Repository navigation
[flutter_tools] validate placeholder type in gen-l10n - #192434
Merged
Merged
Conversation
Validates placeholder type in gen-l10n ARB files to ensure that only valid Dart type names are accepted, preventing arbitrary code injection into generated localizations code. Fixes flutter#192130
Contributor
There was a problem hiding this comment.
Code Review
This pull request introduces validation for placeholder types in Flutter localization files to ensure they are valid Dart type names, throwing an L10nException if validation fails, and adds a corresponding regression test. Feedback on the changes identifies a potential code injection vulnerability in the regular expression used for validation due to a greedy wildcard inside the generic type parameters pattern, and suggests a stricter pattern to resolve this issue.
…gument characters
dcharkes
approved these changes
Sep 9, 2026
This was referenced Sep 10, 2026
This was referenced Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Fixes #192130
In
flutter gen-l10n, placeholder types specified in.arbfiles were previously parsed with_stringAttributewithout validating whether the string is a valid Dart type identifier. When generating method parameter signatures ingenerateMethodParameters,${placeholder.type} ${placeholder.name}was directly interpolated, allowing crafted type strings to prematurely terminate the method declaration and inject arbitrary code.This change:
Placeholderparsing ingen_l10n_types.dartusing_isValidType, ensuring only valid Dart type names (including generic type parameters, library prefixes, and nullable types) are accepted.L10nExceptionif an invalid type string is encountered.generate_localizations_test.dart.Related Issues
Fixes #192130
Tests
packages/flutter_tools/test/general.shard/generate_localizations_test.dart.