mirror of
https://github.com/apache/struts.git
synced 2026-09-10 16:19:39 +00:00
Compare commits
30 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 52628432a9 | |||
| 7ce27107e2 | |||
| a1c8af5574 | |||
| 28657e5f29 | |||
| 1b1981e987 | |||
| 1f16744114 | |||
| efda88b2bb | |||
| 28db4ac276 | |||
| d46d581b07 | |||
| bc369df815 | |||
| d1b16a7657 | |||
| e2fa549b12 | |||
| b455d6a8d4 | |||
| f8d42eb023 | |||
| f9f69482c7 | |||
| 0b14f39a2f | |||
| cf9b51669f | |||
| bf0a695dcc | |||
| 8b8838a55a | |||
| bbb111db20 | |||
| ab08c59737 | |||
| 0db282a51a | |||
| aaf286afa8 | |||
| 84ef60eae8 | |||
| fb35ed410c | |||
| 9abd02d961 | |||
| 59536d824a | |||
| ca1b22d9be | |||
| 59b5e47575 | |||
| 0e22570763 |
@@ -24,11 +24,20 @@ github:
|
||||
# it does not work because our github teams are private/secret, see INFRA-25666
|
||||
require_code_owner_reviews: false
|
||||
required_approving_review_count: 0
|
||||
release/*:
|
||||
support/struts-6-x-x:
|
||||
# contexts are the names of checks that must pass.
|
||||
required_status_checks:
|
||||
contexts:
|
||||
- "Build and Test (JDK 8)"
|
||||
- "Build and Test (8)"
|
||||
required_pull_request_reviews:
|
||||
# it does not work because our github teams are private/secret, see INFRA-25666
|
||||
require_code_owner_reviews: false
|
||||
required_approving_review_count: 0
|
||||
release/struts-6-*:
|
||||
# contexts are the names of checks that must pass.
|
||||
required_status_checks:
|
||||
contexts:
|
||||
- "Build and Test (8)"
|
||||
required_pull_request_reviews:
|
||||
# it does not work because our github teams are private/secret, see INFRA-25666
|
||||
require_code_owner_reviews: false
|
||||
|
||||
@@ -18,6 +18,7 @@ name: "CodeQL"
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- 'support/struts-6-x-x'
|
||||
- 'release/*'
|
||||
pull_request:
|
||||
|
||||
|
||||
@@ -19,7 +19,8 @@ on:
|
||||
pull_request:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
- 'support/struts-6-x-x'
|
||||
- 'release/*'
|
||||
|
||||
permissions: read-all
|
||||
|
||||
|
||||
@@ -20,7 +20,8 @@ on:
|
||||
schedule:
|
||||
- cron: "30 1 * * 6" # Weekly on Saturdays
|
||||
push:
|
||||
branches: [ "master" ]
|
||||
branches:
|
||||
- 'main' # only default branch is supported
|
||||
|
||||
permissions: read-all
|
||||
|
||||
|
||||
@@ -19,7 +19,8 @@ on:
|
||||
pull_request:
|
||||
push:
|
||||
branches:
|
||||
- release/6-8-x
|
||||
- 'support/struts-6-x-x'
|
||||
- 'release/*'
|
||||
|
||||
permissions: read-all
|
||||
|
||||
|
||||
Vendored
+4
-4
@@ -99,7 +99,7 @@ pipeline {
|
||||
stage('Code Quality') {
|
||||
when {
|
||||
anyOf {
|
||||
branch 'release/struts-6-7-x'
|
||||
branch 'support/struts-6-x-x'
|
||||
}
|
||||
}
|
||||
steps {
|
||||
@@ -145,7 +145,7 @@ pipeline {
|
||||
}
|
||||
stage('Build Source & JavaDoc') {
|
||||
when {
|
||||
branch 'release/struts-6-8-x'
|
||||
branch 'support/struts-x-x-x'
|
||||
}
|
||||
steps {
|
||||
dir("local-snapshots-dir/") {
|
||||
@@ -156,7 +156,7 @@ pipeline {
|
||||
}
|
||||
stage('Deploy Snapshot') {
|
||||
when {
|
||||
branch 'release/struts-6-8-x'
|
||||
branch 'support/struts-6-x-x'
|
||||
}
|
||||
steps {
|
||||
withCredentials([file(credentialsId: 'lukaszlenart-repository-access-token', variable: 'CUSTOM_SETTINGS')]) {
|
||||
@@ -166,7 +166,7 @@ pipeline {
|
||||
}
|
||||
stage('Upload nightlies') {
|
||||
when {
|
||||
branch 'release/struts-6-8-x'
|
||||
branch 'support/struts-6-x-x'
|
||||
}
|
||||
steps {
|
||||
sh './mvnw -B package -DskipTests'
|
||||
|
||||
+1
-1
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<packaging>pom</packaging>
|
||||
|
||||
@@ -24,12 +24,12 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-rest-showcase</artifactId>
|
||||
<packaging>war</packaging>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
<name>Struts 2 Rest Showcase Webapp</name>
|
||||
<description>Struts 2 Rest Showcase Example</description>
|
||||
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-showcase</artifactId>
|
||||
@@ -167,7 +167,7 @@
|
||||
<plugin>
|
||||
<groupId>org.apache.maven.plugins</groupId>
|
||||
<artifactId>maven-failsafe-plugin</artifactId>
|
||||
<version>3.5.5</version>
|
||||
<version>3.5.6</version>
|
||||
<configuration>
|
||||
<includes>
|
||||
<include>it.org.apache.struts2.showcase.*Test</include>
|
||||
|
||||
+2
-2
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-assembly</artifactId>
|
||||
@@ -106,7 +106,7 @@
|
||||
<plugin>
|
||||
<groupId>org.apache.maven.plugins</groupId>
|
||||
<artifactId>maven-assembly-plugin</artifactId>
|
||||
<version>3.7.1</version>
|
||||
<version>3.8.0</version>
|
||||
<executions>
|
||||
<execution>
|
||||
<id>make-assembly</id>
|
||||
|
||||
+3
-3
@@ -25,7 +25,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-bom</artifactId>
|
||||
@@ -43,7 +43,7 @@
|
||||
</licenses>
|
||||
|
||||
<properties>
|
||||
<struts-version.version>6.9.0-SNAPSHOT</struts-version.version>
|
||||
<struts-version.version>6.11.0</struts-version.version>
|
||||
<maven.site.skip>true</maven.site.skip>
|
||||
<maven.site.deploy.skip>true</maven.site.deploy.skip>
|
||||
</properties>
|
||||
@@ -189,7 +189,7 @@
|
||||
</dependencyManagement>
|
||||
|
||||
<scm>
|
||||
<tag>STRUTS_6_7_0</tag>
|
||||
<tag>STRUTS_6_11_0</tag>
|
||||
<connection>scm:git:https://gitbox.apache.org/repos/asf/struts.git</connection>
|
||||
<developerConnection>scm:git:https://gitbox.apache.org/repos/asf/struts.git</developerConnection>
|
||||
<url>https://github.com/apache/struts/</url>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-osgi-bundles</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-osgi-admin-bundle</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-osgi-bundles</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-osgi-demo-bundle</artifactId>
|
||||
|
||||
+1
-1
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-osgi-bundles</artifactId>
|
||||
|
||||
+1
-1
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
<artifactId>struts2-core</artifactId>
|
||||
<packaging>jar</packaging>
|
||||
|
||||
@@ -31,6 +31,15 @@ public interface OgnlCache<Key, Value> {
|
||||
|
||||
void putIfAbsent(Key key, Value value);
|
||||
|
||||
/**
|
||||
* Removes the mapping for the given key, if present.
|
||||
*
|
||||
* @param key the key to remove
|
||||
* @return the previous value associated with the key, or {@code null} if none
|
||||
* @since 6.11.0
|
||||
*/
|
||||
Value remove(Key key);
|
||||
|
||||
int size();
|
||||
|
||||
void clear();
|
||||
|
||||
@@ -56,6 +56,11 @@ public class OgnlCaffeineCache<K, V> implements OgnlCache<K, V> {
|
||||
cache.asMap().putIfAbsent(key, value);
|
||||
}
|
||||
|
||||
@Override
|
||||
public V remove(K key) {
|
||||
return cache.asMap().remove(key);
|
||||
}
|
||||
|
||||
@Override
|
||||
public int size() {
|
||||
return cache.asMap().size();
|
||||
|
||||
@@ -57,6 +57,11 @@ public class OgnlDefaultCache<K, V> implements OgnlCache<K, V> {
|
||||
this.clearIfEvictionLimitExceeded();
|
||||
}
|
||||
|
||||
@Override
|
||||
public V remove(K key) {
|
||||
return ognlCache.remove(key);
|
||||
}
|
||||
|
||||
@Override
|
||||
public int size() {
|
||||
return ognlCache.size();
|
||||
|
||||
@@ -64,6 +64,11 @@ public class OgnlLRUCache<K, V> implements OgnlCache<K, V> {
|
||||
ognlLRUCache.putIfAbsent(key, value);
|
||||
}
|
||||
|
||||
@Override
|
||||
public V remove(K key) {
|
||||
return ognlLRUCache.remove(key);
|
||||
}
|
||||
|
||||
@Override
|
||||
public int size() {
|
||||
return ognlLRUCache.size();
|
||||
|
||||
+102
-13
@@ -21,6 +21,10 @@ package com.opensymphony.xwork2.util;
|
||||
import com.opensymphony.xwork2.ActionContext;
|
||||
import com.opensymphony.xwork2.LocalizedTextProvider;
|
||||
import com.opensymphony.xwork2.inject.Inject;
|
||||
import com.opensymphony.xwork2.ognl.DefaultOgnlCacheFactory;
|
||||
import com.opensymphony.xwork2.ognl.OgnlCache;
|
||||
import com.opensymphony.xwork2.ognl.OgnlCacheFactory.CacheType;
|
||||
import org.apache.commons.lang3.EnumUtils;
|
||||
import org.apache.commons.lang3.ObjectUtils;
|
||||
import org.apache.logging.log4j.LogManager;
|
||||
import org.apache.logging.log4j.Logger;
|
||||
@@ -45,6 +49,11 @@ import java.util.concurrent.CopyOnWriteArrayList;
|
||||
|
||||
abstract class AbstractLocalizedTextProvider implements LocalizedTextProvider {
|
||||
|
||||
// Pinned to the value implicitly computed for the pre-6.11.0 class shape, so sessions serialized by
|
||||
// an older node still deserialize here during a rolling upgrade. The caches this change made transient
|
||||
// are simply discarded from such a stream and rebuilt by readObject.
|
||||
private static final long serialVersionUID = -4563130226985473584L;
|
||||
|
||||
private static final Logger LOG = LogManager.getLogger(AbstractLocalizedTextProvider.class);
|
||||
|
||||
public static final String XWORK_MESSAGES_BUNDLE = "com/opensymphony/xwork2/xwork-messages";
|
||||
@@ -56,16 +65,37 @@ abstract class AbstractLocalizedTextProvider implements LocalizedTextProvider {
|
||||
private static final String TOMCAT_WEBAPP_CLASSLOADER_BASE = "org.apache.catalina.loader.WebappClassLoaderBase";
|
||||
private static final String RELOADED = "com.opensymphony.xwork2.util.LocalizedTextProvider.reloaded";
|
||||
|
||||
protected final ConcurrentMap<String, ResourceBundle> bundlesMap = new ConcurrentHashMap<>();
|
||||
protected boolean devMode = false;
|
||||
protected boolean reloadBundles = false;
|
||||
protected boolean searchDefaultBundlesFirst = false; // Search default resource bundles first. Note: This flag may not be meaningful to all implementations.
|
||||
|
||||
private final ConcurrentMap<MessageFormatKey, MessageFormat> messageFormats = new ConcurrentHashMap<>();
|
||||
private final ConcurrentMap<Integer, List<String>> classLoaderMap = new ConcurrentHashMap<>();
|
||||
private final Set<String> missingBundles = ConcurrentHashMap.newKeySet();
|
||||
private final ConcurrentMap<Integer, ClassLoader> delegatedClassLoaderMap = new ConcurrentHashMap<>();
|
||||
|
||||
// Dedicated monitor for bundlesMap-related synchronization: bundlesMap is reassigned by
|
||||
// rebuildI18nCaches(), so locking on it directly would lock on a monitor that can change identity.
