java-topology/defects/exposed/patch/exposed-0002-isAKeyword.patch
russell@unturf.com 547a9f5738 ORM wave 2: 10 new defects — Active Record +3, Exposed +3, SeaORM +4 (167 sites, 64 ecosystems)
rails-0009: FilterAttributeHandler filter_parameters Array O(A×F) → Set (450×)
rails-0010: Encryption::AutoFilteredParameters two Array scans → Set (250×)
rails-0011: TimeZoneConversion skip_list Array O(M×C×S) → Set (20×)

exposed-0001: SchemaUtilityApi mapMissingColumnStatements O(N×M) → map (118×)
exposed-0002: IdentifierManagerApi isAKeyword O(K) linear → HashSet (144×)
exposed-0003: Table.clone consParams.map fresh List → hoisted HashSet (6×)

seaorm-0001: active_model establish_links leftover.any O(N²) → HashSet (501×)
seaorm-0002: rbac engine group_permissions .values().find() → HashMap by ID (502×)
seaorm-0003: schema builder sorted_tables Vec::contains → HashSet (500×)
seaorm-0004: TopologicalSort from_iter seen Vec O(N²) → BTreeSet (28×)

Unit tests: RailsTest 11/11, ExposedTest 3/3, SeaORMTest 4/4 PASS
Whitepaper: 157→167 sites, 62→64 ecosystems; §13.12 ORM Wave 2 added
2026-03-27 13:49:46 -04:00

20 lines
1.1 KiB
Diff

--- a/exposed-core/src/main/kotlin/org/jetbrains/exposed/v1/core/statements/api/IdentifierManagerApi.kt
+++ b/exposed-core/src/main/kotlin/org/jetbrains/exposed/v1/core/statements/api/IdentifierManagerApi.kt
@@ -35,6 +35,10 @@ abstract class IdentifierManagerApi {
/** All keywords for the database, including [ANSI_SQL_2003_KEYWORDS] and database-specific keywords. */
val keywords by lazy {
ANSI_SQL_2003_KEYWORDS + VENDORS_KEYWORDS[currentDialect.name].orEmpty() + dbKeywords()
}
+ // CWE-407 fix: pre-built lowercase HashSet for O(1) case-insensitive keyword lookup
+ private val keywordsLower: Set<String> by lazy {
+ keywords.mapTo(HashSet()) { it.lowercase() }
+ }
+
/** The database-specific special characters that can be additionally used in unquoted identifiers. */
protected abstract val extraNameCharacters: String
@@ -68,7 +73,7 @@ abstract class IdentifierManagerApi {
private fun String.isAKeyword(): Boolean = checkedKeywordsCache.getOrPut(lowercase()) {
- keywords.any { this.equals(it, true) }
+ this.lowercase() in keywordsLower
}