如何修复Jenkins Pipeline中SonarQube检测到的SpringBoot项目JavaScript代码无副作用语句严重漏洞
Let's break down why SonarQube is flagging your code, then walk through practical fixes that address both the vulnerability and your actual goal of passing the penArKeysArray data to your Spring Boot backend.
Why the Vulnerability Triggers
Your code includes this line:
document.getElementById("pendingARModID").action = "annualReviewApproval?status="+ status, {penArKeys : penArKeysArray};
The comma operator here executes both expressions, but the second one ({penArKeys : penArKeysArray}) is just an object literal that gets evaluated and immediately discarded—it doesn't do anything. It has no side effects, isn't assigned to a variable, and doesn't impact control flow. SonarQube sees this as a clear programming mistake (likely a syntax slip or incomplete code) and flags it as a critical vulnerability.
Fix Options (Aligned with Your Goal)
It looks like you want to pass both the status value and penArKeysArray to your backend when the form submits. Here are the cleanest, most reliable ways to do this:
Option 1: Append the Array to the Form's Action URL
If you prefer to pass data via URL query parameters (good for GET requests), build the URL properly using URLSearchParams to handle array formatting:
const form = document.getElementById("pendingARModID"); const actionUrl = new URL("annualReviewApproval", window.location.origin); // Add status parameter actionUrl.searchParams.append("status", status); // Add each array element as a separate penArKeys parameter penArKeysArray.forEach(key => actionUrl.searchParams.append("penArKeys", key)); // Set the formatted action URL form.action = actionUrl.toString();
This creates a URL like annualReviewApproval?status=approved&penArKeys=key1&penArKeys=key2, which your Spring Boot controller can easily parse with @RequestParam List<String> penArKeys.
Option 2: Add Hidden Form Fields for the Array
For POST requests (or to avoid cluttering the URL), add hidden input fields to the form for each element in the array:
const form = document.getElementById("pendingARModID"); // First, remove any existing penArKeys hidden fields to avoid duplicates form.querySelectorAll('input[name="penArKeys"]').forEach(input => input.remove()); // Add a hidden input for each key in the array penArKeysArray.forEach(key => { const hiddenInput = document.createElement("input"); hiddenInput.type = "hidden"; hiddenInput.name = "penArKeys"; hiddenInput.value = key; form.appendChild(hiddenInput); }); // Set the base action URL with status form.action = `annualReviewApproval?status=${status}`;
When the form submits, these hidden fields will be sent alongside other form data, and your Spring Boot backend can pick them up with @RequestParam List<String> penArKeys.
Option 3: Use AJAX for Asynchronous Submission (No Page Refresh)
If you want to submit data without reloading the page, skip setting the form's action entirely and use fetch with FormData:
const form = document.getElementById("pendingARModID"); const formData = new FormData(form); // Add status and array elements to the FormData object formData.append("status", status); penArKeysArray.forEach(key => formData.append("penArKeys", key)); // Submit via fetch fetch("annualReviewApproval", { method: form.method || "POST", body: formData }) .then(response => { // Handle success (e.g., redirect or show a message) if (response.ok) { window.location.href = "/approval-success"; } }) .catch(error => console.error("Submission failed:", error));
This approach gives you full control over the submission flow and keeps the user on the page.
Final Checks
After applying any of these fixes, re-run your SonarQube scan—the vulnerability should be resolved. Be sure to test the form submission to confirm that both status and penArKeysArray are being correctly received by your Spring Boot backend.
内容的提问来源于stack exchange,提问作者Biswabir

