allthingssecurity opened a new pull request, #27528: URL: https://github.com/apache/camel/pull/27528
# Description [CAMEL-25353](https://issues.apache.org/jira/browse/CAMEL-25353) `DefaultSqlPrepareStatementStrategy.prepareQuery` found each `:?in:<name>` and then replaced every match of the regular expression `":?in:" + name` in the whole query. With `:#in:project` before `:#in:projectLicense`, the first replacement also replaced the start of the second parameter, which became `in (?,?License)` (a syntax error); and `:#in:${body[names]}` was not replaced at all, since `[` and `]` were not escaped. This change replaces each match where it is, in one pass (`Matcher.appendReplacement`), with as many placeholders as its own parameter has values. Queries that worked are prepared as before (also a name used more than once, which was replaced everywhere by its first match and is now replaced at each match with the same values), so there is no upgrade-guide note. It also no longer compiles a regular expression per `:#in:` parameter on each exchange. Tests: new `SqlProducerInParameterNamesTest`, both tests fail without the change with a `BadSqlGrammarException` (H2 sees `license in (?,?License)` and `project in (?:$ body[names] )`). camel-sql: 301 tests pass except the 2 of `SqlFunctionDataSourceTest`, whose embedded MariaDB cannot start on my machine (missing `libpcre2`), unrelated to this change. Found with a Lean 4 model of the `replaceAll` loop and of the one-pass replacement: "each IN list has the number of values of its own parameter" fails on main whenever the first name is a prefix of the second, and the fix gives the same SQL as main exactly when it is not (checked exhaustively on a small domain of names and value counts). # Target - [x] I checked that the commit is targeting the correct branch (Camel 4 uses the `main` branch) # Tracking - [x] If this is a large change, bug fix, or code improvement, I checked there is a [JIRA issue](https://issues.apache.org/jira/browse/CAMEL) filed for the change (usually before you start working on it). # Apache Camel coding standards and style - [x] I checked that each commit in the pull request has a meaningful subject line and body. - [ ] I have run `mvn clean install -DskipTests` locally from root folder and I have committed all auto-generated changes. (I built and tested the affected module, including the formatter and import-sort plugins. I did not run the full root build.) # AI-assisted contributions - [x] If this PR includes AI-generated code, commits have proper co-authorship attribution (e.g., `Co-authored-by` trailers) and the PR description identifies the AI tool used. This PR was prepared with Claude Code (Claude Opus 5.5). The commit carries a `Co-Authored-By` trailer. _Claude Code on behalf of allthingssecurity_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
