Skip to content

Conversation

@Fl0ux
Copy link

@Fl0ux Fl0ux commented Feb 5, 2026

In the api controller, validation is done using doubles quotes to check class type. This can lead to errors by interpreting a part of the string as an escaped character.

For exemple, if it compares class name like this one "\My\Namespace\Xcase", "\Xca" will be interpreted as an hexadecimal character and the validator will not match the class.
See https://www.php.net/manual/en/regexp.reference.escape.php for more informations.

Using single quotes fix the problem as strings are not interpreted as escaped ones.

PR checklist

  • Read the contribution guidelines.
  • Pull Request title clearly describes the work in the pull request and Pull Request description provides details about how to validate the work. Missing information here may result in delayed response from the community.
  • Run the following to build the project and update samples:
    ./mvnw clean package || exit
    ./bin/generate-samples.sh ./bin/configs/*.yaml || exit
    ./bin/utils/export_docs_generators.sh || exit
    
    (For Windows users, please run the script in WSL)
    Commit all changed files.
    This is important, as CI jobs will verify all generator outputs of your HEAD commit as it would merge with master.
    These must match the expectations made by your contribution.
    You may regenerate an individual generator by passing the relevant config(s) as an argument to the script, for example ./bin/generate-samples.sh bin/configs/java*.
    IMPORTANT: Do NOT purge/delete any folders/files (e.g. tests) when regenerating the samples as manually written tests may be removed.
  • File the PR against the correct branch: master (upcoming 7.x.0 minor release - breaking changes with fallbacks), 8.0.x (breaking changes without fallbacks)
  • If your PR solves a reported issue, reference it using GitHub's linking syntax (e.g., having "fixes #123" present in the PR description)
  • If your PR is targeting a particular programming language, @mention the technical committee members, so they are more likely to review the pull request.

@jebentier, @dkarlovi, @mandrean, @jfastnacht, @ybelenko, @renepardon


Summary by cubic

Switch Assert\Type strings to single quotes in the PHP Symfony generator to prevent PHP escape-sequence interpretation during class type validation. Regenerated Symfony samples; added a missing return type in the test AppKernel.

  • Bug Fixes
    • Updated api_input_validation.mustache to use single quotes for non-enum types (models and primitives).
    • Prevents misvalidation when class names include backslashes that could be read as escapes (e.g., "\Xca").

Written for commit c57b655. Summary will update on new commits.

Copy link
Contributor

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 4 files

@wing328
Copy link
Member

wing328 commented Feb 9, 2026

thanks for the PR

can you please review the build failure when you've time?

@wing328
Copy link
Member

wing328 commented Feb 9, 2026

Thanks for the PR but your commit (as shown in the Commits tab) is not linked to your Github account, which means this PR won't count as your contribution in https://github.com/OpenAPITools/openapi-generator/graphs/contributors.

Let me know if you need help fixing it.

Ref: https://github.com/OpenAPITools/openapi-generator/wiki/FAQ#how-can-i-update-commits-that-are-not-linked-to-my-github-account
Thanks for the PR but your commit (as shown in the Commits tab) is not linked to your Github account, which means this PR won't count as your contribution in https://github.com/OpenAPITools/openapi-generator/graphs/contributors.

Let me know if you need help fixing it.

Ref: https://github.com/OpenAPITools/openapi-generator/wiki/FAQ#how-can-i-update-commits-that-are-not-linked-to-my-github-account

@wing328 wing328 added this to the 7.20.0 milestone Feb 9, 2026
@Fl0ux Fl0ux force-pushed the php-symfony-fix-sequencial-escape branch from b3afaf6 to c57b655 Compare February 9, 2026 13:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants