Bug Report T890958
Visible to All Users

XPO validates query parameters too strictly in v20.1.3

created 5 years ago (modified 5 years ago)

Problem

We recently documented the following changes:

Unfortunately, we failed to anticipate the scope of query parameter inconsistencies within customer apps (EAP/Beta feedback did not uncover this issue). Despite benefits associated with our changes, we do not want to force XPO users to modify their code immediately or revert to previous behavior manually (with feature toggles).

Answers approved by DevExpress Support

created 5 years ago (modified 5 years ago)

We have fixed the issue described in this ticket and will include the fix in our next maintenance update. To apply this solution before the official update, request a hotfix by clicking the corresponding link for product versions you require.

Note: Hotfixes may be unavailable for beta versions and updates that are about to be released.

Additional information:

We softened default parameter validation with regard to SELECT, UPDATE, and INSERT statements in our v20.1.4 release.
We introduced a new DevExpress.Xpo.DB.QueryParameterMode enumeration with the following values:

  • Legacy: for v19.2 and older versions.
  • SetType (Default): will only validate parameter type without size. Will preserve all performance optimizations. SetType will still catch errors such as Guid parameter comparisons with strings (learn more).
  • SetTypeAndSize: will validate type and size. It will be automatically set for MSSqlConnectionProvider and Always Encrypted).

You can set the ConnectionProviderSql.QueryParameterMode field or the ConnectionProviderSql.GlobalQueryParameterMode static field as needed. Example:

C#
using DevExpress.Xpo.DB; //... ConnectionProviderSql.GlobalQueryParameterMode = QueryParameterMode.Legacy;

The majority of XPO users will not need to modify this behavior, because new defaults should address most requirements.

Feedback

Please test a new build and let us know how this solution works for you.

    Comments (2)
    M M
    Martin Praxmarer - DevExpress MVP 5 years ago

      Thx Guys for this Option!

      Dennis Garavsky (DevExpress) 5 years ago

        Thank you, Noxe!

        Disclaimer: The information provided on DevExpress.com and affiliated web properties (including the DevExpress Support Center) is provided "as is" without warranty of any kind. Developer Express Inc disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. Please refer to the DevExpress.com Website Terms of Use for more information in this regard.

        Confidential Information: Developer Express Inc does not wish to receive, will not act to procure, nor will it solicit, confidential or proprietary materials and information from you through the DevExpress Support Center or its web properties. Any and all materials or information divulged during chats, email communications, online discussions, Support Center tickets, or made available to Developer Express Inc in any manner will be deemed NOT to be confidential by Developer Express Inc. Please refer to the DevExpress.com Website Terms of Use for more information in this regard.