I'm looking into creating a set of REST endpoints that call the Jira cloud API using JQL, specifically this API:
https://developer.atlassian.com/cloud/jira/platform/rest/v3/#api-api-3-search-post
I'm using JQL to search issues because I have custom fields that I need to query against and do not intend on using the issue id(s) at all as part of the search.
// javascipt
const jql = `project = PROJ AND "Some field" ~ ":input_from_user"`
// :input_from_user needs to be sanitized so things like
// "some value AND" cannot be used for the value
Usually with this kind of access, when you allow custom parameters to be sent by the end-user, you have to be careful with SQL-like injection.
Is there anything I can use to build JQL queries in a secure fashion in this scenario? In most database libraries, you can create prepared statements w/ parameter binding.
Is there a good list of operators / keywords / escape items that can be referenced against to possibly build my own sanitization function?
Or is it recommended that JQL-based APIs only be used for internal purposes only?
I'd rather not resort to having to connect to the database that Jira connects to and write SQL directly against it (but at least the SQL drivers / libraries have the capability of preventing injection attacks), so was curious.