Skip to content

πŸ›‘οΈ Sentinel: [CRITICAL] Fix JPQL injection in ChannelScheduleController - #192

Merged
manupawickramasinghe merged 2 commits into
developmentfrom
sentinel-fix-jpql-injection-schedule-controller-6782152643201905493
Jul 24, 2026
Merged

πŸ›‘οΈ Sentinel: [CRITICAL] Fix JPQL injection in ChannelScheduleController#192
manupawickramasinghe merged 2 commits into
developmentfrom
sentinel-fix-jpql-injection-schedule-controller-6782152643201905493

Conversation

@ManupaKDU

Copy link
Copy Markdown

🚨 Severity: CRITICAL
πŸ’‘ Vulnerability: JPQL Injection. In ChannelScheduleController.completeSession(), user-provided input was concatenated directly into a LIKE clause: like '%" + query.toUpperCase() + "%'. This bypassed the ORM's sanitization, allowing potential injection of malicious JPQL syntax.
🎯 Impact: An attacker could craft specific autocomplete queries to manipulate the database query logic, potentially reading unauthorized data (such as other doctors' schedules or user information) or causing denial-of-service through complex queries.
πŸ”§ Fix: Refactored the JPQL string to use named parameters (:query and :staffId) and utilized the JPA facade's parameterized findByJpql(sql, params) method. The case-insensitive search logic was moved safely into the query string via the upper() function.
βœ… Verification:

  1. Confirmed parameterized implementation (cat -n src/main/java/com/divudi/bean/channel/ChannelScheduleController.java | sed -n '680,700p').
  2. Run tests to ensure no regressions using ./detect-maven.sh test.

PR created automatically by Jules for task 6782152643201905493 started by @manupawickramasinghe

Replaced unsafe string concatenation with parameterized query in `completeSession()` to prevent JPQL injection via dynamic autocomplete search queries.

Co-authored-by: manupawickramasinghe <73810867+manupawickramasinghe@users.noreply.github.com>
@google-labs-jules

Copy link
Copy Markdown

πŸ‘‹ Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a πŸ‘€ emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@manupawickramasinghe
manupawickramasinghe merged commit 6091364 into development Jul 24, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants