From 0b851576304b17a8cb9c9a47461f66a186ef11ae Mon Sep 17 00:00:00 2001 From: Cody Guldner Date: Thu, 1 Oct 2026 11:15:27 -0500 Subject: [PATCH 1/8] [csharp] Serialize JSON-content header parameters as JSON A header parameter declared with `content: application/json` was serialized through `ClientUtils.ParameterToString(...)`, which for a model object falls through to `Convert.ToString(obj, ...)` and emits the model's debug `ToString()` representation instead of JSON. This affects every C# client library. Mirror the existing `queryIsJsonMimeType` mechanism: add a shared `headerIsJsonMimeType` flag to CodegenParameter, set in DefaultCodegen.fromParameter via the existing isJsonMimeType(contentType) helper. The C# api templates use it to serialize JSON-content headers as JSON instead of via ParameterToString, keeping existing behavior for regular headers: - restsharp, httpclient, unityWebRequest (Newtonsoft): a new ClientUtils.ParameterToJsonString helper producing ASCII-safe JSON. - generichost (System.Text.Json): JsonSerializer.Serialize(value, _jsonSerializerOptions), consistent with how it serializes bodies. Adds a 3.1 fixture and regression tests for the restsharp and generichost serialization backends. Fixes #25082 --- .../codegen/CodegenParameter.java | 9 ++- .../openapitools/codegen/DefaultCodegen.java | 1 + .../resources/csharp/ClientUtils.mustache | 15 +++++ .../src/main/resources/csharp/api.mustache | 8 +-- .../csharp/libraries/generichost/api.mustache | 8 +-- .../csharp/libraries/httpclient/api.mustache | 8 +-- .../libraries/unityWebRequest/api.mustache | 8 +-- .../CSharpClientCodegenTest.java | 57 +++++++++++++++++++ .../3_1/csharp/json-header-content.yaml | 34 +++++++++++ 9 files changed, 131 insertions(+), 17 deletions(-) create mode 100644 modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content.yaml diff --git a/modules/openapi-generator/src/main/java/org/openapitools/codegen/CodegenParameter.java b/modules/openapi-generator/src/main/java/org/openapitools/codegen/CodegenParameter.java index 90c4c66558c0..aea887c1300d 100644 --- a/modules/openapi-generator/src/main/java/org/openapitools/codegen/CodegenParameter.java +++ b/modules/openapi-generator/src/main/java/org/openapitools/codegen/CodegenParameter.java @@ -50,6 +50,10 @@ public class CodegenParameter implements IJsonSchemaValidationProperties { * If a query parameter should be serialized as json */ public boolean queryIsJsonMimeType; + /** + * True when a header parameter uses a JSON media type in Parameter.content. + */ + public boolean headerIsJsonMimeType; /** * datatype is the generic inner parameter of a std::optional for C++, or Optional (Java) */ @@ -270,6 +274,7 @@ public CodegenParameter copy() { output.isArray = this.isArray; output.isMap = this.isMap; output.queryIsJsonMimeType = this.queryIsJsonMimeType; + output.headerIsJsonMimeType = this.headerIsJsonMimeType; output.isOptional = this.isOptional; output.isExplode = this.isExplode; output.style = this.style; @@ -294,7 +299,7 @@ public int hashCode() { isFormStyle, isSpaceDelimited, isPipeDelimited, jsonSchema, isString, isNumeric, isInteger, isLong, isNumber, isFloat, isDouble, isDecimal, isByteArray, isBinary, isBoolean, isDate, isDateTime, isUuid, isUri, isEmail, isPassword, - isFreeFormObject, isAnyType, isArray, isMap, queryIsJsonMimeType, isOptional, isFile, isEnum, isEnumRef, _enum, allowableValues, + isFreeFormObject, isAnyType, isArray, isMap, queryIsJsonMimeType, headerIsJsonMimeType, isOptional, isFile, isEnum, isEnumRef, _enum, allowableValues, items, mostInnerItems, additionalProperties, vars, requiredVars, vendorExtensions, hasValidation, getMaxProperties(), getMinProperties(), isNullable, isDeprecated, required, getMaximum(), getExclusiveMaximum(), getMinimum(), getExclusiveMinimum(), getMaxLength(), getMinLength(), @@ -345,6 +350,7 @@ public boolean equals(Object o) { isArray == that.isArray && isMap == that.isMap && queryIsJsonMimeType == that.queryIsJsonMimeType && + headerIsJsonMimeType == that.headerIsJsonMimeType && isOptional == that.isOptional && isFile == that.isFile && isEnum == that.isEnum && @@ -486,6 +492,7 @@ public String toString() { sb.append(", isArray=").append(isArray); sb.append(", isMap=").append(isMap); sb.append(", queryIsJsonMimeType=").append(queryIsJsonMimeType); + sb.append(", headerIsJsonMimeType=").append(headerIsJsonMimeType); sb.append(", isOptional=").append(isOptional); sb.append(", isFile=").append(isFile); sb.append(", isEnum=").append(isEnum); diff --git a/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java b/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java index fc74115f6b4c..90478d5dd015 100644 --- a/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java +++ b/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java @@ -5722,6 +5722,7 @@ public CodegenParameter fromParameter(Parameter parameter, Set imports) codegenParameter.isPathParam = true; } else if (parameter instanceof HeaderParameter || "header".equalsIgnoreCase(parameter.getIn())) { codegenParameter.isHeaderParam = true; + codegenParameter.headerIsJsonMimeType = isJsonMimeType(codegenParameter.contentType); } else if (parameter instanceof CookieParameter || "cookie".equalsIgnoreCase(parameter.getIn())) { codegenParameter.isCookieParam = true; } else { diff --git a/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache b/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache index 5c42d2e4fe33..7363beb1f1a5 100644 --- a/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache @@ -146,6 +146,21 @@ namespace {{packageName}}.Client return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/modules/openapi-generator/src/main/resources/csharp/api.mustache b/modules/openapi-generator/src/main/resources/csharp/api.mustache index 7093752ea76c..73d071c32b7c 100644 --- a/modules/openapi-generator/src/main/resources/csharp/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/api.mustache @@ -349,12 +349,12 @@ namespace {{packageName}}.{{apiPackage}} {{/queryParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} @@ -639,12 +639,12 @@ namespace {{packageName}}.{{apiPackage}} {{/constantParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache index 9a12abf424bb..e44ba3021c5a 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache @@ -578,11 +578,11 @@ namespace {{packageName}}.{{apiPackage}} // Set client side default value of Header Param "{{baseName}}". if (ClientUtils.IsContentHeader("{{baseName}}")) { - httpRequestMessageLocalVar.Content?.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{paramName}})); + httpRequestMessageLocalVar.Content?.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{paramName}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{paramName}}){{/headerIsJsonMimeType}}); } else { - httpRequestMessageLocalVar.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{paramName}})); + httpRequestMessageLocalVar.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{paramName}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{paramName}}){{/headerIsJsonMimeType}}); } {{/required}} @@ -592,11 +592,11 @@ namespace {{packageName}}.{{apiPackage}} // Set client side default value of Header Param "{{baseName}}". if (ClientUtils.IsContentHeader("{{baseName}}")) { - httpRequestMessageLocalVar.Content?.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{paramName}}.Value)); + httpRequestMessageLocalVar.Content?.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{paramName}}.Value, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{paramName}}.Value){{/headerIsJsonMimeType}}); } else { - httpRequestMessageLocalVar.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{paramName}}.Value)); + httpRequestMessageLocalVar.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{paramName}}.Value, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{paramName}}.Value){{/headerIsJsonMimeType}}); } } diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache index f7330c2cc26b..331b3396fa00 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache @@ -430,12 +430,12 @@ namespace {{packageName}}.{{apiPackage}} {{/queryParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} @@ -647,12 +647,12 @@ namespace {{packageName}}.{{apiPackage}} {{/constantParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/unityWebRequest/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/unityWebRequest/api.mustache index c94df9125759..eb058f580536 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/unityWebRequest/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/unityWebRequest/api.mustache @@ -356,12 +356,12 @@ namespace {{packageName}}.{{apiPackage}} {{/queryParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} @@ -567,12 +567,12 @@ namespace {{packageName}}.{{apiPackage}} {{/queryParams}} {{#headerParams}} {{#required}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter {{/required}} {{^required}} if ({{paramName}} != null) { - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{paramName}})); // header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{paramName}})); // header parameter } {{/required}} {{/headerParams}} diff --git a/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java b/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java index 55e7cb4d720f..7342abdbfca2 100644 --- a/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java +++ b/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java @@ -203,6 +203,63 @@ public void testHandleConstantParams() throws IOException { "localVarRequestOptions.HeaderParameters.Add(\"X-CUSTOM_CONSTANT_HEADER\", Org.OpenAPITools.Client.ClientUtils.ParameterToString(\"CONSTANT_VALUE\"));"); } + @Test + public void testJsonContentHeaderUsesJsonSerialization() throws IOException { + File output = Files.createTempDirectory("test").toFile().getCanonicalFile(); + output.deleteOnExit(); + final OpenAPI openAPI = TestUtils.parseFlattenSpec("src/test/resources/3_1/csharp/json-header-content.yaml"); + final DefaultGenerator defaultGenerator = new DefaultGenerator(); + final ClientOptInput clientOptInput = new ClientOptInput(); + clientOptInput.openAPI(openAPI); + CSharpClientCodegen cSharpClientCodegen = new CSharpClientCodegen(); + cSharpClientCodegen.setLibrary("restsharp"); + cSharpClientCodegen.setOutputDir(output.getAbsolutePath()); + clientOptInput.config(cSharpClientCodegen); + defaultGenerator.opts(clientOptInput); + + Map files = defaultGenerator.generate().stream() + .collect(Collectors.toMap(File::getPath, Function.identity())); + + File apiFile = files + .get(Paths.get(output.getAbsolutePath(), "src", "Org.OpenAPITools", "Api", "DefaultApi.cs").toString()); + assertNotNull(apiFile); + // JSON-content header is serialized as JSON, not via ParameterToString (which would emit the model's debug ToString()). + assertFileContains(apiFile.toPath(), + "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToJsonString(xJsonArg)); // header parameter"); + assertFileNotContains(apiFile.toPath(), + "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToString(xJsonArg)); // header parameter"); + // A regular (non-JSON) header keeps the existing behavior. + assertFileContains(apiFile.toPath(), + "localVarRequestOptions.HeaderParameters.Add(\"X-Plain-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToString(xPlainArg)); // header parameter"); + } + + @Test + public void testJsonContentHeaderUsesJsonSerializationGenericHost() throws IOException { + File output = Files.createTempDirectory("test").toFile().getCanonicalFile(); + output.deleteOnExit(); + final OpenAPI openAPI = TestUtils.parseFlattenSpec("src/test/resources/3_1/csharp/json-header-content.yaml"); + final DefaultGenerator defaultGenerator = new DefaultGenerator(); + final ClientOptInput clientOptInput = new ClientOptInput(); + clientOptInput.openAPI(openAPI); + CSharpClientCodegen cSharpClientCodegen = new CSharpClientCodegen(); + cSharpClientCodegen.setLibrary("generichost"); + cSharpClientCodegen.setOutputDir(output.getAbsolutePath()); + clientOptInput.config(cSharpClientCodegen); + defaultGenerator.opts(clientOptInput); + + Map files = defaultGenerator.generate().stream() + .collect(Collectors.toMap(File::getPath, Function.identity())); + + File apiFile = files + .get(Paths.get(output.getAbsolutePath(), "src", "Org.OpenAPITools", "Api", "DefaultApi.cs").toString()); + assertNotNull(apiFile); + // JSON-content header is serialized with System.Text.Json using the client's serializer options. + assertFileContains(apiFile.toPath(), + "JsonSerializer.Serialize(xJsonArg, _jsonSerializerOptions)"); + assertFileContains(apiFile.toPath(), + "ClientUtils.ParameterToString(xPlainArg)"); + } + @Test public void testUserAgentIsNotUrlEncoded() throws IOException { // both restsharp Configuration templates: the default one and the useIntForTimeout v7.9.0 fallback diff --git a/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content.yaml b/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content.yaml new file mode 100644 index 000000000000..56fb448d7ce4 --- /dev/null +++ b/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content.yaml @@ -0,0 +1,34 @@ +openapi: 3.1.0 + +info: + title: JSON header repro + version: 1.0.0 + +paths: + /test: + post: + operationId: testJsonHeader + parameters: + - name: X-Json-Arg + in: header + required: true + content: + application/json: + schema: + $ref: '#/components/schemas/HeaderArg' + - name: X-Plain-Arg + in: header + required: true + schema: + type: string + responses: + '204': + description: OK + +components: + schemas: + HeaderArg: + type: object + properties: + path: + type: string From 64172480a6670b4ead17f41615b12b33ed728480 Mon Sep 17 00:00:00 2001 From: Cody Guldner Date: Thu, 1 Oct 2026 11:15:28 -0500 Subject: [PATCH 2/8] [csharp] Regenerate samples for JSON-content header serialization Adds the ClientUtils.ParameterToJsonString helper to the generated Newtonsoft-based clients (restsharp, httpclient, unityWebRequest). --- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ .../src/Org.OpenAPITools/Client/ClientUtils.cs | 15 +++++++++++++++ 23 files changed, 345 insertions(+) diff --git a/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 116c891b4646..9c57e2848b5f 100644 --- a/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -131,6 +131,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs index 510c80551eb5..8dd5bdf6cd10 100644 --- a/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 5b7acd47520f..89373c32e074 100644 --- a/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..54a517aee2cb 100644 --- a/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 5b7acd47520f..89373c32e074 100644 --- a/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..54a517aee2cb 100644 --- a/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 77cb3226ed07..ccd518ff2cf4 100644 --- a/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 5b7acd47520f..89373c32e074 100644 --- a/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..54a517aee2cb 100644 --- a/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs index ba5c33ca6779..dffa9035f21f 100644 --- a/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 77cb3226ed07..ccd518ff2cf4 100644 --- a/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 77cb3226ed07..ccd518ff2cf4 100644 --- a/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..54a517aee2cb 100644 --- a/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 5ebe54e20468..bc8913ae38cf 100644 --- a/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,6 +130,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..54a517aee2cb 100644 --- a/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs index 02d02e362929..28e7da0ccdf4 100644 --- a/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,6 +130,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs index 8ba2457f7bd4..1a841377f970 100644 --- a/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,6 +130,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index a3765e002293..54a517aee2cb 100644 --- a/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,6 +146,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs index 77cb3226ed07..ccd518ff2cf4 100644 --- a/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 77cb3226ed07..ccd518ff2cf4 100644 --- a/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,6 +140,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 2c7601dc903a..6336f24b5742 100644 --- a/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,6 +130,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 2c7601dc903a..6336f24b5742 100644 --- a/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,6 +130,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// diff --git a/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 12fe4347fc80..8da34b9f4323 100644 --- a/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -124,6 +124,21 @@ public static string Serialize(object obj) return obj != null ? Newtonsoft.Json.JsonConvert.SerializeObject(obj) : null; } + /// + /// Serializes the given object as an ASCII-safe JSON string. Used to serialize the value of + /// a header parameter whose content type is JSON (e.g. content: application/json), + /// so model objects are rendered as JSON instead of their debug ToString() representation. + /// + /// The object to serialize. + /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + public static string ParameterToJsonString(object obj) + { + return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + { + StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii + }); + } + /// /// Encode string in base64 format. /// From 38580f0a0b5fb4b8bbd61eb5f9bea704bf9db753 Mon Sep 17 00:00:00 2001 From: Cody Guldner Date: Thu, 1 Oct 2026 11:46:25 -0500 Subject: [PATCH 3/8] [csharp] Address review on JSON-content header serialization - ParameterToJsonString: escape every character >= U+007F (including DEL) as \uXXXX by post-processing the final JSON string, mirroring the Java fix. This is more robust than Newtonsoft's EscapeNonAscii, which leaves DEL (U+007F) unescaped and is bypassed by converters that emit raw JSON. - DefaultCodegen: also treat vendor JSON media types (application/vnd.*+json) as JSON headers via isJsonVendorMimeType, so e.g. application/vnd.acme+json is serialized as JSON instead of ToString(). - Apply the JSON-aware serializer to constant (autoset) header parameters in the restsharp, httpclient and generichost templates. - Extend the fixture with a vendor +json header and add regression tests for the vendor and constant-header cases. Addresses review feedback on #25083. --- .../openapitools/codegen/DefaultCodegen.java | 3 +- .../resources/csharp/ClientUtils.mustache | 21 +++++++++--- .../src/main/resources/csharp/api.mustache | 2 +- .../csharp/libraries/generichost/api.mustache | 4 +-- .../csharp/libraries/httpclient/api.mustache | 2 +- .../CSharpClientCodegenTest.java | 33 +++++++++++++++++++ .../csharp/json-header-content-constant.yaml | 23 +++++++++++++ .../3_1/csharp/json-header-content.yaml | 7 ++++ 8 files changed, 86 insertions(+), 9 deletions(-) create mode 100644 modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml diff --git a/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java b/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java index 90478d5dd015..aea79c36dba9 100644 --- a/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java +++ b/modules/openapi-generator/src/main/java/org/openapitools/codegen/DefaultCodegen.java @@ -5722,7 +5722,8 @@ public CodegenParameter fromParameter(Parameter parameter, Set imports) codegenParameter.isPathParam = true; } else if (parameter instanceof HeaderParameter || "header".equalsIgnoreCase(parameter.getIn())) { codegenParameter.isHeaderParam = true; - codegenParameter.headerIsJsonMimeType = isJsonMimeType(codegenParameter.contentType); + codegenParameter.headerIsJsonMimeType = isJsonMimeType(codegenParameter.contentType) + || isJsonVendorMimeType(codegenParameter.contentType); } else if (parameter instanceof CookieParameter || "cookie".equalsIgnoreCase(parameter.getIn())) { codegenParameter.isCookieParam = true; } else { diff --git a/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache b/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache index 7363beb1f1a5..d465eaaa6ca2 100644 --- a/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache @@ -152,13 +152,26 @@ namespace {{packageName}}.Client /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/modules/openapi-generator/src/main/resources/csharp/api.mustache b/modules/openapi-generator/src/main/resources/csharp/api.mustache index 73d071c32b7c..6e07cfb4e930 100644 --- a/modules/openapi-generator/src/main/resources/csharp/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/api.mustache @@ -634,7 +634,7 @@ namespace {{packageName}}.{{apiPackage}} {{#constantParams}} {{#isHeaderParam}} // Set client side default value of Header Param "{{baseName}}". - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter {{/isHeaderParam}} {{/constantParams}} {{#headerParams}} diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache index e44ba3021c5a..514293d29ec0 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache @@ -564,11 +564,11 @@ namespace {{packageName}}.{{apiPackage}} // Set client side default value of Header Param "{{baseName}}". if (ClientUtils.IsContentHeader("{{baseName}}")) { - httpRequestMessageLocalVar.Content.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter + httpRequestMessageLocalVar.Content.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{#_enum}}"{{{.}}}"{{/_enum}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}}){{/headerIsJsonMimeType}}); // Constant header parameter } else { - httpRequestMessageLocalVar.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter + httpRequestMessageLocalVar.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{#_enum}}"{{{.}}}"{{/_enum}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}}){{/headerIsJsonMimeType}}); // Constant header parameter } {{/isHeaderParam}} diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache index 331b3396fa00..6d3ecbdd4869 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache @@ -642,7 +642,7 @@ namespace {{packageName}}.{{apiPackage}} {{#constantParams}} {{#isHeaderParam}} // Set client side default value of Header Param "{{baseName}}". - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter {{/isHeaderParam}} {{/constantParams}} {{#headerParams}} diff --git a/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java b/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java index 7342abdbfca2..d2c9730705b7 100644 --- a/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java +++ b/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java @@ -228,11 +228,41 @@ public void testJsonContentHeaderUsesJsonSerialization() throws IOException { "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToJsonString(xJsonArg)); // header parameter"); assertFileNotContains(apiFile.toPath(), "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToString(xJsonArg)); // header parameter"); + // A vendor JSON media type (application/vnd.*+json) is also serialized as JSON. + assertFileContains(apiFile.toPath(), + "localVarRequestOptions.HeaderParameters.Add(\"X-Vendor-Json-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToJsonString(xVendorJsonArg)); // header parameter"); // A regular (non-JSON) header keeps the existing behavior. assertFileContains(apiFile.toPath(), "localVarRequestOptions.HeaderParameters.Add(\"X-Plain-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToString(xPlainArg)); // header parameter"); } + @Test + public void testJsonContentConstantHeaderUsesJsonSerialization() throws IOException { + File output = Files.createTempDirectory("test").toFile().getCanonicalFile(); + output.deleteOnExit(); + final OpenAPI openAPI = TestUtils.parseFlattenSpec("src/test/resources/3_1/csharp/json-header-content-constant.yaml"); + final DefaultGenerator defaultGenerator = new DefaultGenerator(); + final ClientOptInput clientOptInput = new ClientOptInput(); + clientOptInput.openAPI(openAPI); + CSharpClientCodegen cSharpClientCodegen = new CSharpClientCodegen(); + cSharpClientCodegen.setLibrary("restsharp"); + cSharpClientCodegen.setOutputDir(output.getAbsolutePath()); + cSharpClientCodegen.additionalProperties().put(CodegenConstants.AUTOSET_CONSTANTS, "true"); + cSharpClientCodegen.setAutosetConstants(true); + clientOptInput.config(cSharpClientCodegen); + defaultGenerator.opts(clientOptInput); + + Map files = defaultGenerator.generate().stream() + .collect(Collectors.toMap(File::getPath, Function.identity())); + + File apiFile = files + .get(Paths.get(output.getAbsolutePath(), "src", "Org.OpenAPITools", "Api", "DefaultApi.cs").toString()); + assertNotNull(apiFile); + // A constant (autoset) header whose content type is JSON is also serialized as JSON. + assertFileContains(apiFile.toPath(), + "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Const\", Org.OpenAPITools.Client.ClientUtils.ParameterToJsonString(\"CONSTANT_VALUE\")); // Constant header parameter"); + } + @Test public void testJsonContentHeaderUsesJsonSerializationGenericHost() throws IOException { File output = Files.createTempDirectory("test").toFile().getCanonicalFile(); @@ -256,6 +286,9 @@ public void testJsonContentHeaderUsesJsonSerializationGenericHost() throws IOExc // JSON-content header is serialized with System.Text.Json using the client's serializer options. assertFileContains(apiFile.toPath(), "JsonSerializer.Serialize(xJsonArg, _jsonSerializerOptions)"); + // A vendor JSON media type (application/vnd.*+json) is also serialized as JSON. + assertFileContains(apiFile.toPath(), + "JsonSerializer.Serialize(xVendorJsonArg, _jsonSerializerOptions)"); assertFileContains(apiFile.toPath(), "ClientUtils.ParameterToString(xPlainArg)"); } diff --git a/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml b/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml new file mode 100644 index 000000000000..500c9621f6bb --- /dev/null +++ b/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml @@ -0,0 +1,23 @@ +openapi: 3.1.0 + +info: + title: JSON constant header repro + version: 1.0.0 + +paths: + /test: + post: + operationId: testJsonConstantHeader + parameters: + - name: X-Json-Const + in: header + required: true + content: + application/json: + schema: + type: string + enum: + - CONSTANT_VALUE + responses: + '204': + description: OK diff --git a/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content.yaml b/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content.yaml index 56fb448d7ce4..fd4d995eea5a 100644 --- a/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content.yaml +++ b/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content.yaml @@ -16,6 +16,13 @@ paths: application/json: schema: $ref: '#/components/schemas/HeaderArg' + - name: X-Vendor-Json-Arg + in: header + required: true + content: + application/vnd.acme.v1+json: + schema: + $ref: '#/components/schemas/HeaderArg' - name: X-Plain-Arg in: header required: true From 3845531e1bfb584cf2ae390ac69aba480e8b53b2 Mon Sep 17 00:00:00 2001 From: Cody Guldner Date: Thu, 1 Oct 2026 11:46:26 -0500 Subject: [PATCH 4/8] [csharp] Regenerate samples: ASCII-safe ParameterToJsonString helper --- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- .../Org.OpenAPITools/Client/ClientUtils.cs | 21 +++++++++++++++---- 23 files changed, 391 insertions(+), 92 deletions(-) diff --git a/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 9c57e2848b5f..12050bad7b86 100644 --- a/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -137,13 +137,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs index 8dd5bdf6cd10..6bf6fa4021a1 100644 --- a/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,13 +146,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 89373c32e074..3f4b752cfb72 100644 --- a/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,13 +152,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 54a517aee2cb..d8f410caeb4a 100644 --- a/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,13 +152,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 89373c32e074..3f4b752cfb72 100644 --- a/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,13 +152,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 54a517aee2cb..d8f410caeb4a 100644 --- a/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,13 +152,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index ccd518ff2cf4..95c2f956eb94 100644 --- a/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,13 +146,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 89373c32e074..3f4b752cfb72 100644 --- a/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,13 +152,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 54a517aee2cb..d8f410caeb4a 100644 --- a/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,13 +152,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs index dffa9035f21f..d1d258f80ed2 100644 --- a/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,13 +146,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index ccd518ff2cf4..95c2f956eb94 100644 --- a/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,13 +146,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index ccd518ff2cf4..95c2f956eb94 100644 --- a/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,13 +146,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 54a517aee2cb..d8f410caeb4a 100644 --- a/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,13 +152,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index bc8913ae38cf..1b2e463fbed3 100644 --- a/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -136,13 +136,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 54a517aee2cb..d8f410caeb4a 100644 --- a/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,13 +152,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs index 28e7da0ccdf4..f6a24ae201bc 100644 --- a/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -136,13 +136,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs index 1a841377f970..3ac6f0d18424 100644 --- a/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -136,13 +136,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 54a517aee2cb..d8f410caeb4a 100644 --- a/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,13 +152,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs index ccd518ff2cf4..95c2f956eb94 100644 --- a/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,13 +146,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index ccd518ff2cf4..95c2f956eb94 100644 --- a/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,13 +146,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 6336f24b5742..2b108ae59885 100644 --- a/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -136,13 +136,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 6336f24b5742..2b108ae59885 100644 --- a/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -136,13 +136,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// diff --git a/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 8da34b9f4323..aec778ddea0b 100644 --- a/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,13 +130,26 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with non-ASCII characters escaped as \uXXXX. + /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - return Newtonsoft.Json.JsonConvert.SerializeObject(obj, new Newtonsoft.Json.JsonSerializerSettings + string json = Serialize(obj); + if (json == null) + return null; + + // Escape every character outside the printable ASCII range (anything >= U+007F, which + // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to + // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + StringBuilder escaped = new StringBuilder(json.Length); + foreach (char c in json) { - StringEscapeHandling = Newtonsoft.Json.StringEscapeHandling.EscapeNonAscii - }); + if (c >= 0x7f) + escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); + else + escaped.Append(c); + } + + return escaped.ToString(); } /// From c55cf5af93aff02db46d1eeeb10010223137eead Mon Sep 17 00:00:00 2001 From: Cody Guldner Date: Thu, 1 Oct 2026 12:17:20 -0500 Subject: [PATCH 5/8] [csharp] Harden JSON header serialization (review round 2) - ParameterToJsonString: serialize with JsonConvert.SerializeObject directly so a null value becomes the JSON literal "null" again (reusing Serialize regressed this to a C# null), and escape every character < U+0020 (C0 controls incl. CR/LF) in addition to >= U+007F. Escaping raw control characters prevents header splitting/injection if a converter emits raw JSON control bytes. - Constant (autoset) JSON headers now render the constant as its schema type: a string constant serializes to a JSON string, an integer/boolean constant to a JSON number/boolean (previously always a quoted string). - Extend the constant fixture/test to cover both a string and an integer constant JSON header. Addresses review feedback on #25083. --- .../src/main/resources/csharp/ClientUtils.mustache | 14 +++++++------- .../src/main/resources/csharp/api.mustache | 7 ++++++- .../csharp/libraries/generichost/api.mustache | 4 ++-- .../csharp/libraries/httpclient/api.mustache | 7 ++++++- .../csharpnetcore/CSharpClientCodegenTest.java | 8 ++++++-- .../3_1/csharp/json-header-content-constant.yaml | 11 ++++++++++- 6 files changed, 37 insertions(+), 14 deletions(-) diff --git a/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache b/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache index d465eaaa6ca2..0f9346cec296 100644 --- a/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache @@ -155,17 +155,17 @@ namespace {{packageName}}.Client /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/modules/openapi-generator/src/main/resources/csharp/api.mustache b/modules/openapi-generator/src/main/resources/csharp/api.mustache index 6e07cfb4e930..77472d783f98 100644 --- a/modules/openapi-generator/src/main/resources/csharp/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/api.mustache @@ -634,7 +634,12 @@ namespace {{packageName}}.{{apiPackage}} {{#constantParams}} {{#isHeaderParam}} // Set client side default value of Header Param "{{baseName}}". - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter + {{#headerIsJsonMimeType}} + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToJsonString({{#isString}}"{{#_enum}}{{{.}}}{{/_enum}}"{{/isString}}{{^isString}}{{#_enum}}{{{.}}}{{/_enum}}{{/isString}})); // Constant header parameter + {{/headerIsJsonMimeType}} + {{^headerIsJsonMimeType}} + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter + {{/headerIsJsonMimeType}} {{/isHeaderParam}} {{/constantParams}} {{#headerParams}} diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache index 514293d29ec0..aa43b2f0de5e 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache @@ -564,11 +564,11 @@ namespace {{packageName}}.{{apiPackage}} // Set client side default value of Header Param "{{baseName}}". if (ClientUtils.IsContentHeader("{{baseName}}")) { - httpRequestMessageLocalVar.Content.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{#_enum}}"{{{.}}}"{{/_enum}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}}){{/headerIsJsonMimeType}}); // Constant header parameter + httpRequestMessageLocalVar.Content.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{#isString}}"{{#_enum}}{{{.}}}{{/_enum}}"{{/isString}}{{^isString}}{{#_enum}}{{{.}}}{{/_enum}}{{/isString}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}}){{/headerIsJsonMimeType}}); // Constant header parameter } else { - httpRequestMessageLocalVar.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{#_enum}}"{{{.}}}"{{/_enum}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}}){{/headerIsJsonMimeType}}); // Constant header parameter + httpRequestMessageLocalVar.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{#isString}}"{{#_enum}}{{{.}}}{{/_enum}}"{{/isString}}{{^isString}}{{#_enum}}{{{.}}}{{/_enum}}{{/isString}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}}){{/headerIsJsonMimeType}}); // Constant header parameter } {{/isHeaderParam}} diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache index 6d3ecbdd4869..80b6fd0c83db 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache @@ -642,7 +642,12 @@ namespace {{packageName}}.{{apiPackage}} {{#constantParams}} {{#isHeaderParam}} // Set client side default value of Header Param "{{baseName}}". - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.{{#headerIsJsonMimeType}}ParameterToJsonString{{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ParameterToString{{/headerIsJsonMimeType}}({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter + {{#headerIsJsonMimeType}} + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToJsonString({{#isString}}"{{#_enum}}{{{.}}}{{/_enum}}"{{/isString}}{{^isString}}{{#_enum}}{{{.}}}{{/_enum}}{{/isString}})); // Constant header parameter + {{/headerIsJsonMimeType}} + {{^headerIsJsonMimeType}} + localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter + {{/headerIsJsonMimeType}} {{/isHeaderParam}} {{/constantParams}} {{#headerParams}} diff --git a/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java b/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java index d2c9730705b7..981cab027806 100644 --- a/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java +++ b/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java @@ -258,9 +258,13 @@ public void testJsonContentConstantHeaderUsesJsonSerialization() throws IOExcept File apiFile = files .get(Paths.get(output.getAbsolutePath(), "src", "Org.OpenAPITools", "Api", "DefaultApi.cs").toString()); assertNotNull(apiFile); - // A constant (autoset) header whose content type is JSON is also serialized as JSON. + // A constant (autoset) JSON header is serialized as JSON, with the constant rendered as its schema type: + // a string constant becomes a JSON string ... assertFileContains(apiFile.toPath(), - "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Const\", Org.OpenAPITools.Client.ClientUtils.ParameterToJsonString(\"CONSTANT_VALUE\")); // Constant header parameter"); + "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Const-Str\", Org.OpenAPITools.Client.ClientUtils.ParameterToJsonString(\"CONSTANT_VALUE\")); // Constant header parameter"); + // ... and an integer constant stays a JSON number (not a quoted string). + assertFileContains(apiFile.toPath(), + "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Const-Int\", Org.OpenAPITools.Client.ClientUtils.ParameterToJsonString(42)); // Constant header parameter"); } @Test diff --git a/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml b/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml index 500c9621f6bb..6619fe09ebc1 100644 --- a/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml +++ b/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml @@ -9,7 +9,7 @@ paths: post: operationId: testJsonConstantHeader parameters: - - name: X-Json-Const + - name: X-Json-Const-Str in: header required: true content: @@ -18,6 +18,15 @@ paths: type: string enum: - CONSTANT_VALUE + - name: X-Json-Const-Int + in: header + required: true + content: + application/json: + schema: + type: integer + enum: + - 42 responses: '204': description: OK From 3869ed6caa5cda90d4e36b8a3af40def674a49bf Mon Sep 17 00:00:00 2001 From: Cody Guldner Date: Thu, 1 Oct 2026 12:17:21 -0500 Subject: [PATCH 6/8] [csharp] Regenerate samples: header-safe ParameterToJsonString --- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 14 +++++++------- 23 files changed, 161 insertions(+), 161 deletions(-) diff --git a/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 12050bad7b86..be8f14a6bc82 100644 --- a/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -140,17 +140,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs index 6bf6fa4021a1..fcdba0648e92 100644 --- a/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -149,17 +149,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 3f4b752cfb72..03808f7cb18f 100644 --- a/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -155,17 +155,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index d8f410caeb4a..44fc3e8a8bff 100644 --- a/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -155,17 +155,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 3f4b752cfb72..03808f7cb18f 100644 --- a/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -155,17 +155,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index d8f410caeb4a..44fc3e8a8bff 100644 --- a/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -155,17 +155,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 95c2f956eb94..9365daf07b09 100644 --- a/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -149,17 +149,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 3f4b752cfb72..03808f7cb18f 100644 --- a/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -155,17 +155,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index d8f410caeb4a..44fc3e8a8bff 100644 --- a/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -155,17 +155,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs index d1d258f80ed2..9528c44804bd 100644 --- a/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -149,17 +149,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 95c2f956eb94..9365daf07b09 100644 --- a/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -149,17 +149,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 95c2f956eb94..9365daf07b09 100644 --- a/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -149,17 +149,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index d8f410caeb4a..44fc3e8a8bff 100644 --- a/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -155,17 +155,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 1b2e463fbed3..ab78125f9948 100644 --- a/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -139,17 +139,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index d8f410caeb4a..44fc3e8a8bff 100644 --- a/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -155,17 +155,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs index f6a24ae201bc..f6610e2423bf 100644 --- a/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -139,17 +139,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs index 3ac6f0d18424..396f97631c3e 100644 --- a/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -139,17 +139,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index d8f410caeb4a..44fc3e8a8bff 100644 --- a/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -155,17 +155,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs index 95c2f956eb94..9365daf07b09 100644 --- a/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -149,17 +149,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 95c2f956eb94..9365daf07b09 100644 --- a/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -149,17 +149,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 2b108ae59885..f340101b609a 100644 --- a/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -139,17 +139,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 2b108ae59885..f340101b609a 100644 --- a/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -139,17 +139,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); diff --git a/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index aec778ddea0b..adc47e768a69 100644 --- a/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -133,17 +133,17 @@ public static string Serialize(object obj) /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. public static string ParameterToJsonString(object obj) { - string json = Serialize(obj); - if (json == null) - return null; + // JsonConvert renders a null reference as the JSON literal "null" (not a null string). + string json = Newtonsoft.Json.JsonConvert.SerializeObject(obj); - // Escape every character outside the printable ASCII range (anything >= U+007F, which - // includes DEL) as \uXXXX. This runs over the final JSON string, so it is robust to - // custom converters that emit raw JSON, producing a value safe to use as an HTTP header. + // Escape everything that is not printable ASCII: C0 controls (including CR and LF), DEL, + // and all non-ASCII characters, as \uXXXX. Because this runs over the final serialized + // string, the result is safe to use as an HTTP header value even if a custom converter + // emitted raw control characters or non-ASCII text (preventing header splitting/injection). StringBuilder escaped = new StringBuilder(json.Length); foreach (char c in json) { - if (c >= 0x7f) + if (c < 0x20 || c >= 0x7f) escaped.Append("\\u").Append(((int)c).ToString("x4", CultureInfo.InvariantCulture)); else escaped.Append(c); From 469d4ec50ea3d3d4a989017e43e13bfacaa7dc36 Mon Sep 17 00:00:00 2001 From: Cody Guldner Date: Thu, 1 Oct 2026 12:39:03 -0500 Subject: [PATCH 7/8] [csharp] Drop constant-header JSON handling; fix doc comment - Revert the JSON-aware serialization of autoset constant header parameters. An autoset (single fixed enum value) header that also declares content: application/json is not a real-world scenario, and correctly serializing arbitrary scalar constant types as JSON source literals (string vs number vs boolean, plus C# literal escaping) adds disproportionate template complexity. Constants keep the existing ParameterToString behavior. The reported bug (variable JSON headers) remains fixed. - Update the ParameterToJsonString doc comment to note that C0 control characters (including CR/LF) are escaped too. Addresses review feedback on #25083. --- .../resources/csharp/ClientUtils.mustache | 2 +- .../src/main/resources/csharp/api.mustache | 5 --- .../csharp/libraries/generichost/api.mustache | 4 +-- .../csharp/libraries/httpclient/api.mustache | 5 --- .../CSharpClientCodegenTest.java | 31 ------------------ .../csharp/json-header-content-constant.yaml | 32 ------------------- 6 files changed, 3 insertions(+), 76 deletions(-) delete mode 100644 modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml diff --git a/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache b/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache index 0f9346cec296..4127944c4b0e 100644 --- a/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/ClientUtils.mustache @@ -152,7 +152,7 @@ namespace {{packageName}}.Client /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/modules/openapi-generator/src/main/resources/csharp/api.mustache b/modules/openapi-generator/src/main/resources/csharp/api.mustache index 77472d783f98..73d071c32b7c 100644 --- a/modules/openapi-generator/src/main/resources/csharp/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/api.mustache @@ -634,12 +634,7 @@ namespace {{packageName}}.{{apiPackage}} {{#constantParams}} {{#isHeaderParam}} // Set client side default value of Header Param "{{baseName}}". - {{#headerIsJsonMimeType}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToJsonString({{#isString}}"{{#_enum}}{{{.}}}{{/_enum}}"{{/isString}}{{^isString}}{{#_enum}}{{{.}}}{{/_enum}}{{/isString}})); // Constant header parameter - {{/headerIsJsonMimeType}} - {{^headerIsJsonMimeType}} localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter - {{/headerIsJsonMimeType}} {{/isHeaderParam}} {{/constantParams}} {{#headerParams}} diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache index aa43b2f0de5e..e44ba3021c5a 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/generichost/api.mustache @@ -564,11 +564,11 @@ namespace {{packageName}}.{{apiPackage}} // Set client side default value of Header Param "{{baseName}}". if (ClientUtils.IsContentHeader("{{baseName}}")) { - httpRequestMessageLocalVar.Content.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{#isString}}"{{#_enum}}{{{.}}}{{/_enum}}"{{/isString}}{{^isString}}{{#_enum}}{{{.}}}{{/_enum}}{{/isString}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}}){{/headerIsJsonMimeType}}); // Constant header parameter + httpRequestMessageLocalVar.Content.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter } else { - httpRequestMessageLocalVar.Headers.Add("{{baseName}}", {{#headerIsJsonMimeType}}JsonSerializer.Serialize({{#isString}}"{{#_enum}}{{{.}}}{{/_enum}}"{{/isString}}{{^isString}}{{#_enum}}{{{.}}}{{/_enum}}{{/isString}}, _jsonSerializerOptions){{/headerIsJsonMimeType}}{{^headerIsJsonMimeType}}ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}}){{/headerIsJsonMimeType}}); // Constant header parameter + httpRequestMessageLocalVar.Headers.Add("{{baseName}}", ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter } {{/isHeaderParam}} diff --git a/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache b/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache index 80b6fd0c83db..331b3396fa00 100644 --- a/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache +++ b/modules/openapi-generator/src/main/resources/csharp/libraries/httpclient/api.mustache @@ -642,12 +642,7 @@ namespace {{packageName}}.{{apiPackage}} {{#constantParams}} {{#isHeaderParam}} // Set client side default value of Header Param "{{baseName}}". - {{#headerIsJsonMimeType}} - localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToJsonString({{#isString}}"{{#_enum}}{{{.}}}{{/_enum}}"{{/isString}}{{^isString}}{{#_enum}}{{{.}}}{{/_enum}}{{/isString}})); // Constant header parameter - {{/headerIsJsonMimeType}} - {{^headerIsJsonMimeType}} localVarRequestOptions.HeaderParameters.Add("{{baseName}}", {{packageName}}.Client.ClientUtils.ParameterToString({{#_enum}}"{{{.}}}"{{/_enum}})); // Constant header parameter - {{/headerIsJsonMimeType}} {{/isHeaderParam}} {{/constantParams}} {{#headerParams}} diff --git a/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java b/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java index 981cab027806..ecb47c16d44d 100644 --- a/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java +++ b/modules/openapi-generator/src/test/java/org/openapitools/codegen/csharpnetcore/CSharpClientCodegenTest.java @@ -236,37 +236,6 @@ public void testJsonContentHeaderUsesJsonSerialization() throws IOException { "localVarRequestOptions.HeaderParameters.Add(\"X-Plain-Arg\", Org.OpenAPITools.Client.ClientUtils.ParameterToString(xPlainArg)); // header parameter"); } - @Test - public void testJsonContentConstantHeaderUsesJsonSerialization() throws IOException { - File output = Files.createTempDirectory("test").toFile().getCanonicalFile(); - output.deleteOnExit(); - final OpenAPI openAPI = TestUtils.parseFlattenSpec("src/test/resources/3_1/csharp/json-header-content-constant.yaml"); - final DefaultGenerator defaultGenerator = new DefaultGenerator(); - final ClientOptInput clientOptInput = new ClientOptInput(); - clientOptInput.openAPI(openAPI); - CSharpClientCodegen cSharpClientCodegen = new CSharpClientCodegen(); - cSharpClientCodegen.setLibrary("restsharp"); - cSharpClientCodegen.setOutputDir(output.getAbsolutePath()); - cSharpClientCodegen.additionalProperties().put(CodegenConstants.AUTOSET_CONSTANTS, "true"); - cSharpClientCodegen.setAutosetConstants(true); - clientOptInput.config(cSharpClientCodegen); - defaultGenerator.opts(clientOptInput); - - Map files = defaultGenerator.generate().stream() - .collect(Collectors.toMap(File::getPath, Function.identity())); - - File apiFile = files - .get(Paths.get(output.getAbsolutePath(), "src", "Org.OpenAPITools", "Api", "DefaultApi.cs").toString()); - assertNotNull(apiFile); - // A constant (autoset) JSON header is serialized as JSON, with the constant rendered as its schema type: - // a string constant becomes a JSON string ... - assertFileContains(apiFile.toPath(), - "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Const-Str\", Org.OpenAPITools.Client.ClientUtils.ParameterToJsonString(\"CONSTANT_VALUE\")); // Constant