Repository navigation
[flutter_tools] Validate optional parameter names in gen-l10n - #193417
Open
anilcancakir wants to merge 1 commit into
Open
anilcancakir wants to merge 1 commit into
anilcancakir wants to merge 1 commit into
Conversation
anilcancakir
marked this pull request as ready for review
September 27, 2026 22:34
Contributor
There was a problem hiding this comment.
Code Review
This pull request introduces validation for optional parameter names in localization placeholders, ensuring they are valid Dart identifiers to prevent code injection or generation issues. It adds a regular expression check and throws an L10nException if an invalid parameter name is encountered, accompanied by a regression test. Feedback on the changes suggests updating a documentation comment for a private member to use triple slashes (///) instead of double slashes (//) to comply with the Flutter Style Guide.
The keys of a placeholder's "optionalParameters" map were written into the generated NumberFormat constructor call as named arguments without any validation, so a crafted ARB key could close the call and inject arbitrary Dart statements into the generated localizations. Reject optional parameter names that are not valid Dart identifiers with an L10nException, as is already done for placeholder types. Fixes flutter#193327
anilcancakir
force-pushed
the
fix-193327
branch
from
September 27, 2026 23:02
4b9f434 to
7ad5075
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
In
flutter gen-l10n, the keys of a placeholder'soptionalParametersmap were written into the generatedNumberFormatconstructor call as named arguments (gen_l10n.dart,'${parameter.name}: ${parameter.value}') without any validation. A crafted key in any ARB file, including a translated locale whose template is benign, could close the constructor call and inject arbitrary Dart statements; the issue shows the result still analyzes cleanly. The values were already safe: numbers are written as is and everything else goes throughgenerateString.This PR rejects optional parameter names that are not valid Dart identifiers with an
L10nExceptionwhile parsing the placeholder, the same way #192434 validates placeholder types. Keys that are not identifiers either failed to compile or only worked by accident (a name padded with whitespace, such as"decimalDigits "); they now fail with a clear message. No ARB in this repo uses such a key.The issue suggests an allowlist of the named parameters each
NumberFormatconstructor supports. A single identifier cannot close the call, so the identifier check already stops the injection, and a wrong but valid name is still reported by the analyzer; an allowlist would additionally tie the tool to intl's constructor signatures.The new test uses the reproduction from the issue: a benign
entemplate and anestranslation whoseoptionalParameterskey injects aprintstatement. Before the fixsetupLocalizationsgenerated the localizations without complaint; now it throwsL10nException.Fixes #193327
Pre-launch Checklist
///).If you need help, consider asking for advice on the #hackers-new channel on Discord.
If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance.
Note: The Flutter team is currently trialing the use of Gemini Code Assist for GitHub. Comments from the
gemini-code-assistbot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed.