5582 Commits

Author SHA1 Message Date
Sébastien Deleuze 86d99790db Refine JavaScriptUtils#javaScriptEscape
Closes gh-36796
2026-06-08 15:13:12 +02:00
rstoyanchev ce90e4b11f RfcParser rejects invalid IPv6 host
Closes gh-36787
2026-06-08 15:13:12 +02:00
Brian Clozel ecfa498ea9 Support multi-line comments in Server Sent Events
Prior to this commit, comments sent with Server Sent Events could break
the wire format when sent over the network when comments contained line
breaks.
While comments are mainly used for sending keepalive messages, they can
also be used for sending debug data. This commit ensures that line
breaks are properly handled in comments.

Fixes gh-36866
2026-06-03 11:22:49 +02:00
rstoyanchev b8ddd2c690 Avoid race in InMemoryWebSession
Closes gh-36742
2026-05-01 15:23:59 +01:00
Brian Clozel a58fdeaf3f Fix PartGenerator token request while creating tmp file
Prior to this commit, the `PartGenerator` would allow requesting
additional part tokens while in the `CreateFileState`. This is invalid
as any new token emitted would be rejected and would fail the entire
process.
This would only happen if the tmp file creation is slow enough for a new
token to be parsed and emitted.

This commit ensures that no new part token is requested while creating
the temporary file.
This change also fixes lifecycle issues and ensures that buffer
resources are cleaned in case of errors.

Fixes gh-36694
2026-04-28 23:30:01 +02:00
Sigurd Gerke e4bfdfa229 Fix a regression on value class parameter handling
This commit fixes a regression introduced by gh-36449 for
nullable value class with an non-null value.

Closes gh-36720
Signed-off-by: Sigurd Gerke <sigurd.gerke@onedata.de>
2026-04-28 11:08:06 +02:00
Juergen Hoeller cba8f225d9 Consistently ignore exceptions for Xerces-specific properties
Closes gh-36682

(cherry picked from commit af7a5716e8)
2026-04-21 20:41:06 +02:00
rstoyanchev b338fdd99d Add doOnDiscard in MultipartHttpMessageReader
Closes gh-36563
2026-04-16 21:19:13 +01:00
Sam Brannen 4e3f264f34 Add missing tests for WebRequestDataBinder
See gh-36625

(cherry picked from commit 63817ce202)
2026-04-16 16:36:27 +02:00
Sam Brannen 9e0b83ead3 Polish WebRequestDataBinderTests
(cherry picked from commit 61bd79017f)
2026-04-16 16:36:18 +02:00
Sam Brannen af4b1229a5 Extract ServletRequestParameterPropertyValuesTests
(cherry picked from commit c9b88b4ebd)
2026-04-16 15:08:23 +02:00
Sam Brannen 623ccd1a4f Revise "Skip binding entirely when field is not allowed"
This commit reverts the changes made to WebDataBinder's doBind()
implementation in e4d03f6625 and instead implements the skipping logic
directly in checkFieldDefaults(), checkFieldMarkers(), and
adaptEmptyArrayIndices() by preemptively checking if the corresponding
field is allowed.

This commit also improves the Javadoc and adds missing tests.

See gh-36625
Fixes gh-36627

(cherry picked from commit 68c575ab14)
2026-04-16 15:08:09 +02:00
Sam Brannen 69068ba33d Further clarify semantics of HttpMethod.valueOf()
See gh-36652

(cherry picked from commit cb320468db)
2026-04-14 16:19:43 +02:00
angry2.k f182f9a76b Clarify semantics of HttpMethod.valueOf()
HttpMethod.valueOf() performs a case-sensitive lookup of predefined
HttpMethod constants. For example, valueOf("GET") resolves to
HttpMethod.GET, whereas valueOf("get") results in a newly created
HttpMethod instance.
Update the Javadoc to explicitly document this behavior.

See gh-36642
Closes gh-36652

Signed-off-by: angry-2k <edkev@kakao.com>

(cherry picked from commit df828458fa)
2026-04-14 16:19:35 +02:00
Sébastien Deleuze b07bc2cb99 Apply nullable value class fix to InvocableHandlerMethod
See gh-36643
2026-04-10 16:24:36 +02:00
Brian Clozel cbdec804a5 Allow null id/event in ServerSentEvent
The builder itself does not allow `null` values so this shouldn't be
necessary, but because the offending change was introduced late in the
6.2.x line, we'll be more flexible here.

Fixes gh-36634
2026-04-10 14:43:29 +02:00
Brian Clozel 589e58e400 Skip binding entirely when field is not allowed
Prior to this commit, fields that are not allowed for binding were
always skipped and would not be bound. But the field and default marker
support (with the "_" and "!" prefixes) would be still considered and
could trigger collection instantiation/autogrow.