|
||||
// transient + reinitialised in readObject: a bare Object is not Serializable.
|
||||
private transient Object bundlesMapLock = new Object();
|
||||
|
||||
private static final int DEFAULT_I18N_CACHE_MAX_SIZE = 10000;
|
||||
|
||||
private volatile CacheType i18nCacheType = CacheType.WTLFU;
|
||||
private volatile int i18nCacheMaxSize = DEFAULT_I18N_CACHE_MAX_SIZE;
|
||||
|
||||
private <K, V> OgnlCache<K, V> buildI18nCache() {
|
||||
return new DefaultOgnlCacheFactory<K, V>(i18nCacheMaxSize, i18nCacheType).buildOgnlCache();
|
||||
}
|
||||
|
||||
// The OgnlCache implementations are themselves thread-safe; volatile only safely publishes the
|
||||
// reference when rebuildI18nCaches() replaces a cache (during injection / readObject), so S3077
|
||||
// ("volatile is not enough") does not apply here.
|
||||
@SuppressWarnings("java:S3077")
|
||||
protected transient volatile OgnlCache<String, ResourceBundle> bundlesMap = buildI18nCache();
|
||||
@SuppressWarnings("java:S3077")
|
||||
private transient volatile OgnlCache<MessageFormatKey, MessageFormat> messageFormats = buildI18nCache();
|
||||
@SuppressWarnings("java:S3077")
|
||||
private transient volatile OgnlCache<String, Boolean> missingBundles = buildI18nCache();
|
||||
|
||||
/**
|
||||
* Adds the bundle to the internal list of default bundles.
|
||||
* If the bundle already exists in the list it will be re-added.
|
||||
@@ -99,6 +129,21 @@ abstract class AbstractLocalizedTextProvider implements LocalizedTextProvider {
|
||||
return Thread.currentThread().getContextClassLoader();
|
||||
}
|
||||
|
||||
/** Test-support accessor: current number of cached resource bundles. */
|
||||
protected int bundlesMapSize() {
|
||||
return bundlesMap.size();
|
||||
}
|
||||
|
||||
/** Test-support accessor: current number of cached missing-bundle markers. */
|
||||
protected int missingBundlesSize() {
|
||||
return missingBundles.size();
|
||||
}
|
||||
|
||||
/** Test-support accessor: current number of cached message formats. */
|
||||
protected int messageFormatsSize() {
|
||||
return messageFormats.size();
|
||||
}
|
||||
|
||||
@Inject(value = StrutsConstants.STRUTS_CUSTOM_I18N_RESOURCES, required = false)
|
||||
public void setCustomI18NResources(String bundles) {
|
||||
if (bundles != null && bundles.length() > 0) {
|
||||
@@ -221,7 +266,7 @@ abstract class AbstractLocalizedTextProvider implements LocalizedTextProvider {
|
||||
* @param classLoader a {@link ClassLoader} to look up the bundle from if none can be found on the current thread's classloader
|
||||
*/
|
||||
public void setDelegatedClassLoader(final ClassLoader classLoader) {
|
||||
synchronized (bundlesMap) {
|
||||
synchronized (bundlesMapLock) {
|
||||
delegatedClassLoaderMap.put(getCurrentThreadContextClassLoader().hashCode(), classLoader);
|
||||
}
|
||||
}
|
||||
@@ -443,6 +488,52 @@ abstract class AbstractLocalizedTextProvider implements LocalizedTextProvider {
|
||||
this.searchDefaultBundlesFirst = Boolean.parseBoolean(searchDefaultBundlesFirst);
|
||||
}
|
||||
|
||||
/**
|
||||
* @param cacheType the type of cache to use for the localized-text caches
|
||||
*
|
||||
* @since 6.11.0
|
||||
*/
|
||||
@Inject(value = StrutsConstants.STRUTS_I18N_CACHE_TYPE, required = false)
|
||||
public void setI18nCacheType(String cacheType) {
|
||||
this.i18nCacheType = EnumUtils.getEnumIgnoreCase(CacheType.class, cacheType, CacheType.WTLFU);
|
||||
rebuildI18nCaches();
|
||||
}
|
||||
|
||||
/**
|
||||
* @param cacheMaxSize the maximum size of each localized-text cache
|
||||
*
|
||||
* @since 6.11.0
|
||||
*/
|
||||
@Inject(value = StrutsConstants.STRUTS_I18N_CACHE_MAXSIZE, required = false)
|
||||
public void setI18nCacheMaxSize(String cacheMaxSize) {
|
||||
this.i18nCacheMaxSize = Integer.parseInt(cacheMaxSize);
|
||||
rebuildI18nCaches();
|
||||
}
|
||||
|
||||
/**
|
||||
* Rebuilds the localized-text caches from the current type/size. Called during dependency injection
|
||||
* (single-threaded startup, before the provider serves lookups); discards any warm-up entries.
|
||||
*/
|
||||
private void rebuildI18nCaches() {
|
||||
bundlesMap = buildI18nCache();
|
||||
messageFormats = buildI18nCache();
|
||||
missingBundles = buildI18nCache();
|
||||
}
|
||||
|
||||
private void readObject(java.io.ObjectInputStream in) throws java.io.IOException, ClassNotFoundException {
|
||||
in.defaultReadObject();
|
||||
bundlesMapLock = new Object();
|
||||
// Field initialisers do not run during deserialization, so a stream written before these settings
|
||||
// existed (an older node in a rolling upgrade) leaves them at null/0. Restore the defaults.
|
||||
if (i18nCacheType == null) {
|
||||
i18nCacheType = CacheType.WTLFU;
|
||||
}
|
||||
if (i18nCacheMaxSize <= 0) {
|
||||
i18nCacheMaxSize = DEFAULT_I18N_CACHE_MAX_SIZE;
|
||||
}
|
||||
rebuildI18nCaches();
|
||||
}
|
||||
|
||||
/**
|
||||
* Finds the given resource bundle by it's name.
|
||||
* <p>
|
||||
@@ -458,34 +549,32 @@ abstract class AbstractLocalizedTextProvider implements LocalizedTextProvider {
|
||||
ClassLoader classLoader = getCurrentThreadContextClassLoader();
|
||||
String key = createMissesKey(String.valueOf(classLoader.hashCode()), aBundleName, locale);
|
||||
|
||||
if (missingBundles.contains(key)) {
|
||||
if (missingBundles.get(key) != null) {
|
||||
return null;
|
||||
}
|
||||
|
||||
ResourceBundle bundle = null;
|
||||
try {
|
||||
if (bundlesMap.containsKey(key)) {
|
||||
bundle = bundlesMap.get(key);
|
||||
} else {
|
||||
bundle = bundlesMap.get(key);
|
||||
if (bundle == null) {
|
||||
bundle = ResourceBundle.getBundle(aBundleName, locale, classLoader);
|
||||
bundlesMap.putIfAbsent(key, bundle);
|
||||
}
|
||||
} catch (MissingResourceException ex) {
|
||||
if (delegatedClassLoaderMap.containsKey(classLoader.hashCode())) {
|
||||
try {
|
||||
if (bundlesMap.containsKey(key)) {
|
||||
bundle = bundlesMap.get(key);
|
||||
} else {
|
||||
bundle = bundlesMap.get(key);
|
||||
if (bundle == null) {
|
||||
bundle = ResourceBundle.getBundle(aBundleName, locale, delegatedClassLoaderMap.get(classLoader.hashCode()));
|
||||
bundlesMap.putIfAbsent(key, bundle);
|
||||
}
|
||||
} catch (MissingResourceException e) {
|
||||
LOG.debug("Missing resource bundle [{}]!", aBundleName, e);
|
||||
missingBundles.add(key);
|
||||
missingBundles.put(key, Boolean.TRUE);
|
||||
}
|
||||
} else {
|
||||
LOG.debug("Missing resource bundle [{}]!", aBundleName);
|
||||
missingBundles.add(key);
|
||||
missingBundles.put(key, Boolean.TRUE);
|
||||
}
|
||||
}
|
||||
return bundle;
|
||||
|
||||
@@ -18,6 +18,8 @@
|
||||
*/
|
||||
package com.opensymphony.xwork2.util;
|
||||
|
||||
import com.github.benmanes.caffeine.cache.Cache;
|
||||
import com.github.benmanes.caffeine.cache.Caffeine;
|
||||
import com.opensymphony.xwork2.config.ConfigurationException;
|
||||
import com.opensymphony.xwork2.ognl.OgnlUtil;
|
||||
|
||||
@@ -33,6 +35,17 @@ import static java.util.stream.Collectors.toSet;
|
||||
import static org.apache.commons.lang3.StringUtils.strip;
|
||||
|
||||
public class ConfigParseUtil {
|
||||
// Size the cache to prevent excessive memory usage in environments with many classloaders and/or large numbers of classes being validated.
|
||||
// While still providing a reasonable caching benefit for common cases (e.g. multiple Struts instances in the same container, or multiple calls to validate the same class across different containers).
|
||||
// The cache is sized to allow for some level of caching across multiple classloaders, while still allowing for a reasonable number of classes to be cached per classloader.
|
||||
private static final int MAX_CLASSLOADER_CACHE_SIZE = 25;
|
||||
// The cache for validated classes is a two-level cache, with the first level keyed by ClassLoader and the second level keyed by class name.
|
||||
private static final int MAX_CLASS_CACHE_PER_LOADER_SIZE = 50;
|
||||
|
||||
private static final Cache<ClassLoader, Cache<String, Class<?>>> VALIDATED_CLASS_CACHE = Caffeine.newBuilder()
|
||||
.weakKeys()
|
||||
.maximumSize(MAX_CLASSLOADER_CACHE_SIZE)
|
||||
.build();
|
||||
|
||||
private ConfigParseUtil() {
|
||||
}
|
||||
@@ -73,7 +86,7 @@ public class ConfigParseUtil {
|
||||
Set<Class<?>> classes = new HashSet<>();
|
||||
for (String className : classNames) {
|
||||
try {
|
||||
classes.add(validatingClassLoader.loadClass(className));
|
||||
classes.add(loadAndCacheClass(validatingClassLoader, className));
|
||||
} catch (ClassNotFoundException e) {
|
||||
throw new ConfigurationException("Cannot load class for exclusion/exemption configuration: " + className, e);
|
||||
}
|
||||
@@ -81,6 +94,35 @@ public class ConfigParseUtil {
|
||||
return classes;
|
||||
}
|
||||
|
||||
private static Class<?> loadAndCacheClass(ClassLoader validatingClassLoader, String className) throws ClassNotFoundException {
|
||||
Cache<String, Class<?>> classLoaderCache = VALIDATED_CLASS_CACHE.get(validatingClassLoader,
|
||||
key -> Caffeine.newBuilder().weakValues().maximumSize(MAX_CLASS_CACHE_PER_LOADER_SIZE).build());
|
||||
|
||||
try {
|
||||
return classLoaderCache.get(className, key -> {
|
||||
try {
|
||||
return validatingClassLoader.loadClass(key);
|
||||
} catch (ClassNotFoundException e) {
|
||||
throw new ClassLookupException(e);
|
||||
}
|
||||
});
|
||||
} catch (ClassLookupException e) {
|
||||
// The ClassLookupException only serves to wrap the checked ClassNotFoundException thrown by ClassLoader.loadClass.
|
||||
throw (ClassNotFoundException) e.getCause();
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* This is a wrapper class to allow the checked ClassNotFoundException thrown by ClassLoader.loadClass to be propagated
|
||||
* We should always be able to unwrap this exception without risk of ClassCastException since the only code that can throw it is the mapping function passed to the cache
|
||||
* and it only ever throws this wrapper with a ClassNotFoundException cause.
