Fix #1683: reject JSON-escaped lone surrogates in ReaderBasedJsonParser - #1684
Conversation
…dJsonParser Mirror of FasterXML#1541 for the Reader-based parser: the \uXXXX escape decoder now rejects lone / reversed surrogates in field-name and string-value positions, plus _skipString for consistency with skipChildren() callers. Error messages match FasterXML#1541's wording. Ships strict-default with no JsonReadFeature gate, matching FasterXML#1542/FasterXML#1583.
|
One clarification: With this change, escaped pairs ( Is this intentional, with validation limited to JSON-escaped surrogates? Or would it make sense to validate surrogate pairs consistently regardless of whether each code unit is escaped or raw? |
|
Good catch @Dongnyoung. Yes, intentional. This PR only checks what Raw lone surrogates are accepted, like you said. The mixed cases are deliberate rather than incidental; the tests here assert both directions Rejecting raw lone surrogates is a different matter -- it would change behaviour for input that |
|
@elang2 Thanks, that makes sense. A separate issue sounds good — I think it would also help clarify the expected behavior for raw and mixed raw/escaped surrogate pairs. |
@Dongnyoung here you go. please review #1705 |
|
Hi @elang2 ! This looks legit and I will review it. One thing before I can merge it (beside the review): CLA, see: https://github.com/FasterXML/jackson/blob/main/CONTRIBUTING.md#paperwork (unless you already sent one) |
Hi @cowtowncoder , sent one now. |
… any other parser; now matches byte-backed UTF8StreamJsonParser
|
I trimmed the PR to drop String value validation and just keep field name validation. I am also bit torn on actual value of this validation altogether; but let's complete field name validation across backends. |
|
Minor: |
Fixes #1683.
Mirror of #1541 for
ReaderBasedJsonParser. The\uXXXXescape decoder now rejects lone / reversed surrogates in field-names. Error messages match #1541's wording; helpers are private and per-parser to keep duplication low across the four sites.Not gated behind a
JsonReadFeature— matches #1542/#1583. If your #1494 note about wanting this class of validation feature-gated has become the preferred shape since, happy to rebase behind a newStreamReadFeature.Scope: PR 1 of a series covering
ReaderBasedJsonParseralone, and just for field names.UTF8DataInputJsonParser(never received #1541), and the async parser (string-value) may follow as separate PRs matching the #1541 → #1567 → #1583 progression.