Browse Source

Wrap SpEL documentation with admonition.

Closes #4085
3.3.x
Mark Paluch 4 years ago
parent
commit
864c94f490
No known key found for this signature in database
GPG Key ID: 4406B84C1661DCD1
  1. 4
      src/main/asciidoc/reference/mongo-repositories.adoc

4
src/main/asciidoc/reference/mongo-repositories.adoc

@ -501,9 +501,9 @@ public interface PersonRepository extends MongoRepository<Person, String> { @@ -501,9 +501,9 @@ public interface PersonRepository extends MongoRepository<Person, String> {
}
----
SpEL in query strings can be a powerful way to enhance queries.
WARNING: SpEL in query strings can be a powerful way to enhance queries.
However, they can also accept a broad range of unwanted arguments.
You should make sure to sanitize strings before passing them to the query to avoid unwanted changes to your query.
Make sure to sanitize strings before passing them to the query to avoid creation of vulnerabilities or unwanted changes to your query.
Expression support is extensible through the Query SPI: `org.springframework.data.repository.query.spi.EvaluationContextExtension`.
The Query SPI can contribute properties and functions and can customize the root object.

Loading…
Cancel
Save