|
||||
*/
|
||||
private static final class ClassLookupException extends RuntimeException {
|
||||
private ClassLookupException(ClassNotFoundException cause) {
|
||||
super(cause);
|
||||
}
|
||||
}
|
||||
|
||||
public static Set<String> toPackageNamesSet(String newDelimitedPackageNames) throws ConfigurationException {
|
||||
Set<String> packageNames = commaDelimitedStringToSet(newDelimitedPackageNames)
|
||||
.stream().map(s -> strip(s, ".")).collect(toSet());
|
||||
|
||||
@@ -33,6 +33,9 @@ import java.util.ResourceBundle;
|
||||
*/
|
||||
public class GlobalLocalizedTextProvider extends AbstractLocalizedTextProvider {
|
||||
|
||||
// Pinned to the value implicitly computed for the pre-6.11.0 class shape, see AbstractLocalizedTextProvider.
|
||||
private static final long serialVersionUID = 7569216885652454296L;
|
||||
|
||||
private static final Logger LOG = LogManager.getLogger(GlobalLocalizedTextProvider.class);
|
||||
|
||||
public GlobalLocalizedTextProvider() {
|
||||
|
||||
@@ -36,6 +36,9 @@ import java.util.ResourceBundle;
|
||||
*/
|
||||
public class StrutsLocalizedTextProvider extends AbstractLocalizedTextProvider {
|
||||
|
||||
// Pinned to the value implicitly computed for the pre-6.11.0 class shape, see AbstractLocalizedTextProvider.
|
||||
private static final long serialVersionUID = -4377984952850818176L;
|
||||
|
||||
private static final Logger LOG = LogManager.getLogger(StrutsLocalizedTextProvider.class);
|
||||
|
||||
/**
|
||||
|
||||
@@ -100,6 +100,14 @@ public final class StrutsConstants {
|
||||
/** The default locale for the Struts application */
|
||||
public static final String STRUTS_LOCALE = "struts.locale";
|
||||
|
||||
/**
|
||||
* When enabled, request-derived locales (from {@code Accept-Language}, used when {@code struts.locale} is
|
||||
* unset) are restricted to the JVM's available-locale set; unavailable values fall back to the default.
|
||||
*
|
||||
* @since 6.11.0
|
||||
*/
|
||||
public static final String STRUTS_LOCALE_VALIDATE_REQUEST = "struts.locale.validateRequestLocale";
|
||||
|
||||
/** Whether to use a Servlet request parameter workaround necessary for some versions of WebLogic */
|
||||
public static final String STRUTS_DISPATCHER_PARAMETERSWORKAROUND = "struts.dispatcher.parametersWorkaround";
|
||||
|
||||
@@ -288,6 +296,22 @@ public final class StrutsConstants {
|
||||
*/
|
||||
public static final String STRUTS_OGNL_BEANINFO_CACHE_FACTORY = "struts.ognl.beanInfoCacheFactory";
|
||||
|
||||
/**
|
||||
* Specifies the type of cache to use for the localized-text provider caches. Valid values defined in
|
||||
* {@link com.opensymphony.xwork2.ognl.OgnlCacheFactory.CacheType}.
|
||||
*
|
||||
* @since 6.11.0
|
||||
*/
|
||||
public static final String STRUTS_I18N_CACHE_TYPE = "struts.i18n.cacheType";
|
||||
|
||||
/**
|
||||
* Specifies the maximum size of each localized-text provider cache. Configure based on the cache type
|
||||
* chosen and application-specific needs.
|
||||
*
|
||||
* @since 6.11.0
|
||||
*/
|
||||
public static final String STRUTS_I18N_CACHE_MAXSIZE = "struts.i18n.cacheMaxSize";
|
||||
|
||||
/**
|
||||
* Specifies the type of cache to use for BeanInfo objects.
|
||||
* @since 6.4.0
|
||||
@@ -518,6 +542,13 @@ public final class StrutsConstants {
|
||||
public static final String STRUTS_CSP_NONCE_READER = "struts.csp.nonce.reader";
|
||||
public static final String STRUTS_CSP_NONCE_SOURCE = "struts.csp.nonce.source";
|
||||
|
||||
/**
|
||||
* See {@link org.apache.struts2.action.CspReportAction}
|
||||
*
|
||||
* @since 6.11.0
|
||||
*/
|
||||
public static final String STRUTS_CSP_REPORT_MAX_SIZE = "struts.csp.report.maxSize";
|
||||
|
||||
/**
|
||||
* Specifies the type of cache to use for proxy detection in ProxyUtil.
|
||||
* Valid values defined in {@link com.opensymphony.xwork2.ognl.OgnlCacheFactory.CacheType}.
|
||||
|
||||
@@ -19,11 +19,16 @@
|
||||
package org.apache.struts2.action;
|
||||
|
||||
import com.opensymphony.xwork2.ActionSupport;
|
||||
import com.opensymphony.xwork2.inject.Inject;
|
||||
import org.apache.commons.lang3.StringUtils;
|
||||
import org.apache.logging.log4j.LogManager;
|
||||
import org.apache.logging.log4j.Logger;
|
||||
import org.apache.struts2.StrutsConstants;
|
||||
|
||||
import javax.servlet.http.HttpServletRequest;
|
||||
import javax.servlet.http.HttpServletResponse;
|
||||
import java.io.BufferedReader;
|
||||
import java.io.IOException;
|
||||
import java.io.Reader;
|
||||
|
||||
import static org.apache.struts2.interceptor.csp.CspSettings.CSP_REPORT_TYPE;
|
||||
|
||||
@@ -51,7 +56,58 @@ import static org.apache.struts2.interceptor.csp.CspSettings.CSP_REPORT_TYPE;
|
||||
* @see DefaultCspReportAction
|
||||
*/
|
||||
public abstract class CspReportAction extends ActionSupport implements ServletRequestAware, ServletResponseAware {
|
||||
|
||||
private static final Logger LOG = LogManager.getLogger(CspReportAction.class);
|
||||
|
||||
/**
|
||||
* Default upper bound, in characters, on the report body accepted by {@link #withServletRequest}.
|
||||
* CSP violation reports are small JSON documents; anything larger is not treated as a report.
|
||||
*/
|
||||
public static final int DEFAULT_MAX_REPORT_SIZE = 8192;
|
||||
|
||||
/**
|
||||
* Largest value accepted for {@code struts.csp.report.maxSize}. A configured value above this is
|
||||
* ignored, so that a mistyped setting cannot size a per-request buffer large enough to exhaust
|
||||
* memory.
|
||||
*/
|
||||
private static final int MAX_REPORT_SIZE_LIMIT = 1024 * 1024;
|
||||
|
||||
private HttpServletRequest request;
|
||||
private int maxReportSize = DEFAULT_MAX_REPORT_SIZE;
|
||||
|
||||
/**
|
||||
* Sets the upper bound, in characters, on an accepted report body. A body exceeding this size is
|
||||
* discarded and not passed to {@link #processReport(String)}.
|
||||
* <p>
|
||||
* The value is injected from {@code struts.csp.report.maxSize} when the action is built, which is
|
||||
* before the interceptor stack runs. It is deliberately not an action property: the report body is
|
||||
* read by {@link #withServletRequest(HttpServletRequest)}, which the {@code servletConfig}
|
||||
* interceptor invokes ahead of {@code staticParams} and {@code params}, so a value applied by
|
||||
* either of those would arrive too late to have any effect.
|
||||
*
|
||||
* @param maxReportSize maximum accepted report size in characters
|
||||
* @since 6.11.0
|
||||
*/
|
||||
@Inject(value = StrutsConstants.STRUTS_CSP_REPORT_MAX_SIZE, required = false)
|
||||
public void setMaxReportSize(String maxReportSize) {
|
||||
if (StringUtils.isBlank(maxReportSize)) {
|
||||
return;
|
||||
}
|
||||
int size;
|
||||
try {
|
||||
size = Integer.parseInt(maxReportSize.trim());
|
||||
} catch (NumberFormatException e) {
|
||||
LOG.warn("Ignoring non-numeric {} value: {}, keeping {}",
|
||||
StrutsConstants.STRUTS_CSP_REPORT_MAX_SIZE, maxReportSize, this.maxReportSize);
|
||||
return;
|
||||
}
|
||||
if (size < 1 || size > MAX_REPORT_SIZE_LIMIT) {
|
||||
LOG.warn("Ignoring out-of-range {} value: {}, expected 1..{}, keeping {}",
|
||||
StrutsConstants.STRUTS_CSP_REPORT_MAX_SIZE, size, MAX_REPORT_SIZE_LIMIT, this.maxReportSize);
|
||||
return;
|
||||
}
|
||||
this.maxReportSize = size;
|
||||
}
|
||||
|
||||
@Override
|
||||
public void withServletRequest(HttpServletRequest request) {
|
||||
@@ -60,13 +116,36 @@ public abstract class CspReportAction extends ActionSupport implements ServletRe
|
||||
}
|
||||
|
||||
try {
|
||||
BufferedReader reader = request.getReader();
|
||||
String cspReport = reader.readLine();
|
||||
String cspReport = readReport(request.getReader());
|
||||
if (cspReport == null) {
|
||||
LOG.warn("Discarding CSP report larger than the configured limit of {} characters", maxReportSize);
|
||||
return;
|
||||
}
|
||||
processReport(cspReport);
|
||||
} catch (IOException ignored) {
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Reads at most {@link #maxReportSize} characters from the report body.
|
||||
*
|
||||
* @param reader reader over the report body
|
||||
* @return the report body, or {@code null} if it exceeds the limit
|
||||
* @throws IOException if the body cannot be read
|
||||
*/
|
||||
private String readReport(Reader reader) throws IOException {
|
||||
char[] buffer = new char[maxReportSize];
|
||||
int total = 0;
|
||||
int read;
|
||||
while (total < buffer.length && (read = reader.read(buffer, total, buffer.length - total)) != -1) {
|
||||
total += read;
|
||||
}
|
||||
if (total == buffer.length && reader.read() != -1) {
|
||||
return null;
|
||||
}
|
||||
return new String(buffer, 0, total);
|
||||
}
|
||||
|
||||
private boolean isCspReportRequest(HttpServletRequest request) {
|
||||
if (!"POST".equals(request.getMethod()) || request.getContentLength() <= 0){
|
||||
return false;
|
||||
|
||||
@@ -152,6 +152,11 @@ public class Dispatcher {
|
||||
*/
|
||||
private String defaultLocale;
|
||||
|
||||
/**
|
||||
* Store state of {@link StrutsConstants#STRUTS_LOCALE_VALIDATE_REQUEST} setting.
|
||||
*/
|
||||
private boolean validateRequestLocale = false;
|
||||
|
||||
/**
|
||||
* Store state of StrutsConstants.STRUTS_MULTIPART_SAVEDIR setting.
|
||||
*/
|
||||
@@ -311,6 +316,18 @@ public class Dispatcher {
|
||||
defaultLocale = val;
|
||||
}
|
||||
|
||||
/**
|
||||
* Modify state of {@link StrutsConstants#STRUTS_LOCALE_VALIDATE_REQUEST} setting.
|
||||
*
|
||||
* @param val New setting
|
||||
*
|
||||
* @since 6.11.0
|
||||
*/
|
||||
@Inject(value = StrutsConstants.STRUTS_LOCALE_VALIDATE_REQUEST, required = false)
|
||||
public void setValidateRequestLocale(String val) {
|
||||
validateRequestLocale = Boolean.parseBoolean(val);
|
||||
}
|
||||
|
||||
/**
|
||||
* Modify state of StrutsConstants.STRUTS_I18N_ENCODING setting.
|
||||
*
|
||||
@@ -950,7 +967,7 @@ public class Dispatcher {
|
||||
locale = LocaleUtils.toLocale(defaultLocale);
|
||||
} catch (IllegalArgumentException e) {
|
||||
try {
|
||||
locale = request.getLocale();
|
||||
locale = resolveRequestLocale(request);
|
||||
LOG.warn(new ParameterizedMessage("Cannot convert 'struts.locale' = [{}] to proper locale, defaulting to request locale [{}]",
|
||||
defaultLocale, locale), e);
|
||||
} catch (RuntimeException rex) {
|
||||
@@ -961,7 +978,7 @@ public class Dispatcher {
|
||||
}
|
||||
} else {
|
||||
try {
|
||||
locale = request.getLocale();
|
||||
locale = resolveRequestLocale(request);
|
||||
} catch (RuntimeException rex) {
|
||||
LOG.warn("Cannot get locale from HTTP Request, falling back to system default locale", rex);
|
||||
locale = Locale.getDefault();
|
||||
@@ -970,6 +987,33 @@ public class Dispatcher {
|
||||
return locale;
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolves the request locale. When {@code struts.locale.validateRequestLocale} is enabled and the
|
||||
* request locale is not part of the JVM's available-locale set, falls back to the configured
|
||||
* {@code struts.locale} when set and parseable, otherwise the JVM default. When disabled (default),
|
||||
* returns the request locale unchanged.
|
||||
*
|
||||
* @param request the current request
|
||||
* @return the locale to use for this request
|
||||
*
|
||||
* @since 6.11.0
|
||||
*/
|
||||
protected Locale resolveRequestLocale(HttpServletRequest request) {
|
||||
Locale locale = request.getLocale();
|
||||
if (!validateRequestLocale || LocaleUtils.isAvailableLocale(locale)) {
|
||||
return locale;
|
||||
}
|
||||
if (defaultLocale != null) {
|
||||
try {
|
||||
return LocaleUtils.toLocale(defaultLocale);
|
||||
} catch (IllegalArgumentException e) {
|
||||
LOG.debug("Configured 'struts.locale' = [{}] is not parseable; falling back to system default", defaultLocale);
|
||||
}
|
||||
}
|
||||
LOG.debug("Request locale [{}] is not available; falling back to system default locale", locale);
|
||||
return Locale.getDefault();
|
||||
}
|
||||
|
||||
/**
|
||||
* Return the path to save uploaded files to (this is configurable).
|
||||
*
|
||||
|
||||
+2
-1
@@ -90,7 +90,8 @@ public class HttpMethodInterceptor extends AbstractInterceptor {
|
||||
invocation.getProxy().getMethod(), AllowedHttpMethod.class.getSimpleName(), request.getMethod());
|
||||
return doIntercept(invocation, method);
|
||||
}
|
||||
} else if (AnnotationUtils.isAnnotatedBy(action.getClass(), HTTP_METHOD_ANNOTATIONS)) {
|
||||
}
|
||||
if (AnnotationUtils.isAnnotatedBy(action.getClass(), HTTP_METHOD_ANNOTATIONS)) {
|
||||
LOG.debug("Action: {} annotated with: {}, checking if request: {} meets allowed methods!",
|
||||
action, AllowedHttpMethod.class.getSimpleName(), request.getMethod());
|
||||
return doIntercept(invocation, action.getClass());
|
||||
|
||||
@@ -21,6 +21,7 @@ package org.apache.struts2.result;
|
||||
import com.opensymphony.xwork2.ActionContext;
|
||||
import com.opensymphony.xwork2.ActionInvocation;
|
||||
import com.opensymphony.xwork2.inject.Inject;
|
||||
import org.apache.commons.text.StringEscapeUtils;
|
||||
import org.apache.struts2.dispatcher.mapper.ActionMapper;
|
||||
import org.apache.struts2.dispatcher.mapper.ActionMapping;
|
||||
|
||||
@@ -101,7 +102,7 @@ public class PostbackResult extends StrutsResultSupport {
|
||||
|
||||
// Render
|
||||
PrintWriter pw = new PrintWriter(response.getOutputStream());
|
||||
pw.write("<!DOCTYPE html><html><body><form action=\"" + finalLocation + "\" method=\"POST\">");
|
||||
pw.write("<!DOCTYPE html><html><body><form action=\"" + StringEscapeUtils.escapeHtml4(finalLocation) + "\" method=\"POST\">");
|
||||
writeFormElements(request, pw);
|
||||
writePrologueScript(pw);
|
||||
pw.write("</html>");
|
||||
|
||||
@@ -24,6 +24,9 @@
|
||||
|
||||
### This can be used to set your default locale and encoding scheme
|
||||
# struts.locale=en_US
|
||||
### When true, restrict request-derived locales (Accept-Language, used when struts.locale is unset) to the
|
||||
### JVM's available-locale set; unavailable values fall back to the default locale. Defaults to false.
|
||||
struts.locale.validateRequestLocale=false
|
||||
struts.i18n.encoding=UTF-8
|
||||
|
||||
### if specified, the default object factory can be overridden here
|
||||
@@ -240,6 +243,13 @@ struts.ognl.expressionCacheType=wtlfu
|
||||
### chosen and application-specific needs.
|
||||
struts.ognl.expressionCacheMaxSize=10000
|
||||
|
||||
### Specifies the type of cache to use for the localized-text provider caches. See StrutsConstants for details.
|
||||
struts.i18n.cacheType=wtlfu
|
||||
|
||||
### Specifies the maximum size of each localized-text provider cache. This should be configured based on the
|
||||
### cache type chosen and application-specific needs.
|
||||
struts.i18n.cacheMaxSize=10000
|
||||
|
||||
### Specifies the type of cache to use for BeanInfo objects. See StrutsConstants class for further information.
|
||||
struts.ognl.beanInfoCacheType=wtlfu
|
||||
|
||||
@@ -290,4 +300,8 @@ struts.url.decoder=strutsUrlDecoder
|
||||
### Defines source to read nonce value from, possible values are: request, session
|
||||
struts.csp.nonceSource=session
|
||||
|
||||
### Maximum size, in characters, of a CSP violation report accepted by CspReportAction
|
||||
### Reports larger than this are discarded. Values outside 1..1048576 are ignored.
|
||||
struts.csp.report.maxSize=8192
|
||||
|
||||
### END SNIPPET: complete_file
|
||||
|
||||
@@ -0,0 +1,50 @@
|
||||
/*
|
||||
* Licensed to the Apache Software Foundation (ASF) under one
|
||||
* or more contributor license agreements. See the NOTICE file
|
||||
* distributed with this work for additional information
|
||||
* regarding copyright ownership. The ASF licenses this file
|
||||
* to you under the Apache License, Version 2.0 (the
|
||||
* "License"); you may not use this file except in compliance
|
||||
* with the License. You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing,
|
||||
* software distributed under the License is distributed on an
|
||||
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||
* KIND, either express or implied. See the License for the
|
||||
* specific language governing permissions and limitations
|
||||
* under the License.
|
||||
*/
|
||||
package com.opensymphony.xwork2.ognl;
|
||||
|
||||
import org.junit.Test;
|
||||
|
||||
import static org.junit.Assert.assertEquals;
|
||||
import static org.junit.Assert.assertNull;
|
||||
|
||||
public class OgnlCacheRemoveTest {
|
||||
|
||||
private void assertRemoveContract(OgnlCache<String, String> cache) {
|
||||
cache.put("k", "v");
|
||||
assertEquals("v", cache.get("k"));
|
||||
assertEquals("remove returns previous value", "v", cache.remove("k"));
|
||||
assertNull("entry gone after remove", cache.get("k"));
|
||||
assertNull("remove of absent key returns null", cache.remove("absent"));
|
||||
}
|
||||
|
||||
@Test
|
||||
public void caffeineCacheRemove() {
|
||||
assertRemoveContract(new OgnlCaffeineCache<>(10, 16));
|
||||
}
|
||||
|
||||
@Test
|
||||
public void defaultCacheRemove() {
|
||||
assertRemoveContract(new OgnlDefaultCache<>(10, 16, 0.75f));
|
||||
}
|
||||
|
||||
@Test
|
||||
public void lruCacheRemove() {
|
||||
assertRemoveContract(new OgnlLRUCache<>(10, 16, 0.75f));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
/*
|
||||
* Licensed to the Apache Software Foundation (ASF) under one
|
||||
* or more contributor license agreements. See the NOTICE file
|
||||
* distributed with this work for additional information
|
||||
* regarding copyright ownership. The ASF licenses this file
|
||||
* to you under the Apache License, Version 2.0 (the
|
||||
* "License"); you may not use this file except in compliance
|
||||
* with the License. You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing,
|
||||
* software distributed under the License is distributed on an
|
||||
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||
* KIND, either express or implied. See the License for the
|
||||
* specific language governing permissions and limitations
|
||||
* under the License.
|
||||
*/
|
||||
package com.opensymphony.xwork2.util;
|
||||
|
||||
/**
|
||||
* Simple fixture whose class-associated bundle ({@code CacheFixture.properties}) backs the
|
||||
* localized-text caching tests.
|
||||
*
|
||||
* @since 6.11.0
|
||||
*/
|
||||
public class CacheFixture {
|
||||
}
|
||||
@@ -0,0 +1,255 @@
|
||||
/*
|
||||
* Licensed to the Apache Software Foundation (ASF) under one
|
||||
* or more contributor license agreements. See the NOTICE file
|
||||
* distributed with this work for additional information
|
||||
* regarding copyright ownership. The ASF licenses this file
|
||||
* to you under the Apache License, Version 2.0 (the
|
||||
* "License"); you may not use this file except in compliance
|
||||
* with the License. You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing,
|
||||
* software distributed under the License is distributed on an
|
||||
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||
* KIND, either express or implied. See the License for the
|
||||
* specific language governing permissions and limitations
|
||||
* under the License.
|
||||
*/
|
||||
package com.opensymphony.xwork2.util;
|
||||
|
||||
import com.github.benmanes.caffeine.cache.Cache;
|
||||
import com.opensymphony.xwork2.config.ConfigurationException;
|
||||
import org.junit.After;
|
||||
import org.junit.Before;
|
||||
import org.junit.Test;
|
||||
|
||||
import java.lang.reflect.Field;
|
||||
import java.util.Collections;
|
||||
import java.util.HashMap;
|
||||
import java.util.HashSet;
|
||||
import java.util.LinkedHashSet;
|
||||
import java.util.Map;
|
||||
import java.util.Set;
|
||||
|
||||
import static org.junit.Assert.assertEquals;
|
||||
import static org.junit.Assert.assertNotNull;
|
||||
import static org.junit.Assert.assertTrue;
|
||||
import static org.junit.Assert.fail;
|
||||
|
||||
public class ConfigParseUtilTest {
|
||||
|
||||
@Before
|
||||
public void setUp() {
|
||||
validatedClassCache().invalidateAll();
|
||||
}
|
||||
|
||||
@After
|
||||
public void tearDown() {
|
||||
validatedClassCache().invalidateAll();
|
||||
}
|
||||
|
||||
/**
|
||||
* (a) Single-loader caching: one loader validates several distinct classes; repeating the call
|
||||
* loads each class exactly once. Covers both "repeated calls hit the cache" and "the inner cache
|
||||
* is keyed per class name".
|
||||
*/
|
||||
@Test
|
||||
public void testSameLoaderCachesEachDistinctClassOnce() {
|
||||
CountingClassLoader loader = new CountingClassLoader(getClass().getClassLoader(), "single-loader");
|
||||
Set<String> classNames = new HashSet<>();
|
||||
classNames.add(String.class.getName());
|
||||
classNames.add(Integer.class.getName());
|
||||
classNames.add(Boolean.class.getName());
|
||||
|
||||
ConfigParseUtil.validateClasses(classNames, loader);
|
||||
ConfigParseUtil.validateClasses(classNames, loader);
|
||||
|
||||
assertEquals(1, loader.getLoadCount(String.class.getName()));
|
||||
assertEquals(1, loader.getLoadCount(Integer.class.getName()));
|
||||
assertEquals(1, loader.getLoadCount(Boolean.class.getName()));
|
||||
}
|
||||
|
||||
/**
|
||||
* (b) Per-loader isolation: the outer cache is keyed by classloader identity, not by toString().
|
||||
* Two loaders that share the same toString() each load the class once, and re-validating one
|
||||
* loader still hits its own cache.
