Sitelet https://github.com/flutter/flutter/pull/193417
Skip to content

[flutter_tools] Validate optional parameter names in gen-l10n - #193417

Open
anilcancakir wants to merge 1 commit into
flutter:masterfrom
anilcancakir:fix-193327
Open

anilcancakir wants to merge 1 commit into
flutter:masterfrom
anilcancakir:fix-193327

Conversation

@anilcancakir

Copy link
Copy Markdown

In flutter gen-l10n, the keys of a placeholder's optionalParameters map were written into the generated NumberFormat constructor call as named arguments (gen_l10n.dart, '${parameter.name}: ${parameter.value}') without any validation. A crafted key in any ARB file, including a translated locale whose template is benign, could close the constructor call and inject arbitrary Dart statements; the issue shows the result still analyzes cleanly. The values were already safe: numbers are written as is and everything else goes through generateString.

This PR rejects optional parameter names that are not valid Dart identifiers with an L10nException while parsing the placeholder, the same way #192434 validates placeholder types. Keys that are not identifiers either failed to compile or only worked by accident (a name padded with whitespace, such as "decimalDigits "); they now fail with a clear message. No ARB in this repo uses such a key.

The issue suggests an allowlist of the named parameters each NumberFormat constructor supports. A single identifier cannot close the call, so the identifier check already stops the injection, and a wrong but valid name is still reported by the analyzer; an allowlist would additionally tie the tool to intl's constructor signatures.

The new test uses the reproduction from the issue: a benign en template and an es translation whose optionalParameters key injects a print statement. Before the fix setupLocalizations generated the localizations without complaint; now it throws L10nException.

Fixes #193327

Pre-launch Checklist

If you need help, consider asking for advice on the #hackers-new channel on Discord.

If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance.

Note: The Flutter team is currently trialing the use of Gemini Code Assist for GitHub. Comments from the gemini-code-assist bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed.

@github-actions github-actions Bot added the tool Affects the "flutter" command-line tool. See also t: labels. label Sep 27, 2026
@anilcancakir
anilcancakir marked this pull request as ready for review September 27, 2026 22:34

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces validation for optional parameter names in localization placeholders, ensuring they are valid Dart identifiers to prevent code injection or generation issues. It adds a regular expression check and throws an L10nException if an invalid parameter name is encountered, accompanied by a regression test. Feedback on the changes suggests updating a documentation comment for a private member to use triple slashes (///) instead of double slashes (//) to comply with the Flutter Style Guide.

Comment thread packages/flutter_tools/lib/src/localizations/gen_l10n_types.dart Outdated
The keys of a placeholder's "optionalParameters" map were written into
the generated NumberFormat constructor call as named arguments without
any validation, so a crafted ARB key could close the call and inject
arbitrary Dart statements into the generated localizations.

Reject optional parameter names that are not valid Dart identifiers with
an L10nException, as is already done for placeholder types.

Fixes flutter#193327
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tool Affects the "flutter" command-line tool. See also t: labels.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

gen-l10n optionalParameters keys can inject arbitrary Dart source from ARB files

1 participant