape()).willReturn("@");
given(databaseMetaData.getProcedureColumns("", "ME", "ADD_INVOICE", null)).willReturn(procedureColumnsResultSet); given(databaseMetaData.getProcedures("", "ME", "ADD@_INVOICE")).willReturn(proceduresResultSet);
given(databaseMetaData.getProcedureColumns("", "ME", "ADD@_INVOICE", null)).willReturn(procedureColumnsResultSet);
given(proceduresResultSet.next()).willReturn(true, false); given(proceduresResultSet.next()).willReturn(true, false);
given(proceduresResultSet.getString("PROCEDURE_NAME")).willReturn("add_invoice"); given(proceduresResultSet.getString("PROCEDURE_NAME")).willReturn("add_invoice");
@ -306,8 +307,9 @@ class SimpleJdbcCallTests {
given(databaseMetaData.getDatabaseProductName()).willReturn("Oracle"); given(databaseMetaData.getDatabaseProductName()).willReturn("Oracle");
given(databaseMetaData.getUserName()).willReturn("ME"); given(databaseMetaData.getUserName()).willReturn("ME");
given(databaseMetaData.storesUpperCaseIdentifiers()).willReturn(true); given(databaseMetaData.storesUpperCaseIdentifiers()).willReturn(true);
given(databaseMetaData.getProcedures("", "ME", "ADD_INVOICE")).willReturn(proceduresResultSet); given(databaseMetaData.getSearchStringEscape()).willReturn("@");
given(databaseMetaData.getProcedureColumns("", "ME", "ADD_INVOICE", null)).willReturn(procedureColumnsResultSet); given(databaseMetaData.getProcedures("", "ME", "ADD@_INVOICE")).willReturn(proceduresResultSet);
given(databaseMetaData.getProcedureColumns("", "ME", "ADD@_INVOICE", null)).willReturn(procedureColumnsResultSet);
given(proceduresResultSet.next()).willReturn(true, false); given(proceduresResultSet.next()).willReturn(true, false);
given(proceduresResultSet.getString("PROCEDURE_NAME")).willReturn("add_invoice"); given(proceduresResultSet.getString("PROCEDURE_NAME")).willReturn("add_invoice");
@ -330,8 +332,8 @@ class SimpleJdbcCallTests {
} }
private void verifyAddInvoiceWithMetaData(boolean isFunction) throws SQLException { private void verifyAddInvoiceWithMetaData(boolean isFunction) throws SQLException {
ResultSet proceduresResultSet = databaseMetaData.getProcedures("", "ME", "ADD_INVOICE"); ResultSet proceduresResultSet = databaseMetaData.getProcedures("", "ME", "ADD@_INVOICE");
ResultSet procedureColumnsResultSet = databaseMetaData.getProcedureColumns("", "ME", "ADD_INVOICE", null); ResultSet procedureColumnsResultSet = databaseMetaData.getProcedureColumns("", "ME", "ADD@_INVOICE", null);
if (isFunction) { if (isFunction) {
verify(callableStatement).registerOutParameter(1, 4); verify(callableStatement).registerOutParameter(1, 4);
verify(callableStatement).setObject(2, 1103, 4); verify(callableStatement).setObject(2, 1103, 4);