|
||||
*/
|
||||
@Test
|
||||
public void testDifferentLoadersWithSameNameCacheIndependently() {
|
||||
CountingClassLoader firstLoader = new CountingClassLoader(getClass().getClassLoader(), "same-name");
|
||||
CountingClassLoader secondLoader = new CountingClassLoader(getClass().getClassLoader(), "same-name");
|
||||
Set<String> classNames = Collections.singleton(String.class.getName());
|
||||
|
||||
ConfigParseUtil.validateClasses(classNames, firstLoader);
|
||||
ConfigParseUtil.validateClasses(classNames, secondLoader);
|
||||
|
||||
assertEquals(1, firstLoader.getStringClassLoads());
|
||||
assertEquals(1, secondLoader.getStringClassLoads());
|
||||
|
||||
// Re-validating the first loader still hits its own cache.
|
||||
ConfigParseUtil.validateClasses(classNames, firstLoader);
|
||||
assertEquals(1, firstLoader.getStringClassLoads());
|
||||
}
|
||||
|
||||
/**
|
||||
* Negative case: a missing class throws ConfigurationException (cause ClassNotFoundException) on
|
||||
* every call, and the failure is not cached (each call re-attempts the load).
|
||||
*/
|
||||
@Test
|
||||
public void testMissingClassThrowsAndIsNotCached() {
|
||||
String missingClassName = "com.opensymphony.xwork2.util.NonExistingClassForValidationTest";
|
||||
Set<String> classNames = Collections.singleton(missingClassName);
|
||||
int[] missingClassLoads = new int[1];
|
||||
ClassLoader loader = new ClassLoader(getClass().getClassLoader()) {
|
||||
@Override
|
||||
public Class<?> loadClass(String name) throws ClassNotFoundException {
|
||||
if (missingClassName.equals(name)) {
|
||||
missingClassLoads[0]++;
|
||||
throw new ClassNotFoundException(name);
|
||||
}
|
||||
return super.loadClass(name);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return "missing-class-loader";
|
||||
}
|
||||
};
|
||||
|
||||
for (int i = 0; i < 2; i++) {
|
||||
try {
|
||||
ConfigParseUtil.validateClasses(classNames, loader);
|
||||
fail("Expected ConfigurationException for class: " + missingClassName);
|
||||
} catch (ConfigurationException e) {
|
||||
assertTrue(e.getMessage().contains(missingClassName));
|
||||
assertNotNull(e.getCause());
|
||||
assertEquals(ClassNotFoundException.class, e.getCause().getClass());
|
||||
}
|
||||
}
|
||||
|
||||
assertEquals(2, missingClassLoads[0]);
|
||||
}
|
||||
|
||||
/**
|
||||
* (c) Outer cache bound: registering more classloaders than the maximum keeps the outer cache at
|
||||
* or below its configured size.
|
||||
*/
|
||||
@Test
|
||||
public void testOuterCacheBoundedByMaxClassloaders() {
|
||||
Set<String> classNames = Collections.singleton(String.class.getName());
|
||||
|
||||
for (int i = 0; i < outerCacheLimit() + 10; i++) {
|
||||
CountingClassLoader loader = new CountingClassLoader(getClass().getClassLoader(), "loader-" + i);
|
||||
ConfigParseUtil.validateClasses(classNames, loader);
|
||||
}
|
||||
|
||||
Cache<Object, Object> cache = validatedClassCache();
|
||||
cache.cleanUp();
|
||||
|
||||
assertTrue("Outer cache size should not exceed configured maximum",
|
||||
cache.estimatedSize() <= outerCacheLimit());
|
||||
}
|
||||
|
||||
/**
|
||||
* (c) Inner cache bound: validating more class names than the per-loader maximum keeps that
|
||||
* loader's inner cache at or below its configured size. Synthetic names are resolved to a real
|
||||
* class so the count is driven by distinct keys, not by which JDK classes happen to exist.
|
||||
*/
|
||||
@Test
|
||||
public void testInnerCacheBoundedByMaxClassesPerLoader() {
|
||||
int limit = innerCacheLimit();
|
||||
ClassLoader loader = new ClassLoader(getClass().getClassLoader()) {
|
||||
@Override
|
||||
public Class<?> loadClass(String name) {
|
||||
// Resolve any synthetic name to a strongly-reachable class so weakValues never evicts it.
|
||||
return Object.class;
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return "inner-bound-loader";
|
||||
}
|
||||
};
|
||||
|
||||
Set<String> classNames = new LinkedHashSet<>();
|
||||
for (int i = 0; i <= limit + 10; i++) {
|
||||
classNames.add("synthetic.Class" + i);
|
||||
}
|
||||
assertTrue("Test must request more class names than the inner cache capacity",
|
||||
classNames.size() > limit);
|
||||
|
||||
ConfigParseUtil.validateClasses(classNames, loader);
|
||||
|
||||
Cache<Object, Object> innerCache = innerCacheFor(loader);
|
||||
innerCache.cleanUp();
|
||||
assertTrue("Inner cache size should not exceed configured maximum per loader",
|
||||
innerCache.estimatedSize() <= limit);
|
||||
}
|
||||
|
||||
@SuppressWarnings("unchecked")
|
||||
private static Cache<Object, Object> validatedClassCache() {
|
||||
try {
|
||||
Field cacheField = ConfigParseUtil.class.getDeclaredField("VALIDATED_CLASS_CACHE");
|
||||
cacheField.setAccessible(true);
|
||||
return (Cache<Object, Object>) cacheField.get(null);
|
||||
} catch (NoSuchFieldException | IllegalAccessException e) {
|
||||
throw new AssertionError("Cannot access ConfigParseUtil cache field", e);
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("unchecked")
|
||||
private static Cache<Object, Object> innerCacheFor(ClassLoader loader) {
|
||||
Cache<Object, Object> outer = validatedClassCache();
|
||||
Object inner = outer.getIfPresent(loader);
|
||||
assertNotNull("Expected an inner cache entry for loader", inner);
|
||||
return (Cache<Object, Object>) inner;
|
||||
}
|
||||
|
||||
private static int outerCacheLimit() {
|
||||
return intConstant("MAX_CLASSLOADER_CACHE_SIZE");
|
||||
}
|
||||
|
||||
private static int innerCacheLimit() {
|
||||
return intConstant("MAX_CLASS_CACHE_PER_LOADER_SIZE");
|
||||
}
|
||||
|
||||
private static int intConstant(String fieldName) {
|
||||
try {
|
||||
Field field = ConfigParseUtil.class.getDeclaredField(fieldName);
|
||||
field.setAccessible(true);
|
||||
return field.getInt(null);
|
||||
} catch (NoSuchFieldException | IllegalAccessException e) {
|
||||
throw new AssertionError("Cannot access ConfigParseUtil constant: " + fieldName, e);
|
||||
}
|
||||
}
|
||||
|
||||
private static final class CountingClassLoader extends ClassLoader {
|
||||
private final String loaderName;
|
||||
private final Map<String, Integer> loadCounts = new HashMap<>();
|
||||
|
||||
private CountingClassLoader(ClassLoader parent, String loaderName) {
|
||||
super(parent);
|
||||
this.loaderName = loaderName;
|
||||
}
|
||||
|
||||
@Override
|
||||
public Class<?> loadClass(String name) throws ClassNotFoundException {
|
||||
loadCounts.merge(name, 1, Integer::sum);
|
||||
return super.loadClass(name);
|
||||
}
|
||||
|
||||
private int getStringClassLoads() {
|
||||
return loadCounts.getOrDefault(String.class.getName(), 0);
|
||||
}
|
||||
|
||||
private int getLoadCount(String className) {
|
||||
return loadCounts.getOrDefault(className, 0);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return loaderName;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -34,6 +34,11 @@ import com.opensymphony.xwork2.test.TestBean2;
|
||||
import org.apache.struts2.config.StrutsXmlConfigurationProvider;
|
||||
import org.apache.struts2.interceptor.parameter.StrutsParameter;
|
||||
|
||||
import java.io.ByteArrayInputStream;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.ObjectInputStream;
|
||||
import java.io.ObjectOutputStream;
|
||||
import java.lang.reflect.Field;
|
||||
import java.text.DateFormat;
|
||||
import java.text.ParseException;
|
||||
import java.util.Date;
|
||||
@@ -563,6 +568,109 @@ public class StrutsLocalizedTextProviderTest extends XWorkTestCase {
|
||||
assertEquals("Result of bean2.name lookup not as expected ?", "Okay! You found Me!", messageResult);
|
||||
}
|
||||
|
||||
public void testCachesAreBoundedByConfiguredMaxSize() {
|
||||
TestStrutsLocalizedTextProvider provider = new TestStrutsLocalizedTextProvider();
|
||||
provider.setI18nCacheMaxSize("100");
|
||||
ValueStack valueStack = ActionContext.getContext().getValueStack();
|
||||
|
||||
for (int i = 0; i < 20000; i++) {
|
||||
Locale locale = Locale.forLanguageTag("en-US-x" + String.format("%05d", i));
|
||||
provider.findText(CacheFixture.class, "cache.missing", locale, "Fallback", null, valueStack);
|
||||
}
|
||||
|
||||
assertTrue("bundlesMap not bounded ?", provider.bundlesMapSize() <= 2000);
|
||||
assertTrue("missingBundles not bounded ?", provider.missingBundlesSize() <= 2000);
|
||||
assertTrue("messageFormats not bounded ?", provider.messageFormatsSize() <= 2000);
|
||||
}
|
||||
|
||||
public void testCorrectTextStillReturnedUnderEviction() {
|
||||
TestStrutsLocalizedTextProvider provider = new TestStrutsLocalizedTextProvider();
|
||||
provider.setI18nCacheMaxSize("50");
|
||||
ValueStack valueStack = ActionContext.getContext().getValueStack();
|
||||
|
||||
// Force heavy eviction with many distinct locales.
|
||||
for (int i = 0; i < 5000; i++) {
|
||||
Locale locale = Locale.forLanguageTag("en-US-x" + String.format("%05d", i));
|
||||
provider.findText(CacheFixture.class, "cache.missing", locale, "Fallback", null, valueStack);
|
||||
}
|
||||
|
||||
// A real key in a real locale still resolves correctly after eviction pressure.
|
||||
String result = provider.findText(CacheFixture.class, "cache.static", Locale.ENGLISH, null, null, valueStack);
|
||||
assertEquals("Static cached value", result);
|
||||
}
|
||||
|
||||
public void testReloadClearsBoundedCaches() {
|
||||
TestStrutsLocalizedTextProvider provider = new TestStrutsLocalizedTextProvider();
|
||||
ValueStack valueStack = ActionContext.getContext().getValueStack();
|
||||
|
||||
provider.findText(CacheFixture.class, "cache.missing", Locale.ENGLISH, "Fallback", null, valueStack);
|
||||
assertTrue("missingBundles not populated ?", provider.missingBundlesSize() > 0);
|
||||
|
||||
provider.callReloadBundlesForceReload();
|
||||
assertEquals("reload did not clear bundlesMap ?", 0, provider.bundlesMapSize());
|
||||
}
|
||||
|
||||
public void testProviderIsUsableAfterDeserialization() throws Exception {
|
||||
StrutsLocalizedTextProvider provider = new StrutsLocalizedTextProvider();
|
||||
ValueStack valueStack = ActionContext.getContext().getValueStack();
|
||||
provider.findText(CacheFixture.class, "cache.static", Locale.ENGLISH, null, null, valueStack);
|
||||
|
||||
ByteArrayOutputStream baos = new ByteArrayOutputStream();
|
||||
try (ObjectOutputStream oos = new ObjectOutputStream(baos)) {
|
||||
oos.writeObject(provider);
|
||||
}
|
||||
Object restored;
|
||||
try (ObjectInputStream ois = new ObjectInputStream(new ByteArrayInputStream(baos.toByteArray()))) {
|
||||
restored = ois.readObject();
|
||||
}
|
||||
StrutsLocalizedTextProvider deserialized = (StrutsLocalizedTextProvider) restored;
|
||||
// Caches were transient (null right after defaultReadObject) but readObject rebuilds them:
|
||||
assertEquals("Deserialized caches not rebuilt empty", 0, deserialized.bundlesMapSize());
|
||||
String result = deserialized.findText(CacheFixture.class, "cache.static", Locale.ENGLISH, null, null, valueStack);
|
||||
assertEquals("Static cached value", result);
|
||||
}
|
||||
|
||||
/**
|
||||
* A stream written before the i18n cache settings existed carries no value for them, and field
|
||||
* initialisers do not run during deserialization, so they arrive as null/0. The provider must still
|
||||
* come back usable rather than failing while rebuilding its caches.
