What's wrong
PrefixAndSuffixAttribute.ValidateValue (Semantics.Strings/Validation/Attributes/Text/PrefixAndSuffixAttribute.cs:54-71) has two problems.
1. The prefix and suffix can overlap. It checks StartsWith(prefix) and EndsWith(suffix) independently and never requires value.Length >= prefix.Length + suffix.Length. So one character can serve as both the prefix and the suffix.
2. Empty strings always pass. It returns Success for string.IsNullOrEmpty(value). The sibling [StartsWith] (StartsWithAttribute.cs:49-52) and [EndsWith] reject an empty string, and ValidationStrategyTests.EmptyString_WithValidations_HandledCorrectly asserts that rejection for StartsWith.
Reproduced against HEAD 9c64b67:
- A type with
[PrefixAndSuffix("\"", "\"")]: Create("\"") succeeds.
- The same type:
Create("") succeeds.
- A type with
[PrefixAndSuffix("ab", "ba")]: Create("aba") succeeds.
Why it matters
The obvious use of this attribute is a "quoted string" or "delimited token" type. Such a type currently accepts values that don't contain both delimiters, and code downstream that strips prefix.Length and suffix.Length characters will throw ArgumentOutOfRangeException or produce garbage on those values.
Suggested fix
- Fail when
value.Length < prefix.Length + suffix.Length.
- Treat an empty string the way
[StartsWith]/[EndsWith] do.
Acceptance criteria
- The three inputs above throw
ArgumentException from Create.
- The existing
PrefixAndSuffix_* tests in AttributeValidationTests.cs (e.g. "PrefixTestSuffix") still pass.
What's wrong
PrefixAndSuffixAttribute.ValidateValue(Semantics.Strings/Validation/Attributes/Text/PrefixAndSuffixAttribute.cs:54-71) has two problems.1. The prefix and suffix can overlap. It checks
StartsWith(prefix)andEndsWith(suffix)independently and never requiresvalue.Length >= prefix.Length + suffix.Length. So one character can serve as both the prefix and the suffix.2. Empty strings always pass. It returns
Successforstring.IsNullOrEmpty(value). The sibling[StartsWith](StartsWithAttribute.cs:49-52) and[EndsWith]reject an empty string, andValidationStrategyTests.EmptyString_WithValidations_HandledCorrectlyasserts that rejection forStartsWith.Reproduced against HEAD 9c64b67:
[PrefixAndSuffix("\"", "\"")]:Create("\"")succeeds.Create("")succeeds.[PrefixAndSuffix("ab", "ba")]:Create("aba")succeeds.Why it matters
The obvious use of this attribute is a "quoted string" or "delimited token" type. Such a type currently accepts values that don't contain both delimiters, and code downstream that strips
prefix.Lengthandsuffix.Lengthcharacters will throwArgumentOutOfRangeExceptionor produce garbage on those values.Suggested fix
value.Length < prefix.Length + suffix.Length.[StartsWith]/[EndsWith]do.Acceptance criteria
ArgumentExceptionfromCreate.PrefixAndSuffix_*tests inAttributeValidationTests.cs(e.g."PrefixTestSuffix") still pass.