From e5548b3d2d195c5b6b94484d5bdf3318601d16f1 Mon Sep 17 00:00:00 2001 From: Jacopo Carlini Date: Thu, 26 Sep 2024 17:01:15 +0200 Subject: [PATCH] Fix code scanning alert no. 538: Log Injection Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .../payments/controller/receipt/impl/PaymentsController.java | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/main/java/it/gov/pagopa/payments/controller/receipt/impl/PaymentsController.java b/src/main/java/it/gov/pagopa/payments/controller/receipt/impl/PaymentsController.java index b94646b..277a880 100644 --- a/src/main/java/it/gov/pagopa/payments/controller/receipt/impl/PaymentsController.java +++ b/src/main/java/it/gov/pagopa/payments/controller/receipt/impl/PaymentsController.java @@ -36,13 +36,14 @@ public PaymentsController(PaymentsService paymentsService) { public ResponseEntity getReceiptByIUV( String organizationFiscalCode, String iuv, String segregationCodes) { String sanitizedOrganizationFiscalCode = sanitizeInput(organizationFiscalCode); + String sanitizedIuv = sanitizeInput(iuv); log.debug( String.format( LOG_BASE_HEADER_INFO, "GET", String.format(LOG_BASE_PARAMS_DETAIL, sanitizedOrganizationFiscalCode) + "; iuv= " - + iuv + + sanitizedIuv + "; validSegregationCodes= " + segregationCodes));