|
||||
*/
|
||||
public void testProviderIsUsableAfterDeserializingLegacyStream() throws Exception {
|
||||
StrutsLocalizedTextProvider provider = new StrutsLocalizedTextProvider();
|
||||
ValueStack valueStack = ActionContext.getContext().getValueStack();
|
||||
provider.findText(CacheFixture.class, "cache.static", Locale.ENGLISH, null, null, valueStack);
|
||||
|
||||
// Simulate the absent-field state an older stream produces.
|
||||
Field cacheType = AbstractLocalizedTextProvider.class.getDeclaredField("i18nCacheType");
|
||||
cacheType.setAccessible(true);
|
||||
cacheType.set(provider, null);
|
||||
Field maxSize = AbstractLocalizedTextProvider.class.getDeclaredField("i18nCacheMaxSize");
|
||||
maxSize.setAccessible(true);
|
||||
maxSize.setInt(provider, 0);
|
||||
|
||||
ByteArrayOutputStream baos = new ByteArrayOutputStream();
|
||||
try (ObjectOutputStream oos = new ObjectOutputStream(baos)) {
|
||||
oos.writeObject(provider);
|
||||
}
|
||||
Object restored;
|
||||
try (ObjectInputStream ois = new ObjectInputStream(new ByteArrayInputStream(baos.toByteArray()))) {
|
||||
restored = ois.readObject();
|
||||
}
|
||||
|
||||
StrutsLocalizedTextProvider deserialized = (StrutsLocalizedTextProvider) restored;
|
||||
String result = deserialized.findText(CacheFixture.class, "cache.static", Locale.ENGLISH, null, null, valueStack);
|
||||
assertEquals("Static cached value", result);
|
||||
}
|
||||
|
||||
public void testCacheTypeSelectionKeepsProviderWorking() {
|
||||
TestStrutsLocalizedTextProvider provider = new TestStrutsLocalizedTextProvider();
|
||||
provider.setI18nCacheType("basic");
|
||||
ValueStack valueStack = ActionContext.getContext().getValueStack();
|
||||
String result = provider.findText(CacheFixture.class, "cache.static", Locale.ENGLISH, null, null, valueStack);
|
||||
assertEquals("Static cached value", result);
|
||||
assertTrue("bundlesMap should populate", provider.bundlesMapSize() >= 1);
|
||||
}
|
||||
|
||||
@Override
|
||||
protected void setUp() throws Exception {
|
||||
super.setUp();
|
||||
|
||||
@@ -0,0 +1,185 @@
|
||||
/*
|
||||
* Licensed to the Apache Software Foundation (ASF) under one
|
||||
* or more contributor license agreements. See the NOTICE file
|
||||
* distributed with this work for additional information
|
||||
* regarding copyright ownership. The ASF licenses this file
|
||||
* to you under the Apache License, Version 2.0 (the
|
||||
* "License"); you may not use this file except in compliance
|
||||
* with the License. You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing,
|
||||
* software distributed under the License is distributed on an
|
||||
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||
* KIND, either express or implied. See the License for the
|
||||
* specific language governing permissions and limitations
|
||||
* under the License.
|
||||
*/
|
||||
package org.apache.struts2.action;
|
||||
|
||||
import com.opensymphony.xwork2.XWorkTestCase;
|
||||
import org.apache.struts2.StrutsConstants;
|
||||
import org.apache.struts2.interceptor.csp.CspSettings;
|
||||
import org.springframework.mock.web.MockHttpServletRequest;
|
||||
|
||||
import java.io.BufferedReader;
|
||||
import java.io.IOException;
|
||||
import java.io.InputStream;
|
||||
import java.io.Reader;
|
||||
import java.util.Properties;
|
||||
import java.util.concurrent.atomic.AtomicLong;
|
||||
|
||||
/**
|
||||
* Verifies that {@link CspReportAction} applies an upper bound to the report body it accepts, and
|
||||
* that the bound is configurable.
|
||||
*/
|
||||
public class CspReportActionReportSizeTest extends XWorkTestCase {
|
||||
|
||||
/**
|
||||
* The reader supplied by the container buffers ahead, so consumption is bounded by the limit
|
||||
* plus one buffer rather than by the limit exactly. That overshoot is fixed, not proportional
|
||||
* to the size of the body.
|
||||
*/
|
||||
private static final long READ_AHEAD_ALLOWANCE = 8192L;
|
||||
|
||||
/**
|
||||
* Produces {@code total} characters without buffering them, and records how many the caller
|
||||
* actually consumed.
|
||||
*/
|
||||
private static final class CountingReader extends Reader {
|
||||
private final long total;
|
||||
private final AtomicLong consumed;
|
||||
private long produced = 0;
|
||||
|
||||
CountingReader(long total, AtomicLong consumed) {
|
||||
this.total = total;
|
||||
this.consumed = consumed;
|
||||
}
|
||||
|
||||
@Override
|
||||
public int read(char[] cbuf, int off, int len) {
|
||||
if (produced >= total) {
|
||||
return -1;
|
||||
}
|
||||
int count = (int) Math.min(len, total - produced);
|
||||
for (int i = 0; i < count; i++) {
|
||||
cbuf[off + i] = 'a';
|
||||
}
|
||||
produced += count;
|
||||
consumed.addAndGet(count);
|
||||
return count;
|
||||
}
|
||||
|
||||
@Override
|
||||
public void close() {
|
||||
// characters are generated on demand, so there is nothing to release
|
||||
}
|
||||
}
|
||||
|
||||
private static final class CapturingCspReportAction extends CspReportAction {
|
||||
String captured;
|
||||
int reports;
|
||||
|
||||
@Override
|
||||
void processReport(String jsonCspReport) {
|
||||
captured = jsonCspReport;
|
||||
reports++;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* A request that both declares and delivers {@code size} characters, matching what a client can
|
||||
* actually send: the declared length and the delivered body agree.
|
||||
*/
|
||||
private MockHttpServletRequest requestOfSize(final long size, final AtomicLong consumed) {
|
||||
MockHttpServletRequest request = new MockHttpServletRequest("POST", "/csp-reports") {
|
||||
@Override
|
||||
public int getContentLength() {
|
||||
return (int) Math.min(size, Integer.MAX_VALUE);
|
||||
}
|
||||
|
||||
@Override
|
||||
public BufferedReader getReader() {
|
||||
return new BufferedReader(new CountingReader(size, consumed));
|
||||
}
|
||||
};
|
||||
request.setContentType(CspSettings.CSP_REPORT_TYPE);
|
||||
return request;
|
||||
}
|
||||
|
||||
public void testReportAboveLimitIsNotProcessed() {
|
||||
AtomicLong consumed = new AtomicLong();
|
||||
MockHttpServletRequest request = requestOfSize(64L * 1024 * 1024, consumed);
|
||||
|
||||
CapturingCspReportAction action = new CapturingCspReportAction();
|
||||
action.withServletRequest(request);
|
||||
|
||||
assertEquals("A report above the limit should not be processed", 0, action.reports);
|
||||
assertTrue("Consumed " + consumed.get() + " characters for a limit of "
|
||||
+ CspReportAction.DEFAULT_MAX_REPORT_SIZE,
|
||||
consumed.get() <= CspReportAction.DEFAULT_MAX_REPORT_SIZE + READ_AHEAD_ALLOWANCE);
|
||||
}
|
||||
|
||||
public void testReportWithinLimitIsProcessed() {
|
||||
String sampleReport = "{\"csp-report\":{\"document-uri\":\"https://example.test/\"}}";
|
||||
MockHttpServletRequest request = new MockHttpServletRequest("POST", "/csp-reports");
|
||||
request.setContent(sampleReport.getBytes());
|
||||
request.setContentType(CspSettings.CSP_REPORT_TYPE);
|
||||
|
||||
CapturingCspReportAction action = new CapturingCspReportAction();
|
||||
action.withServletRequest(request);
|
||||
|
||||
assertEquals("A report within the limit should be processed", 1, action.reports);
|
||||
assertEquals("The report should be passed through unchanged", sampleReport, action.captured);
|
||||
}
|
||||
|
||||
public void testConfiguredLimitIsApplied() {
|
||||
AtomicLong consumed = new AtomicLong();
|
||||
MockHttpServletRequest request = requestOfSize(4096, consumed);
|
||||
|
||||
CapturingCspReportAction action = new CapturingCspReportAction();
|
||||
action.setMaxReportSize("1024");
|
||||
action.withServletRequest(request);
|
||||
|
||||
assertEquals("A report above the configured limit should not be processed", 0, action.reports);
|
||||
assertTrue("Consumed " + consumed.get() + " characters for a configured limit of 1024",
|
||||
consumed.get() <= 1024L + READ_AHEAD_ALLOWANCE);
|
||||
}
|
||||
|
||||
/**
|
||||
* The key named by {@link StrutsConstants#STRUTS_CSP_REPORT_MAX_SIZE} must exist in
|
||||
* default.properties under exactly that name. If the two drift apart the value is silently never
|
||||
* injected, leaving the limit hard-coded and the documented setting inert.
|
||||
*/
|
||||
public void testLimitKeyIsDefinedInDefaultProperties() throws IOException {
|
||||
Properties defaults = new Properties();
|
||||
try (InputStream in = getClass().getClassLoader()
|
||||
.getResourceAsStream("org/apache/struts2/default.properties")) {
|
||||
assertNotNull("default.properties should be on the classpath", in);
|
||||
defaults.load(in);
|
||||
}
|
||||
|
||||
assertEquals(StrutsConstants.STRUTS_CSP_REPORT_MAX_SIZE + " should be defined in default.properties",
|
||||
String.valueOf(CspReportAction.DEFAULT_MAX_REPORT_SIZE),
|
||||
defaults.getProperty(StrutsConstants.STRUTS_CSP_REPORT_MAX_SIZE));
|
||||
}
|
||||
|
||||
public void testUnusableConfiguredValuesAreIgnored() {
|
||||
String[] unusable = {"", " ", "not-a-number", "0", "-1", "2147483647"};
|
||||
|
||||
for (String value : unusable) {
|
||||
AtomicLong consumed = new AtomicLong();
|
||||
MockHttpServletRequest request = requestOfSize(64L * 1024 * 1024, consumed);
|
||||
|
||||
CapturingCspReportAction action = new CapturingCspReportAction();
|
||||
action.setMaxReportSize(value);
|
||||
action.withServletRequest(request);
|
||||
|
||||
assertEquals("A report above the default limit should not be processed for value '"
|
||||
+ value + "'", 0, action.reports);
|
||||
assertTrue("Consumed " + consumed.get() + " characters for value '" + value + "'",
|
||||
consumed.get() <= CspReportAction.DEFAULT_MAX_REPORT_SIZE + READ_AHEAD_ALLOWANCE);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -570,6 +570,46 @@ public class DispatcherTest extends StrutsJUnit4InternalTestCase {
|
||||
assertEquals(Locale.getDefault(), context.getLocale()); // Expect the system default value when Mock request access fails.
|
||||
}
|
||||
|
||||
@Test
|
||||
public void testValidateRequestLocaleOffPassesThrough() {
|
||||
initDispatcher(new HashMap<>());
|
||||
dispatcher.setDefaultLocale(null); // Force struts.locale unset; the test-config default would otherwise mask the request locale.
|
||||
HttpServletRequest request = mock(HttpServletRequest.class);
|
||||
// A syntactically valid but not JVM-available locale.
