Skip to content

[PrefixAndSuffix] lets prefix and suffix overlap: [PrefixAndSuffix("\"", "\"")] accepts a lone ", and empty strings always pass #338

Description

@matt-edmondson

What's wrong

PrefixAndSuffixAttribute.ValidateValue (Semantics.Strings/Validation/Attributes/Text/PrefixAndSuffixAttribute.cs:54-71) has two problems.

1. The prefix and suffix can overlap. It checks StartsWith(prefix) and EndsWith(suffix) independently and never requires value.Length >= prefix.Length + suffix.Length. So one character can serve as both the prefix and the suffix.

2. Empty strings always pass. It returns Success for string.IsNullOrEmpty(value). The sibling [StartsWith] (StartsWithAttribute.cs:49-52) and [EndsWith] reject an empty string, and ValidationStrategyTests.EmptyString_WithValidations_HandledCorrectly asserts that rejection for StartsWith.

Reproduced against HEAD 9c64b67:

  • A type with [PrefixAndSuffix("\"", "\"")]: Create("\"") succeeds.
  • The same type: Create("") succeeds.
  • A type with [PrefixAndSuffix("ab", "ba")]: Create("aba") succeeds.

Why it matters

The obvious use of this attribute is a "quoted string" or "delimited token" type. Such a type currently accepts values that don't contain both delimiters, and code downstream that strips prefix.Length and suffix.Length characters will throw ArgumentOutOfRangeException or produce garbage on those values.

Suggested fix

  • Fail when value.Length < prefix.Length + suffix.Length.
  • Treat an empty string the way [StartsWith]/[EndsWith] do.

Acceptance criteria

  • The three inputs above throw ArgumentException from Create.
  • The existing PrefixAndSuffix_* tests in AttributeValidationTests.cs (e.g. "PrefixTestSuffix") still pass.

Activity

  1. matt-edmondson commented on Sep 30, 2026

    @matt-edmondson
    ContributorAuthor

    Triage

    • Category: Bug
    • Priority: Medium. It is a validation hole: types built on [PrefixAndSuffix] accept values that lack one of the delimiters, and code that strips the delimiters then throws or produces garbage. The empty-string behaviour also doesn't match [StartsWith]/[EndsWith]. Tightening it may break callers that currently rely on "" being accepted, so it is worth a note in the release.
    • Area: Semantics.Strings/Validation/Attributes/Text/PrefixAndSuffixAttribute.cs.
    • Suggested assignment: Semantics.Strings validation maintainer.
    • Duplicates / in progress: None found, and no open PR touches validation attributes.

    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

bugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions