diff --git a/modules/openapi-generator/src/main/java/org/openapitools/codegen/CodegenParameter.java b/modules/openapi-generator/src/main/java/org/openapitools/codegen/CodegenParameter.java index 90c4c66558c0..aea887c1300d 100644 --- a/modules/openapi-generator/src/main/java/org/openapitools/codegen/CodegenParameter.java +++ b/modules/openapi-generator/src/main/java/org/openapitools/codegen/CodegenParameter.java @@ -50,6 +50,10 @@ public class CodegenParameter implements IJsonSchemaValidationProperties { * If a query parameter should be serialized as json */ public boolean queryIsJsonMimeType; + /** + * True when a header parameter uses a JSON media type in Parameter.content. + */ + public boolean headerIsJsonMimeType; /** * datatype is the generic inner parameter of a std::optional for C++, or Optional (Java) */ @@ -270,6 +274,7 @@ public CodegenParameter copy() { output.isArray = this.isArray; output.isMap = this.isMap; output.queryIsJsonMimeType = this.queryIsJsonMimeType; + output.headerIsJsonMimeType = this.headerIsJsonMimeType; output.isOptional = this.isOptional; output.isExplode = this.isExplode; output.style = this.style; @@ -294,7 +299,7 @@ public int hashCode() { isFormStyle, isSpaceDelimited, isPipeDelimited, jsonSchema, isString, isNumeric, isInteger, isLong, isNumber, isFloat, isDouble, isDecimal, isByteArray, isBinary, isBoolean, isDate, isDateTime, isUuid, isUri, isEmail, isPassword, - isFreeFormObject, isAnyType, isArray, isMap, queryIsJsonMimeType, isOptional, isFile, isEnum, isEnumRef, _enum, allowableValues, + isFreeFormObject, isAnyType, isArray, isMap, queryIsJsonMimeType, headerIsJsonMimeType, isOptional, isFile, isEnum, isEnumRef, _enum, allowableValues, items, mostInnerItems, additionalProperties, vars, requiredVars, vendorExtensions, hasValidation, getMaxProperties(), getMinProperties(), isNullable, isDeprecated, required, getMaximum(), getExclusiveMaximum(), getMinimum(), getExclusiveMinimum(), getMaxLength(), getMinLength(), @@ -345,6 +350,7 @@ public boolean equals(Object o) { isArray == that.isArray && isMap == that.isMap && queryIsJsonMimeType == that.queryIsJsonMimeType && + headerIsJsonMimeType == that.headerIsJsonMimeType && isOptional == that.isOptional && isFile == that.isFile && isEnum == that.isEnum && @@ -486,6 +492,7 @@ public String toString() { sb.append(", isArray=").append(isArray); sb.append(", isMap=").append(isMap); sb.append(", queryIsJsonMimeType=").append(queryIsJsonMimeType); + sb.append(", headerIsJsonMimeType=").append(headerIsJsonMimeType); sb.append(", isOptional=").append(isOptional); sb.append(", isFile=").append(isFile); sb.append(", isEnum=").append(isEnum); diff --git a/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java b/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java index fc74115f6b4c..aea79c36dba9 100644 --- a/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java +++ b/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java @@ -5722,6 +5722,8 @@ public CodegenParameter fromParameter(Parameter parameter, Set imports) codegenParameter.isPathParam = true; } else if (parameter instanceof HeaderParameter || "header".equalsIgnoreCase(parameter.getIn())) { codegenParameter.isHeaderParam = true; + codegenParameter.headerIsJsonMimeType = isJsonMimeType(codegenParameter.contentType) + || isJsonVendorMimeType(codegenParameter.contentType); } else if (parameter instanceof CookieParameter || "cookie".equalsIgnoreCase(parameter.getIn())) { codegenParameter.isCookieParam = true; } else { diff --git a/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache b/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache index 5c42d2e4fe33..4127944c4b0e 100644 --- a/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache @@ -146,6 +146,34 @@ namespace {{packageName}}.Client return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/modules/openapi-generator/src/main/resources/csharp/api.mustache b/modules/openapi-generator/src/main/resources/csharp/api.mustache index 7093752ea76c..73d071c32b7c 100644 --- a/modules/openapi-generator/src/main/resources/csharp/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/api.mustache @@ -349,12 +349,12 @@ namespace {{packageName}}.{{apiPackage}} {{/queryParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} @@ -639,12 +639,12 @@ namespace {{packageName}}.{{apiPackage}} {{/constantParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache index 9a12abf424bb..e44ba3021c5a 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache @@ -578,11 +578,11 @@ namespace {{packageName}}.{{apiPackage}} // Set client side default value of Header Param "{{baseName}}". if (ClientUtils.IsContentHeader("{{baseName}}")) { - httpRequestMessageLocalVar.Content?.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{paramName}})); + httpRequestMessageLocalVar.Content?.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{paramName}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{paramName}}){{/headerIsJsonMimeType}}); } else { - httpRequestMessageLocalVar.