|
||||
Locale exotic = new Locale("en", "US", "xzz99");
|
||||
when(request.getLocale()).thenReturn(exotic);
|
||||
|
||||
assertEquals("Default off must pass the request locale through unchanged",
|
||||
exotic, dispatcher.getLocale(request));
|
||||
}
|
||||
|
||||
@Test
|
||||
public void testValidateRequestLocaleOnKeepsAvailableLocale() {
|
||||
Map<String, String> params = new HashMap<>();
|
||||
params.put(StrutsConstants.STRUTS_LOCALE_VALIDATE_REQUEST, "true");
|
||||
initDispatcher(params);
|
||||
dispatcher.setDefaultLocale(null); // Force struts.locale unset; the test-config default would otherwise mask the request locale.
|
||||
HttpServletRequest request = mock(HttpServletRequest.class);
|
||||
when(request.getLocale()).thenReturn(Locale.UK);
|
||||
|
||||
assertEquals("Available request locale must be kept", Locale.UK, dispatcher.getLocale(request));
|
||||
}
|
||||
|
||||
@Test
|
||||
public void testValidateRequestLocaleOnFallsBackForUnavailableLocale() {
|
||||
Map<String, String> params = new HashMap<>();
|
||||
params.put(StrutsConstants.STRUTS_LOCALE_VALIDATE_REQUEST, "true");
|
||||
initDispatcher(params);
|
||||
dispatcher.setDefaultLocale(null); // Force struts.locale unset; the test-config default would otherwise mask the request locale.
|
||||
HttpServletRequest request = mock(HttpServletRequest.class);
|
||||
Locale exotic = new Locale("en", "US", "xzz99");
|
||||
when(request.getLocale()).thenReturn(exotic);
|
||||
|
||||
// struts.locale unset in this dispatcher -> fall back to the JVM default.
|
||||
assertEquals("Unavailable request locale must fall back to system default",
|
||||
Locale.getDefault(), dispatcher.getLocale(request));
|
||||
}
|
||||
|
||||
@Test
|
||||
public void dispatcherReinjectedAfterReload() {
|
||||
HttpServletRequest request = mock(HttpServletRequest.class);
|
||||
|
||||
+71
@@ -19,13 +19,17 @@
|
||||
package org.apache.struts2.interceptor.httpmethod;
|
||||
|
||||
import com.opensymphony.xwork2.ActionContext;
|
||||
import com.opensymphony.xwork2.ActionProxy;
|
||||
import com.opensymphony.xwork2.mock.MockActionInvocation;
|
||||
import com.opensymphony.xwork2.mock.MockActionProxy;
|
||||
import org.apache.struts2.HttpMethodsTestAction;
|
||||
import org.apache.struts2.StrutsInternalTestCase;
|
||||
import org.apache.struts2.TestAction;
|
||||
import org.apache.struts2.config.StrutsXmlConfigurationProvider;
|
||||
import org.springframework.mock.web.MockHttpServletRequest;
|
||||
|
||||
import java.util.Map;
|
||||
|
||||
public class HttpMethodInterceptorTest extends StrutsInternalTestCase {
|
||||
|
||||
private HttpMethodInterceptor interceptor;
|
||||
@@ -254,6 +258,73 @@ public class HttpMethodInterceptorTest extends StrutsInternalTestCase {
|
||||
assertEquals(HttpMethod.POST, action.getHttpMethod());
|
||||
}
|
||||
|
||||
/**
|
||||
* Regression for wildcard-resolved methods with no method-level HTTP annotation:
|
||||
* a class-level {@code @AllowedHttpMethod(POST)} must still cause GET to be rejected.
|
||||
* Previously the interceptor's {@code if/else-if} structure made the class-level
|
||||
* branch unreachable when {@code isMethodSpecified()=true} and the resolved method
|
||||
* carried no annotation of its own.
|
||||
*/
|
||||
public void testWildcardResolvedUnannotatedMethodRespectsClassLevelAnnotation() throws Exception {
|
||||
HttpMethodsTestAction action = new HttpMethodsTestAction();
|
||||
prepareActionInvocation(action);
|
||||
actionProxy.setMethod("execute");
|
||||
actionProxy.setMethodSpecified(true);
|
||||
|
||||
prepareRequest("get");
|
||||
|
||||
String resultName = interceptor.intercept(invocation);
|
||||
|
||||
assertEquals("bad-request", resultName);
|
||||
}
|
||||
|
||||
/**
|
||||
* Counterpart to the above: POST against a wildcard-resolved unannotated method must succeed
|
||||
* when the class allows POST via {@code @AllowedHttpMethod(POST)}.
|
||||
*/
|
||||
public void testWildcardResolvedUnannotatedMethodAllowsPostWithClassLevelAnnotation() throws Exception {
|
||||
HttpMethodsTestAction action = new HttpMethodsTestAction();
|
||||
prepareActionInvocation(action);
|
||||
actionProxy.setMethod("execute");
|
||||
actionProxy.setMethodSpecified(true);
|
||||
invocation.setResultCode("success");
|
||||
|
||||
prepareRequest("post");
|
||||
|
||||
String resultName = interceptor.intercept(invocation);
|
||||
|
||||
assertEquals("success", resultName);
|
||||
}
|
||||
|
||||
/**
|
||||
* Exercises the full wildcard resolution path through a real {@link com.opensymphony.xwork2.DefaultActionProxy}.
|
||||
* <p>
|
||||
* Config (from xwork-test-allowed-methods.xml):
|
||||
* {@code <action name="Wild-*" class="HttpMethodsTestAction" method="{1}">}.
|
||||
* URL {@code Wild-execute} resolves to {@code ActionSupport.execute()} — no method-level
|
||||
* HTTP annotation. {@code HttpMethodsTestAction} carries class-level
|
||||
* {@code @AllowedHttpMethod(POST)}, so GET must be rejected end-to-end.
|
||||
*/
|
||||
public void testWildcardResolvedExecuteRejectsGetThroughRealProxy() throws Exception {
|
||||
loadConfigurationProviders(new StrutsXmlConfigurationProvider(
|
||||
"com/opensymphony/xwork2/config/providers/xwork-test-allowed-methods.xml"));
|
||||
|
||||
MockHttpServletRequest request = new MockHttpServletRequest("GET", "/Wild-execute");
|
||||
Map<String, Object> extraContext = ActionContext.of()
|
||||
.withServletRequest(request)
|
||||
.getContextMap();
|
||||
|
||||
ActionProxy proxy = actionProxyFactory.createActionProxy("", "Wild-execute", null, extraContext);
|
||||
|
||||
assertEquals("execute", proxy.getMethod());
|
||||
assertTrue("Wildcard-resolved method must report isMethodSpecified()=true", proxy.isMethodSpecified());
|
||||
|
||||
HttpMethodInterceptor realInterceptor = new HttpMethodInterceptor();
|
||||
String result = realInterceptor.intercept(proxy.getInvocation());
|
||||
|
||||
assertEquals("bad-request", result);
|
||||
}
|
||||
|
||||
private void prepareActionInvocation(Object action) {
|
||||
interceptor = new HttpMethodInterceptor();
|
||||
invocation = new MockActionInvocation();
|
||||
|
||||
@@ -146,5 +146,108 @@ public class PostbackResultTest extends StrutsInternalTestCase {
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* WW-5623: Verify that HTML special characters in finalLocation are properly
|
||||
* escaped in the rendered form action attribute.
|
||||
*/
|
||||
public void testFormActionHtmlEscaping() throws Exception {
|
||||
ActionContext context = ActionContext.getContext();
|
||||
ValueStack stack = context.getValueStack();
|
||||
MockHttpServletRequest req = new MockHttpServletRequest();
|
||||
MockHttpServletResponse res = new MockHttpServletResponse();
|
||||
context.put(ServletActionContext.HTTP_REQUEST, req);
|
||||
context.put(ServletActionContext.HTTP_RESPONSE, res);
|
||||
|
||||
// Push an object with a malicious property onto the value stack
|
||||
stack.push(new Object() {
|
||||
public String getTargetUrl() {
|
||||
return "/test\"onmouseover=\"alert(1)";
|
||||
}
|
||||
});
|
||||
|
||||
PostbackResult result = new PostbackResult();
|
||||
result.setLocation("/redirect?url=${targetUrl}");
|
||||
result.setPrependServletContext(false);
|
||||
|
||||
IMocksControl control = createControl();
|
||||
ActionInvocation mockInvocation = control.createMock(ActionInvocation.class);
|
||||
expect(mockInvocation.getInvocationContext()).andReturn(context).anyTimes();
|
||||
expect(mockInvocation.getStack()).andReturn(stack).anyTimes();
|
||||
|
||||
control.replay();
|
||||
result.setActionMapper(container.getInstance(ActionMapper.class));
|
||||
|
||||
// Call doExecute directly with a malicious location containing all critical chars
|
||||
result.doExecute("/test\"onmouseover=\"alert(1)\"¶m=<script>", mockInvocation);
|
||||
|
||||
String output = res.getContentAsString();
|
||||
|
||||
// The action attribute must contain escaped HTML entities
|
||||
assertTrue("Double quote should be escaped to "",
|
||||
output.contains("action=\"/test"onmouseover="alert(1)"&param=<script>\""));
|
||||
// Must not contain unescaped double-quote that breaks out of the attribute
|
||||
assertFalse("Raw double-quote must not appear in action value",
|
||||
output.contains("action=\"/test\""));
|
||||
|
||||
control.verify();
|
||||
}
|
||||
|
||||
/**
|
||||
* WW-5623: Verify that each individual HTML special character is properly escaped.
|
||||
*/
|
||||
public void testFormActionEscapesAllHtmlSpecialChars() throws Exception {
|
||||
ActionContext context = ActionContext.getContext();
|
||||
MockHttpServletRequest req = new MockHttpServletRequest();
|
||||
MockHttpServletResponse res = new MockHttpServletResponse();
|
||||
context.put(ServletActionContext.HTTP_REQUEST, req);
|
||||
context.put(ServletActionContext.HTTP_RESPONSE, res);
|
||||
|
||||
IMocksControl control = createControl();
|
||||
ActionInvocation mockInvocation = control.createMock(ActionInvocation.class);
|
||||
expect(mockInvocation.getInvocationContext()).andReturn(context).anyTimes();
|
||||
|
||||
control.replay();
|
||||
|
||||
PostbackResult result = new PostbackResult();
|
||||
result.setActionMapper(container.getInstance(ActionMapper.class));
|
||||
result.doExecute("/path?a=1&b=2\"<>", mockInvocation);
|
||||
|
||||
String output = res.getContentAsString();
|
||||
|
||||
assertTrue("Ampersand should be escaped", output.contains("&"));
|
||||
assertTrue("Double-quote should be escaped", output.contains("""));
|
||||
assertTrue("Less-than should be escaped", output.contains("<"));
|
||||
assertTrue("Greater-than should be escaped", output.contains(">"));
|
||||
|
||||
control.verify();
|
||||
}
|
||||
|
||||
/**
|
||||
* WW-5623: Verify that a clean location (no special chars) renders unchanged.
