From: Javid Khan Date: Mon, 20 Jul 2026 09:14:51 +0000 (+0530) Subject: reject empty reference token as array index in json_pointer X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=70f3169bae5f2306fbb1a70e02b3f6ade96e47f4;p=thirdparty%2Fjson-c.git reject empty reference token as array index in json_pointer --- diff --git a/json_pointer.c b/json_pointer.c index f7bf696..9d7ad18 100644 --- a/json_pointer.c +++ b/json_pointer.c @@ -46,6 +46,12 @@ static void string_replace_all_occurrences_with_char(char *s, const char *occur, static int is_valid_index(const char *path, size_t *idx) { size_t i, len = strlen(path); + /* an empty reference token is never a valid array index */ + if (len == 0) + { + errno = EINVAL; + return 0; + } /* this code-path optimizes a bit, for when we reference the 0-9 index range * in a JSON array and because leading zeros not allowed */ diff --git a/tests/test_json_pointer.c b/tests/test_json_pointer.c index 09c195a..b18c98a 100644 --- a/tests/test_json_pointer.c +++ b/tests/test_json_pointer.c @@ -203,6 +203,10 @@ static void test_wrong_inputs_get(void) assert(0 != json_pointer_get(jo1, "/foo/01", NULL)); assert(errno == EINVAL); errno = 0; + /* An empty reference token is not a valid array index */ + assert(0 != json_pointer_get(jo1, "/foo/", NULL)); + assert(errno == EINVAL); + errno = 0; assert(0 != json_pointer_getf(jo1, NULL, "/%s/a", "foo")); assert(errno == EINVAL); errno = 0; @@ -314,6 +318,10 @@ static void test_wrong_inputs_set(void) printf("PASSED - SET - failed with invalid array index'\n"); json_object_put(jo2); + assert(0 != json_pointer_set(&jo1, "/foo/", (jo2 = json_object_new_string("cod")))); + printf("PASSED - SET - failed with empty array index'\n"); + json_object_put(jo2); + jo2 = json_object_new_string("whatever"); assert(0 != json_pointer_set(&jo1, "/fud/gaw", jo2)); assert(0 == json_pointer_set(&jo1, "/fud", json_object_new_object())); diff --git a/tests/test_json_pointer.expected b/tests/test_json_pointer.expected index 7cb158e..3b363a5 100644 --- a/tests/test_json_pointer.expected +++ b/tests/test_json_pointer.expected @@ -36,4 +36,5 @@ PASSED - SET - failed with NULL params for input json & path PASSED - SET - failed 'cod' with path 'foo/bar' PASSED - SET - failed 'cod' with path 'foo/bar' PASSED - SET - failed with invalid array index' +PASSED - SET - failed with empty array index' PASSED - SET - failed to set index to non-array