header parameter"); - // ... and an integer constant stays a JSON number (not a quoted string). - assertFileContains(apiFile.toPath(), - "localVarRequestOptions.HeaderParameters.Add(\"X-Json-Const-Int\", Org.OpenAPITools.Client.ClientUtils.ParameterToJsonString(42)); // Constant header parameter"); - } - @Test public void testJsonContentHeaderUsesJsonSerializationGenericHost() throws IOException { File output = Files.createTempDirectory("test").toFile().getCanonicalFile(); diff --git a/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml b/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml deleted file mode 100644 index 6619fe09ebc1..000000000000 --- a/modules/openapi-generator/src/test/resources/3_1/csharp/json-header-content-constant.yaml +++ /dev/null @@ -1,32 +0,0 @@ -openapi: 3.1.0 - -info: - title: JSON constant header repro - version: 1.0.0 - -paths: - /test: - post: - operationId: testJsonConstantHeader - parameters: - - name: X-Json-Const-Str - in: header - required: true - content: - application/json: - schema: - type: string - enum: - - CONSTANT_VALUE - - name: X-Json-Const-Int - in: header - required: true - content: - application/json: - schema: - type: integer - enum: - - 42 - responses: - '204': - description: OK From 834a599e0438a0ec9dc6adc497cbd26e0bb746b7 Mon Sep 17 00:00:00 2001 From: Cody Guldner Date: Thu, 1 Oct 2026 12:39:04 -0500 Subject: [PATCH 8/8] [csharp] Regenerate samples: ParameterToJsonString doc comment --- .../net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- .../Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs | 2 +- 23 files changed, 23 insertions(+), 23 deletions(-) diff --git a/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs index be8f14a6bc82..e3787b1a8311 100644 --- a/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/echo_api/csharp/restsharp/net8/EchoApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -137,7 +137,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs index fcdba0648e92..d4d76fa0662c 100644 --- a/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/others/csharp-complex-files/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,7 +146,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 03808f7cb18f..2f93eb8fd38e 100644 --- a/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net10/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,7 +152,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 44fc3e8a8bff..5976bafe2823 100644 --- a/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,7 +152,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs index 03808f7cb18f..2f93eb8fd38e 100644 --- a/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net9/Petstore-nonPublicApi/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,7 +152,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 44fc3e8a8bff..5976bafe2823 100644 --- a/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,7 +152,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 9365daf07b09..06699bfc386b 100644 --- a/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/httpclient/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,7 +146,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 03808f7cb18f..2f93eb8fd38e 100644 --- a/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net10/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,7 +152,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 44fc3e8a8bff..5976bafe2823 100644 --- a/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,7 +152,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs index 9528c44804bd..66e372d5c6d9 100644 --- a/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.7/MultipleFrameworks/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,7 +146,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 9365daf07b09..06699bfc386b 100644 --- a/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.7/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,7 +146,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 9365daf07b09..06699bfc386b 100644 --- a/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net4.8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,7 +146,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 44fc3e8a8bff..5976bafe2823 100644 --- a/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,7 +152,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index ab78125f9948..7fa3d4709d28 100644 --- a/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/ParameterMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -136,7 +136,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 44fc3e8a8bff..5976bafe2823 100644 --- a/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,7 +152,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs index f6610e2423bf..27c78cc269c8 100644 --- a/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/UseDateTimeForDate/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -136,7 +136,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs index 396f97631c3e..02232ccae29f 100644 --- a/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net8/useVirtualForHooks/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -136,7 +136,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs index 44fc3e8a8bff..5976bafe2823 100644 --- a/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/net9/EnumMappings/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -152,7 +152,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs index 9365daf07b09..06699bfc386b 100644 --- a/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/standard2.0/ConditionalSerialization/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,7 +146,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index 9365daf07b09..06699bfc386b 100644 --- a/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/restsharp/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -146,7 +146,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index f340101b609a..e4b650c9de82 100644 --- a/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/net10/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -136,7 +136,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index f340101b609a..e4b650c9de82 100644 --- a/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/net9/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -136,7 +136,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string). diff --git a/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs b/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs index adc47e768a69..5d6275437696 100644 --- a/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs +++ b/samples/client/petstore/csharp/unityWebRequest/standard2.0/Petstore/src/Org.OpenAPITools/Client/ClientUtils.cs @@ -130,7 +130,7 @@ public static string Serialize(object obj) /// so model objects are rendered as JSON instead of their debug ToString() representation. /// /// The object to serialize. - /// JSON representation of the object with every non-ASCII character (including DEL, U+007F) escaped as \uXXXX. + /// JSON representation of the object with every C0 control character (including CR and LF), DEL, and non-ASCII character escaped as \uXXXX, so raw control bytes can never reach the header value. public static string ParameterToJsonString(object obj) { // JsonConvert renders a null reference as the JSON literal "null" (not a null string).