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{paramName}})); + httpRequestMessageLocalVar.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{paramName}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{paramName}}){{/headerIsJsonMimeType}}); } {{/required}} @@ -592,11 +592,11 @@ namespace {{packageName}}.{{apiPackage}} // Set client side default value of Header Param "{{baseName}}". if (ClientUtils.IsContentHeader("{{baseName}}")) { - httpRequestMessageLocalVar.Content?.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{paramName}}.Value)); + httpRequestMessageLocalVar.Content?.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{paramName}}.Value, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{paramName}}.Value){{/headerIsJsonMimeType}}); } else { - httpRequestMessageLocalVar.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{paramName}}.Value)); + httpRequestMessageLocalVar.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{paramName}}.Value, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{paramName}}.Value){{/headerIsJsonMimeType}}); } } diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache index f7330c2cc26b..331b3396fa00 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache @@ -430,12 +430,12 @@ namespace {{packageName}}.{{apiPackage}} {{/queryParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} @@ -647,12 +647,12 @@ namespace {{packageName}}.{{apiPackage}} {{/constantParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/unityWebRequest/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/unityWebRequest/api.mustache index c94df9125759..eb058f580536 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/unityWebRequest/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/unityWebRequest/api.mustache @@ -356,12 +356,12 @@ namespace {{packageName}}.{{apiPackage}} {{/queryParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} @@ -567,12 +567,12 @@ namespace {{packageName}}.{{apiPackage}} {{/queryParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} diff --git a/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java b/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java index 55e7cb4d720f..ecb47c16d44d 100644 --- a/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java +++ b/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java @@ -203,6 +203,69 @@ public void testHandleConstantParams() throws IOException { "localVarRequestOptions.HeaderParameters.Add(\"X-CUSTOM_CONSTANT_HEADER\", Org.OpenAPITools.Client.ClientUtils.ParameterToString(\"CONSTANT_VALUE\"));"); } + @Test + public void testJsonContentHeaderUsesJsonSerialization() throws IOException { + File output = Files.createTempDirectory("test").toFile().getCanonicalFile(); + output.deleteOnExit(); + final OpenAPI openAPI = TestUtils.parseFlattenSpec("src/test/resources/3_1/csharp/json-header-content.yaml"); + final DefaultGenerator defaultGenerator = new DefaultGenerator(); + final ClientOptInput clientOptInput = new ClientOptInput(); + clientOptInput.openAPI(openAPI); + CSharpClientCodegen cSharpClientCodegen = new CSharpClientCodegen(); + cSharpClientCodegen.setLibrary("restsharp"); + cSharpClientCodegen.setOutputDir(output.getAbsolutePath()); + clientOptInput.config(cSharpClientCodegen); + defaultGenerator.opts(clientOptInput); + + Map files = defaultGenerator.generate().stream() + .collect(Collectors.toMap(File::getPath, Function.identity())); + + File apiFile = files + .get(Paths.get(output.getAbsolutePath(), "src", "Org.OpenAPITools", "Api", "DefaultApi.cs").toString()); + assertNotNull(apiFile); + // JSON-content header is serialized as JSON, not via ParameterToString (which would emit the model's debug ToString()). + assertFileContains(apiFile.toPath(), + "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToJsonString(xJsonArg)); // header parameter"); + assertFileNotContains(apiFile.toPath(), + "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToString(xJsonArg)); // header parameter"); + // A vendor JSON media type (application/vnd.*+json) is also serialized as JSON. + assertFileContains(apiFile.toPath(), + "localVarRequestOptions.HeaderParameters.Add(\"X-Vendor-Json-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToJsonString(xVendorJsonArg)); // header parameter"); + // A regular (non-JSON) header keeps the existing behavior. + assertFileContains(apiFile.toPath(), + "localVarRequestOptions.HeaderParameters.Add(\"X-Plain-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToString(xPlainArg)); // header parameter"); + } + + @Test + public void testJsonContentHeaderUsesJsonSerializationGenericHost() throws IOException { + File output = Files.createTempDirectory("test").toFile().getCanonicalFile(); + output.deleteOnExit(); + final OpenAPI openAPI = TestUtils.parseFlattenSpec("src/test/resources/3_1/csharp/json-header-content.yaml"); + final DefaultGenerator defaultGenerator = new DefaultGenerator(); + final ClientOptInput clientOptInput = new ClientOptInput(); + clientOptInput.openAPI(openAPI); + CSharpClientCodegen