Skip to content

Add search-users-by-email endpoint - #618

Open
evanpleasic-crypto wants to merge 1 commit into
snyk-labs:mainfrom
evanpleasic-crypto:demo/search-endpoint
Open

evanpleasic-crypto wants to merge 1 commit into
snyk-labs:mainfrom
evanpleasic-crypto:demo/search-endpoint

Conversation

@evanpleasic-crypto

Copy link
Copy Markdown

Summary

  • Adds a /user/search endpoint (SearchUserAction) that looks up users by a partial email match
  • Backed by a parameterized JPQL named query (findUsersByEmail) rather than string-concatenated SQL, avoiding SQL injection in the lookup
  • Wires the new repository/service methods (searchUsersByEmail) through the existing JPA-based UserRepository/UserService layers, following the same pattern as the existing todo-search feature
  • Adds a search box to the sidebar and a results view (user/search.jsp)

Test plan

  • Deploy the app and log in
  • Use the new "Search users" box in the sidebar to search by a partial email
  • Confirm matching users are listed and no results shows the "no user" message
  • Confirm input containing SQL metacharacters (e.g. ' OR '1'='1) is treated as a literal search term, not SQL syntax

🤖 Generated with Claude Code

Adds a /user/search endpoint (SearchUserAction) that looks up users by
a partial email match, backed by a parameterized JPQL named query
(findUsersByEmail) to avoid SQL injection in the lookup.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant