You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修复Jenkins Pipeline中SonarQube检测到的SpringBoot项目JavaScript代码无副作用语句严重漏洞

Fix for SonarQube's "Unused Expression" Vulnerability in Your JavaScript Code

Let's break down why SonarQube is flagging your code, then walk through practical fixes that address both the vulnerability and your actual goal of passing the penArKeysArray data to your Spring Boot backend.

Why the Vulnerability Triggers

Your code includes this line:

document.getElementById("pendingARModID").action = "annualReviewApproval?status="+ status, {penArKeys : penArKeysArray};

The comma operator here executes both expressions, but the second one ({penArKeys : penArKeysArray}) is just an object literal that gets evaluated and immediately discarded—it doesn't do anything. It has no side effects, isn't assigned to a variable, and doesn't impact control flow. SonarQube sees this as a clear programming mistake (likely a syntax slip or incomplete code) and flags it as a critical vulnerability.

Fix Options (Aligned with Your Goal)

It looks like you want to pass both the status value and penArKeysArray to your backend when the form submits. Here are the cleanest, most reliable ways to do this:

Option 1: Append the Array to the Form's Action URL

If you prefer to pass data via URL query parameters (good for GET requests), build the URL properly using URLSearchParams to handle array formatting:

const form = document.getElementById("pendingARModID");
const actionUrl = new URL("annualReviewApproval", window.location.origin);

// Add status parameter
actionUrl.searchParams.append("status", status);
// Add each array element as a separate penArKeys parameter
penArKeysArray.forEach(key => actionUrl.searchParams.append("penArKeys", key));

// Set the formatted action URL
form.action = actionUrl.toString();

This creates a URL like annualReviewApproval?status=approved&penArKeys=key1&penArKeys=key2, which your Spring Boot controller can easily parse with @RequestParam List<String> penArKeys.

Option 2: Add Hidden Form Fields for the Array

For POST requests (or to avoid cluttering the URL), add hidden input fields to the form for each element in the array:

const form = document.getElementById("pendingARModID");

// First, remove any existing penArKeys hidden fields to avoid duplicates
form.querySelectorAll('input[name="penArKeys"]').forEach(input => input.remove());

// Add a hidden input for each key in the array
penArKeysArray.forEach(key => {
  const hiddenInput = document.createElement("input");
  hiddenInput.type = "hidden";
  hiddenInput.name = "penArKeys";
  hiddenInput.value = key;
  form.appendChild(hiddenInput);
});

// Set the base action URL with status
form.action = `annualReviewApproval?status=${status}`;

When the form submits, these hidden fields will be sent alongside other form data, and your Spring Boot backend can pick them up with @RequestParam List<String> penArKeys.

Option 3: Use AJAX for Asynchronous Submission (No Page Refresh)

If you want to submit data without reloading the page, skip setting the form's action entirely and use fetch with FormData:

const form = document.getElementById("pendingARModID");
const formData = new FormData(form);

// Add status and array elements to the FormData object
formData.append("status", status);
penArKeysArray.forEach(key => formData.append("penArKeys", key));

// Submit via fetch
fetch("annualReviewApproval", {
  method: form.method || "POST",
  body: formData
})
.then(response => {
  // Handle success (e.g., redirect or show a message)
  if (response.ok) {
    window.location.href = "/approval-success";
  }
})
.catch(error => console.error("Submission failed:", error));

This approach gives you full control over the submission flow and keeps the user on the page.

Final Checks

After applying any of these fixes, re-run your SonarQube scan—the vulnerability should be resolved. Be sure to test the form submission to confirm that both status and penArKeysArray are being correctly received by your Spring Boot backend.

内容的提问来源于stack exchange,提问作者Biswabir

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 20:37:43