T09 · Insecure Skill Coding Practices
- Location
scripts/salesforce-helper.sh:46- Finding
User-Controlled Values Are Directly Interpolated into SOQL Queries
- Content
View full analysis
${NC}" exit 1 fi echo -e "${GREEN}🔍 Searching Contacts: $SEARCH${NC}" sf data query --query " SELECT Id, Name, Email, Phone, Account.Name FROM Contact WHERE Name LIKE '%$SEARCH%' OR Email LIKE '%$SEARCH%' LIMIT 25 " $ORG_FLAG --result-format table ;; ``` ```bash search-accounts) SEARCH="${1:-}" if [[ -z "$SEARCH" ]]; then echo -e "${RED}Usage: search-accounts ${NC}" exit 1 fi echo -e "${GREEN}🔍 Searching Accounts: $SEARCH${NC}" sf data query --query " SELECT Id, Name, Industry, Website, (SELECT Name, Email FROM Contacts LIMIT 5) FROM Account WHERE Name LIKE '%$SEARCH%' LIMIT 25 " $ORG_FLAG --result-format table ;; ``` ### Technical Analysis Arguments such as `SEARCH`, `LIMIT`, and `DAYS` are inserted directly into SOQL text. The script ...[truncated 1839 chars]- Remediation
View remediation
&2 exit 1 } (( value >= 1 && value <= maximum )) || { echo "Value is outside the permitted range" >&2 exit 1 } } validate_positive_integer "$LIMIT" 200 validate_positive_integer "$DAYS" 365 ``` - Escape all SOQL string literals with a dedicated, tested routine that handles at least single quotes and backslashes according to Salesforce SOQL rules. - Prefer Salesforce-supported parameter binding or a structured query interface when one is available. - Construct queries only from fixed templates. Do not permit user input to control selected fields, object names, operators, ordering, or arbitrary clauses. - Apply least-privilege Salesforce profiles and permission sets so that a query injection cannot access unrelated objects or sensitive fields. - Add automated tests using apostrophes, backslashes, wildcard characters, clause fragments, and invalid numeric values. ]]>
