Skip to content

Commit b987b1f

Browse files
Potential fix for code scanning alert no. 1: Log Injection
Fixed Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
1 parent d0c3e49 commit b987b1f

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

src/main/java/uk/gov/hmcts/cp/subscription/controllers/SubscriptionController.java

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,10 @@ public class SubscriptionController implements SubscriptionApi {
2727
@Override
2828
@Transactional
2929
public ResponseEntity<ClientSubscription> createClientSubscription(final String callbackUrl,
30-
final CreateClientSubscriptionRequest request) {
30+
final String sanitizedCallbackUrl = callbackUrl == null
31+
? null
32+
: callbackUrl.replace("\r", " ").replace("\n", " ");
33+
log.info("createClientSubscription callbackUrl:{} clientId:{}", sanitizedCallbackUrl, CLIENT_ID);
3134
log.info("createClientSubscription callbackUrl:{} clientId:{}", getSanitizedCallbackUrl(callbackUrl), CLIENT_ID);
3235
final ClientSubscription response = subscriptionService.saveSubscription(callbackUrl, request);
3336
log.info("createClientSubscription created subscription:{}", response.getClientSubscriptionId());

0 commit comments

Comments
 (0)