|
||||
*/
|
||||
public void testFormActionCleanLocationUnchanged() throws Exception {
|
||||
ActionContext context = ActionContext.getContext();
|
||||
MockHttpServletRequest req = new MockHttpServletRequest();
|
||||
MockHttpServletResponse res = new MockHttpServletResponse();
|
||||
context.put(ServletActionContext.HTTP_REQUEST, req);
|
||||
context.put(ServletActionContext.HTTP_RESPONSE, res);
|
||||
|
||||
IMocksControl control = createControl();
|
||||
ActionInvocation mockInvocation = control.createMock(ActionInvocation.class);
|
||||
expect(mockInvocation.getInvocationContext()).andReturn(context).anyTimes();
|
||||
|
||||
control.replay();
|
||||
|
||||
PostbackResult result = new PostbackResult();
|
||||
result.setActionMapper(container.getInstance(ActionMapper.class));
|
||||
result.doExecute("/clean/path/action.do", mockInvocation);
|
||||
|
||||
String output = res.getContentAsString();
|
||||
|
||||
assertTrue("Clean location should render as-is in action attribute",
|
||||
output.contains("action=\"/clean/path/action.do\""));
|
||||
|
||||
control.verify();
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one
|
||||
# or more contributor license agreements. See the NOTICE file
|
||||
# distributed with this work for additional information
|
||||
# regarding copyright ownership. The ASF licenses this file
|
||||
# to you under the Apache License, Version 2.0 (the
|
||||
# "License"); you may not use this file except in compliance
|
||||
# with the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing,
|
||||
# software distributed under the License is distributed on an
|
||||
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||
# KIND, either express or implied. See the License for the
|
||||
# specific language governing permissions and limitations
|
||||
# under the License.
|
||||
#
|
||||
cache.static=Static cached value
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-async-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
|
||||
|
||||
+1
-1
@@ -25,7 +25,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-cdi-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-config-browser-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-convention-plugin</artifactId>
|
||||
|
||||
+1
-1
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-dwr-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-embeddedjsp-plugin</artifactId>
|
||||
|
||||
+1
-1
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-gxp-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-jasperreports-plugin</artifactId>
|
||||
|
||||
@@ -25,7 +25,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-javatemplates-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-jfreechart-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-json-plugin</artifactId>
|
||||
|
||||
@@ -57,6 +57,9 @@ public class JSONUtil {
|
||||
|
||||
public final static String RFC3339_FORMAT = "yyyy-MM-dd'T'HH:mm:ss";
|
||||
public static final boolean CACHE_BEAN_INFO_DEFAULT = true;
|
||||
|
||||
/** Chunk size used to read input incrementally while applying the length limit. */
|
||||
private static final int READ_CHUNK_SIZE = 8192;
|
||||
|
||||
private static final Logger LOG = LogManager.getLogger(JSONUtil.class);
|
||||
|
||||
@@ -337,13 +340,15 @@ public class JSONUtil {
|
||||
*/
|
||||
public Object deserializeInput(Reader reader, int maxLength, int maxElements, int maxDepth,
|
||||
int maxStringLength, int maxKeyLength) throws JSONException {
|
||||
BufferedReader bufferReader = new BufferedReader(reader);
|
||||
StringBuilder buffer = new StringBuilder();
|
||||
String line;
|
||||
char[] chunk = new char[READ_CHUNK_SIZE];
|
||||
|
||||
try {
|
||||
while ((line = bufferReader.readLine()) != null) {
|
||||
buffer.append(line);
|
||||
int read;
|
||||
// Apply the limit while reading rather than afterwards, so input that contains no
|
||||
// line terminator is not accumulated in full before the limit can be evaluated.
|
||||
while ((read = reader.read(chunk)) != -1) {
|
||||
buffer.append(chunk, 0, read);
|
||||
if (buffer.length() > maxLength) {
|
||||
throw new JSONException("JSON input length exceeds maximum allowed length of " + maxLength);
|
||||
}
|
||||
|
||||
@@ -0,0 +1,119 @@
|
||||
/*
|
||||
* Licensed to the Apache Software Foundation (ASF) under one
|
||||
* or more contributor license agreements. See the NOTICE file
|
||||
* distributed with this work for additional information
|
||||
* regarding copyright ownership. The ASF licenses this file
|
||||
* to you under the Apache License, Version 2.0 (the
|
||||
* "License"); you may not use this file except in compliance
|
||||
* with the License. You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing,
|
||||
* software distributed under the License is distributed on an
|
||||
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||
* KIND, either express or implied. See the License for the
|
||||
* specific language governing permissions and limitations
|
||||
* under the License.
|
||||
*/
|
||||
package org.apache.struts2.json;
|
||||
|
||||
import org.junit.Test;
|
||||
|
||||
import java.io.Reader;
|
||||
import java.io.StringReader;
|
||||
import java.util.Map;
|
||||
import java.util.concurrent.atomic.AtomicLong;
|
||||
|
||||
import static org.junit.Assert.assertEquals;
|
||||
import static org.junit.Assert.assertTrue;
|
||||
import static org.junit.Assert.fail;
|
||||
|
||||
/**
|
||||
* Verifies that {@link JSONUtil#deserializeInput(Reader, int, int, int, int, int)} applies the
|
||||
* configured input length limit while reading, bounding how much input is consumed before the limit
|
||||
* takes effect, and that input within the limit still parses.
|
||||
*/
|
||||
public class JSONUtilInputLimitTest {
|
||||
|
||||
/**
|
||||
* Emits {@code total} characters with no line terminator anywhere, and records how many
|
||||
* characters the caller actually consumed.
|
||||
*/
|
||||
private static final class UnterminatedReader extends Reader {
|
||||
private final long total;
|
||||
private final AtomicLong consumed;
|
||||
private long produced = 0;
|
||||
|
||||
UnterminatedReader(long total, AtomicLong consumed) {
|
||||
this.total = total;
|
||||
this.consumed = consumed;
|
||||
}
|
||||
|
||||
@Override
|
||||
public int read(char[] cbuf, int off, int len) {
|
||||
if (produced >= total) {
|
||||
return -1;
|
||||
}
|
||||
int count = (int) Math.min(len, total - produced);
|
||||
for (int i = 0; i < count; i++) {
|
||||
cbuf[off + i] = 'a';
|
||||
}
|
||||
produced += count;
|
||||
consumed.addAndGet(count);
|
||||
return count;
|
||||
}
|
||||
|
||||
@Override
|
||||
public void close() {
|
||||
// characters are generated on demand, so there is nothing to release
|
||||
}
|
||||
}
|
||||
|
||||
@Test
|
||||
public void inputWithoutLineTerminatorIsLimitedWhileReading() {
|
||||
int maxLength = 1024;
|
||||
long inputSize = 64L * 1024 * 1024;
|
||||
AtomicLong consumed = new AtomicLong();
|
||||
|
||||
JSONUtil util = new JSONUtil();
|
||||
Reader input = new UnterminatedReader(inputSize, consumed);
|
||||
|
||||
try {
|
||||
util.deserializeInput(input, maxLength, 100, 10, 1000, 100);
|
||||
fail("Expected JSONException for exceeding max length");
|
||||
} catch (JSONException expected) {
|
||||
// the limit is expected to be reported
|
||||
}
|
||||
|
||||
long read = consumed.get();
|
||||
// Reading proceeds in chunks, so a single chunk of overshoot beyond the limit is expected.
|
||||
assertTrue("Consumed " + read + " characters for a limit of " + maxLength,
|
||||
read < maxLength + 65_536L);
|
||||
}
|
||||
|
||||
@Test
|
||||
public void inputWithinLimitIsParsed() throws JSONException {
|
||||
JSONUtil util = new JSONUtil();
|
||||
|
||||
Object result = util.deserializeInput(
|
||||
new StringReader("{\"a\":1, \"b\":\"hello\"}"), 1024, 100, 10, 1000, 100);
|
||||
|
||||
assertTrue("Expected a parsed JSON object", result instanceof Map);
|
||||
assertEquals(1L, ((Map<?, ?>) result).get("a"));
|
||||
assertEquals("hello", ((Map<?, ?>) result).get("b"));
|
||||
}
|
||||
|
||||
@Test
|
||||
public void inputSpanningMultipleLinesIsParsed() throws JSONException {
|
||||
JSONUtil util = new JSONUtil();
|
||||
|
||||
// Line terminators between tokens are insignificant whitespace to the reader.
|
||||
Object result = util.deserializeInput(
|
||||
new StringReader("{\n\"a\":1,\n\"b\":2\n}"), 1024, 100, 10, 1000, 100);
|
||||
|
||||
assertTrue("Expected a parsed JSON object", result instanceof Map);
|
||||
assertEquals(1L, ((Map<?, ?>) result).get("a"));
|
||||
assertEquals(2L, ((Map<?, ?>) result).get("b"));
|
||||
}
|
||||
}
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-junit-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-osgi-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-oval-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-pell-multipart-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-plexus-plugin</artifactId>
|
||||
|
||||
+1
-1
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-portlet-junit-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-portlet-mocks-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-portlet-tiles-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-portlet-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-rest-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-sitemesh-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-spring-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-testng-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-tiles-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-velocity-plugin</artifactId>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-xslt-plugin</artifactId>
|
||||
|
||||
@@ -29,7 +29,7 @@
|
||||
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>6.9.0-SNAPSHOT</version>
|
||||
<version>6.11.0</version>
|
||||
<packaging>pom</packaging>
|
||||
<name>Struts 2</name>
|
||||
<url>https://struts.apache.org/</url>
|
||||
@@ -51,7 +51,7 @@
|
||||
<connection>scm:git:https://gitbox.apache.org/repos/asf/struts.git</connection>
|
||||
<developerConnection>scm:git:https://gitbox.apache.org/repos/asf/struts.git</developerConnection>
|
||||
<url>https://github.com/apache/struts/</url>
|
||||
<tag>STRUTS_6_7_0</tag>
|
||||
<tag>STRUTS_6_11_0</tag>
|
||||
</scm>
|
||||
|
||||
<issueManagement>
|
||||
@@ -104,20 +104,20 @@
|
||||
|
||||
<properties>
|
||||
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
|
||||
<project.build.outputTimestamp>2026-03-09T08:01:35Z</project.build.outputTimestamp>
|
||||
<project.build.outputTimestamp>2026-08-01T10:22:19Z</project.build.outputTimestamp>
|
||||
<maven.compiler.source>1.8</maven.compiler.source>
|
||||
<maven.compiler.target>1.8</maven.compiler.target>
|
||||
|
||||
<!-- dependency versions in alphanumeric order -->
|
||||
<asm.version>9.10</asm.version>
|
||||
<jackson.version>2.21.3</jackson.version>
|
||||
<log4j2.version>2.25.4</log4j2.version>
|
||||
<asm.version>9.10.1</asm.version>
|
||||
<jackson.version>2.22.1</jackson.version>
|
||||
<log4j2.version>2.26.1</log4j2.version>
|
||||
<ognl.version>3.3.5</ognl.version>
|
||||
<slf4j.version>2.0.18</slf4j.version>
|
||||
<spring.platformVersion>5.3.39</spring.platformVersion>
|
||||
<tiles.version>3.0.8</tiles.version>
|
||||
<tiles-request.version>1.0.7</tiles-request.version>
|
||||
<maven-surefire-plugin.version>3.5.5</maven-surefire-plugin.version>
|
||||
<maven-surefire-plugin.version>3.5.6</maven-surefire-plugin.version>
|
||||
<hibernate-validator.version>6.2.4.Final</hibernate-validator.version>
|
||||
<freemarker.version>2.3.34</freemarker.version>
|
||||
|
||||
@@ -224,7 +224,7 @@
|
||||
<plugin>
|
||||
<groupId>org.jacoco</groupId>
|
||||
<artifactId>jacoco-maven-plugin</artifactId>
|
||||
<version>0.8.14</version>
|
||||
<version>0.8.15</version>
|
||||
<executions>
|
||||
<execution>
|
||||
<id>prepare-agent</id>
|
||||
@@ -300,7 +300,7 @@
|
||||
<plugin>
|
||||
<groupId>org.apache.maven.plugins</groupId>
|
||||
<artifactId>maven-dependency-plugin</artifactId>
|
||||
<version>3.10.0</version>
|
||||
<version>3.11.0</version>
|
||||
</plugin>
|
||||
<plugin>
|
||||
<groupId>org.apache.maven.plugins</groupId>
|
||||
@@ -407,7 +407,7 @@
|
||||
<plugin>
|
||||
<groupId>org.apache.maven.plugins</groupId>
|
||||
<artifactId>maven-site-plugin</artifactId>
|
||||
<version>3.21.0</version>
|
||||
<version>3.22.0</version>
|
||||
<configuration>
|
||||
<relativizeDecorationLinks>false</relativizeDecorationLinks>
|
||||
</configuration>
|
||||
@@ -846,7 +846,7 @@
|
||||
<dependency>
|
||||
<groupId>commons-logging</groupId>
|
||||
<artifactId>commons-logging</artifactId>
|
||||
<version>1.3.6</version>
|
||||
<version>1.4.0</version>
|
||||
</dependency>
|
||||
<dependency>
|
||||
<groupId>org.apache.commons</groupId>
|
||||
|
||||
Reference in New Issue
Block a user