cSharpClientCodegen = new CSharpClientCodegen(); + cSharpClientCodegen.setLibrary("generichost"); + cSharpClientCodegen.setOutputDir(output.getAbsolutePath()); + clientOptInput.config(cSharpClientCodegen); + defaultGenerator.opts(clientOptInput); + + Map files = defaultGenerator.generate().stream() + .collect(Collectors.toMap(File::getPath, Function.identity())); + + File apiFile = files + .get(Paths.get(output.getAbsolutePath(), "src", "Org.OpenAPITools", "Api", "DefaultApi.cs").toString()); + assertNotNull(apiFile); + // JSON-content header is serialized with System.Text.Json using the client's serializer options. + assertFileContains(apiFile.toPath(), + "JsonSerializer.Serialize(xJsonArg, _jsonSerializerOptions)"); + // A vendor JSON media type (application/vnd.*+json) is also serialized as JSON. + assertFileContains(apiFile.toPath(), + "JsonSerializer.Serialize(xVendorJsonArg, _jsonSerializerOptions)"); + assertFileContains(apiFile.toPath(), + "ClientUtils.ParameterToString(xPlainArg)"); + } + @Test public void testUserAgentIsNotUrlEncoded() throws IOException { // both restsharp Configuration templates: the default one and the useIntForTimeout v7.9.0 fallback diff --git a/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content.yaml b/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content.yaml new file mode 100644 index 000000000000..fd4d995eea5a --- /dev/null +++ b/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content.yaml @@ -0,0 +1,41 @@ +openapi: 3.1.0 + +info: + title: JSON header repro + version: 1.0.0 + +paths: + /test: + post: + operationId: testJsonHeader + parameters: + - name: X-Json-Arg + in: header + required: true + content: + application/json: + schema: + $ref: '#/components/schemas/HeaderArg' + - name: X-Vendor-Json-Arg + in: header + required: true + content: + application/vnd.acme.v1+json: + schema: + $ref: '#/components/schemas/HeaderArg' + - name: X-Plain-Arg + in: header + required: true + schema: + type: string + responses: + '204': + description: OK + +components: + schemas: + HeaderArg: + type: object + properties: + path: + type: string diff --git a/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 116c891b4646..e3787b1a8311 100644 --- a/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -131,6 +131,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs index 510c80551eb5..d4d76fa0662c 100644 --- a/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 5b7acd47520f..2f93eb8fd38e 100644 --- a/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..5976bafe2823 100644 --- a/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 5b7acd47520f..2f93eb8fd38e 100644 --- a/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..5976bafe2823 100644 --- a/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 77cb3226ed07..06699bfc386b 100644 --- a/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 5b7acd47520f..2f93eb8fd38e 100644 --- a/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..5976bafe2823 100644 --- a/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs index ba5c33ca6779..66e372d5c6d9 100644 --- a/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 77cb3226ed07..06699bfc386b 100644 --- a/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 77cb3226ed07..06699bfc386b 100644 --- a/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..5976bafe2823 100644 --- a/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 5ebe54e20468..7fa3d4709d28 100644 --- a/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,6 +130,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..5976bafe2823 100644 --- a/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs index 02d02e362929..27c78cc269c8 100644 --- a/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,6 +130,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs index 8ba2457f7bd4..02232ccae29f 100644 --- a/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,6 +130,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..5976bafe2823 100644 --- a/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs index 77cb3226ed07..06699bfc386b 100644 --- a/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 77cb3226ed07..06699bfc386b 100644 --- a/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 2c7601dc903a..e4b650c9de82 100644 --- a/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,6 +130,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 2c7601dc903a..e4b650c9de82 100644 --- a/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,6 +130,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 12fe4347fc80..5d6275437696 100644 --- a/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -124,6 +124,34 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. + public static string ParameterToJsonString(object obj) + { + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); + + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) + { + if (c < 0x20 || c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); + } + /// /// Encode string in base64 format. ///