Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-44754

If the form is broken custom fields may result in NPE

    Details

      Description

      If for some reason the HTML form for the custom fields got badly implemented (perhaps had coded) it's possible for an NPE to be thrown when verifying the inputs.

      [do not QA, observed potential risk during code review]

      Assume a custom field is created with the name colour who's type is an array of values (exact type does not matter).

      The HTML inputs for custom fields is usually generated by the

      <liferay-ui:custom-attribute />

      tag and the HTML looks something like so:

      <input name="_58_ExpandoAttributeName--colour--" type="hidden" value="colour" />
      <select name="_58_ExpandoAttribute--colour--" multiple>
      <option>red</option>
      <option>white</option>
      <option>blue</option>
      <option>green</option>
      </select>
      

      If you place this code in a page where custom fields are supported, the ServiceContext will populate it's expando attributes with an attribute called colour with an array of values something like ["red", "white"] (whatever was selected).

      However, if the HTML is broken, and only the following remains:

      <input name="_58_ExpandoAttributeName--colour--" type="hidden" value="colour" />
      

      the server side could get confused and cause an null pointer exception.

      To reproduce:

      • add a custom field to some entity, make the type an array (the group/collection ones)
      • go to the add operation for the entity
      • while on the UI edit the HTML to remove the actual form inputs for the custom field
      • do NOT remove the custom field's hidden field
      • fill the other entity required fields
      • save

      If everything went according to plan, you should see an error page and an exception in the log.

        Attachments

          Issue Links

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:
                  Days since last comment:
                  5 years, 41 weeks, 1 day ago

                  Packages

                  Version Package
                  6.1.X EE
                  6.2.2 CE GA3
                  6.2.X EE
                  7.0.0 M1