While this does not cause unwanted binding, this allocates memory for no
reason. This commit revisits the binding algorithm to only consider
default and field marker support if the regular field is allowed.

Fixes gh-36627
2026-04-09 11:06:46 +02:00
Juergen Hoeller 63cd96fa5f Revise target bean exception with consistent message formatting 2026-04-08 15:48:17 +02:00
Juergen Hoeller 241a7dca02 Polishing
(cherry picked from commit 1687d90a8c)
2026-04-08 15:09:33 +02:00
Brian Clozel df198987e0 Allow unlimited caching in ContentCachingRequestWrapper
Prior to this commit the `ContentCachingRequestWrapper(HttpServletRequest)`
constructor was deprecated; this variant caches by default an unlimited
amount of data. The replacement
`ContentCachingRequestWrapper(HttpServletRequest, int)` allows such
behavior in 7.0 but that change has not been bacported to 6.2.x.

This commit ensures that the replacement constructor can be safely used
in 6.2.x, preparing for the 7.0.x upgrade.

Fixes gh-36620
2026-04-08 11:29:27 +02:00
Brian Clozel 39a6d4709f Deprecate types removed in 7.0
This commit `@Deprecate` for removal the following because support was
removed in 7.0:

* Netty 5 and Reactor Netty2 experimental support is abandonned
* Undertow does not support the Framework 7.0 baseline, developers
  should consider another Servlet container at this point

See gh-36591
2026-04-03 17:50:38 +02:00
Sam Brannen 6f204bf4a3 Polishing
(cherry picked from commit 24c7d31ba7)
2026-04-02 13:24:03 +02:00
Sam Brannen 5873e40782 Enforce use of AssertJ assumptions via Checkstyle
Closes gh-36582

(cherry picked from commit b6fc3a1b6f)
2026-04-02 13:24:03 +02:00
Juergen Hoeller 9ceb9efb2c Polishing 2026-04-01 21:25:11 +02:00
Juergen Hoeller 96a028a028 Consistent IOException spelling in class/method names 2026-03-21 12:19:07 +01:00
Sam Brannen 506c6f1777 Clean up AssertJ usage after migration
- Avoid the use of assertThat(Arrays.equals(...))
- Convert assertThat(Boolean.FALSE).isEqualTo(x) to assertThat(x).isEqualTo(Boolean.FALSE)
- Convert assertThat(Boolean.TRUE).isEqualTo(x) to assertThat(x).isEqualTo(Boolean.TRUE)
- Convert assertThat(x.equals(y)).isTrue() to assertThat(x).isEqualTo(y)
- Convert assertThat(x.equals(y)).isFalse() to assertThat(x).isNotEqualTo(y)
- Remove unnecessary parentheses in assertThat() arguments
- Convert assertThat(x instanceof X).isFalse() to assertThat(x).isNotInstanceOf()
- Convert assertThat(x instanceof X).isTrue() to assertThat(x).isInstanceOf()
- Convert assertThat(!x).isTrue() to assertThat(x).isFalse()
- Inline conditions in assertThat() statements

Closes gh-36504

(cherry picked from commit e1e4d52b61)
2026-03-20 11:38:33 +01:00
Sam Brannen 6d6b788b25 Enable SpringJUnit5 Checkstyle rule
See gh-36496
Closes gh-36496

(cherry picked from commit 1256307c83)
2026-03-18 19:07:27 +01:00
Sam Brannen 01248c7753 Remove obsolete "test" prefix from test method names
Although this commit also changes the visibility of some test methods
to package-private, the remainder of that task will be addressed in
conjunction with gh-36496.

Closes gh-36495

(cherry picked from commit 4c14abf0cd)
2026-03-18 18:27:53 +01:00
Sam Brannen e598df8c60 Fix common typos and grammatical mistakes
Closes gh-36471

(cherry picked from commit 5eb0e99d58)
2026-03-15 17:19:28 +01:00
Sam Brannen 0c4ed55fd2 Consistently use American English spelling
Since the Spring Framework uses American English spelling, this commit
updates Javadoc and the reference manual to ensure consistency in that
regard. However, there are two exceptions to this rule that arise due
to their use within a technical context.

- We use "cancelled/cancelling" instead of "canceled/canceling" in
  numerous places (including error messages).
- We use "implementor" instead of "implementer".

Closes gh-36470

(cherry picked from commit 17699103dc)
2026-03-15 17:16:39 +01:00
Brian Clozel 8dc888e1b8 Guard against invalid id/event values in Server Sent Events
Prior to this commit, our implementation of Server Sent Events (SSE),
`SseEmitter` (MVC) and `ServerSentEvent` (WebFlux), would not guard
against invalid characters if the application mistakenly inserts such
characters in the `id` or `event` types.
Both implementations would also behave differently when it comes
to escaping comment multi-line events.

This commit ensures that both implementations handle multi-line comment
events and reject invalid characters in id/event types.
This commit also optimizes `String` concatenation and memory usage
when writing data.

Fixes gh-36440
2026-03-10 17:56:39 +01:00
Sam Brannen f41786b6af Fix typo
(cherry picked from commit bd40f0e6bb)
2026-03-01 13:06:56 +01:00
Sam Brannen 2d10d513e1 Consistently refer to URLs and URIs in documentation
(cherry picked from commit 04186fdf0e)
2026-03-01 13:06:56 +01:00
rstoyanchev 9042682b56 Optimal charset handling in AbstractHttpMessageConverter
Closes gh-36320
2026-02-23 15:44:26 +00:00
Brian Clozel 2d81a9fe9b Optimize MediaType(MediaType, Charset) constructor
Prior to this commit, the `MediaType` and `MimeType` "copy" constructors
would not leverage the fact that the existing instance has been
validated already (types, subtype and parameters have been checked
already for errors) and the entire validation would be performed again.
This would also allocate map instances in the process.

This commit ensures that the already validated information is reused
directly and that we avoid unnessecary operations and allocations for
such constructors.

Closes gh-36318
2026-02-23 15:40:18 +00:00
rstoyanchev 50ef3b0a29 Update Javadoc of RestClient.Builder defaultStatusHandler
See gh-36248
2026-02-19 11:45:33 +00:00
Juergen Hoeller 999bbe3959 Polishing 2026-02-17 18:41:07 +01:00
Juergen Hoeller acab61f9a7 Consistent adaptation of HTTP headers on Servlet responses
Closes gh-36345
2026-02-17 18:40:50 +01:00
Juergen Hoeller bfa81290b3 Polishing 2026-02-17 12:18:31 +01:00
Brian Clozel 474d520182 Fix MultipartParser & PartGenerator memory leak
Prior to this commit, the reactive `MultipartParser` and `PartGenerator`
types were leaking memory at runtime in specific cases:

* many HTTP clients must send multipart requests to be parsed and close
  the connection while uploading
* the `PartGenerator` must be configured to write file parts to
  temporary files on disk
* concurrency, upload speed must be important to trigger cases where the
  file system is not fast enough to consume incoming buffers

The `MultipartParser` parses and emits `BodyToken` to its sink
(here, the `PartGenerator`). By definition, Reactor's `FluxSink` when
created with `Flux.create(FluxSink)` will use a "buffer" strategy and
will queue emitted elements if they cannot be consumed.

Here, the cancellation signal does dispose internal states in the
`MultiPartParser` and `PartGenerator` but does not clear the internal
queue in `FluxSink`.

This commit ensures that an operation is registered to release buffers
on the discard event.

Fixes gh-36262
2026-02-13 18:45:05 +01:00
Juergen Hoeller 50bffe7ddc Detect all common size exceptions from Tomcat and Commons FileUpload 2.x
Closes gh-36317

(cherry picked from commit e8e24e65d2)
2026-02-13 16:32:56 +01:00
rstoyanchev 6162d89042 Cache HandlerMethod with resolved bean if singleton
See gh-36278
2026-02-11 09:12:08 +00:00
rstoyanchev 849553dc8e Avoid determineValidationGroups not necessary
There is no need to call determineValidationGroups if the method
itself doesn't require method validation.

See gh-36274
2026-02-11 09:05:19 +00:00
Brian Clozel 0c3dd8cb00 Fix "remove" implementation in netty headers adapter
Prior to this commit, the `Netty4HeadersAdapter` `MultiValueMapi#remove`
implementation would return an empty list if no value was present. This
is not consistent with other implementations.

This change ensures that `null` is returned for those cases.

Fixes gh-36226
2026-01-29 11:31:50 +01:00
rstoyanchev af1e9da3d7 Update docs on trailing slash handling
Closes gh-36198
2026-01-28 12:23:47 +00:00
Juergen Hoeller 1ec3cb4d5f Polishing (aligned with main) 2026-01-27 21:25:23 +01:00
rstoyanchev 7b7126ae3d Polishing in ReactorClientHttpConnector 2026-01-26 10:46:59 +00:00
rstoyanchev 9f1332c716 Refine solution to clear Netty channel attribute
Closes gh-36158
2026-01-26 10:45:33 +00:00
Sam Brannen 154dad6587 Revise contribution
See gh-36170

(cherry picked from commit b164db35c1)
2026-01-18 17:02:09 +01:00
Tran Ngoc Nhan fd8b4d5936 Replace getErrors() with getBindingResult() in examples
DataBinder#getErrors was removed in v4.0.0.M1.

Closes gh-36170

Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com>

(cherry picked from commit 385e62dbf0)
2026-01-18 17:02:01 +01:00