Commit Graph

34567 Commits

Author SHA1 Message Date
Brian Clozel 2691489381 Fix InvalidMimeTypeException for compatible media types
The `AbstractMessageConverterMethodProcessor` is in charge of handling
controller method return values and to write those as HTTP response
messages. The content negotiation process is an important part.

The `MimeTypeUtils#sortBySpecificity` is in charge of sorting inbound
"Accept" media types by their specificity and reject them if the list
is too large, in order to protect the application from ddos attacks.

Prior to this commit, the content negotiation process would first get
the sorted "Accept" media types, the producible media types as
advertized by message converters - and collect the intersection of both
in a new list (also sorted by specificity). If the "Accept" list is
large enough (but under the limit), the list of compatible media types
could exceed that limit because duplicates could be introduced in that
list: several converters can produce the same content type.

This commit ensures that compatible media types are collected in a set
to avoid duplicates. Without that, exceeding the limit at this point
will throw an `InvalidMimeTypeException` that's not handled by the
processor and result in a server error.

Fixes gh-36300
2026-02-20 18:21:45 +01:00
Tran Ngoc Nhan f103af4982 Remove obsolete space in HandlerMethod.html#assertTargetBean javadoc
Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com>
2026-02-20 13:43:11 +00:00
rstoyanchev b9a59853fa Use case-insensitive comparator in HttpHeadersAssert
Closes gh-36349
2026-02-20 13:38:51 +00:00
rstoyanchev d4b2a493f9 Fix duplicate header writing in ResponseBodyEmitterReturnValueHandler
Closes gh-36357
2026-02-20 10:45:22 +00:00
rstoyanchev 188cb9b24d Update Javadoc of RestClient.Builder defaultStatusHandler
See gh-36248
2026-02-19 11:42:59 +00:00
rstoyanchev e3568a3f0a Fix generic return type support in HttpServiceMethod
Closes gh-36326
2026-02-18 17:27:02 +00:00
rstoyanchev e106fc0434 Polishing in RestClientAdapterTests and WebClientAdapterTests 2026-02-18 17:27:02 +00:00
Stéphane Nicoll ca3adf43eb Next development version (v7.0.6-SNAPSHOT) 2026-02-18 14:07:54 +01:00
rstoyanchev 85c18caf25 Update docs on supported versions with baseline notation
Closes gh-36316
2026-02-18 11:33:08 +00:00
Juergen Hoeller 22bd8bd704 Skip serialization of potentially non-serializable cached state
Closes gh-36346
2026-02-17 22:13:57 +01:00
Juergen Hoeller 9b10bb5e08 Polishing 2026-02-17 18:57:09 +01:00
Juergen Hoeller 727ccd04ef Avoid setCharacterEncoding(Charset) call with null value
Includes consistent content length check for functional response.

See gh-36343
2026-02-17 18:56:59 +01:00
Juergen Hoeller a9f447e8d7 Consistent adaptation of HTTP headers on Servlet responses
Includes use of Servlet 6.1 setCharacterEncoding(Charset)

Closes gh-36343
2026-02-17 17:38:50 +01:00
海子 Yang 0841e79e32 Copy methodAnnotations in MethodParameter copy constructor
Signed-off-by: 海子 Yang <i.take.today@gmail.com>
2026-02-17 17:17:22 +01:00
Niravil a1868d3e9e fix TransactionAspectSupport#currentTransactionStatus javadoc
Signed-off-by: Niravil <messerignacius@gmail.com>
2026-02-17 16:26:02 +01:00
rstoyanchev e5aac66157 ServletResponseHeadersAdapter checks contentType property
Issue gh-36334
2026-02-17 11:55:34 +00:00
Juergen Hoeller 8bf85d2596 Polishing 2026-02-17 12:27:00 +01:00
Juergen Hoeller 508b31da4f Optimize Entry hashCode in HttpHeaders (plus related polishing) 2026-02-17 11:55:10 +01:00
Juergen Hoeller d291272736 Use HandlerMethod-determined validation groups
Closes gh-36336
2026-02-17 11:50:07 +01:00
海子 Yang db01f07037 Remove unused EMPTY_GROUPS in InvocableHandlerMethod
Signed-off-by: 海子 Yang <i.take.today@gmail.com>
2026-02-17 11:30:54 +01:00
Brian Clozel b9e190e313 Fix HttpMessageConverters configurers support
This commit fixes the `configureMessageConverters` and
`configureMessageConvertersList` behavior.

`configureMessageConverters` was not executing consumers in their order
of registration (but in the reverse order).
`configureMessageConvertersList` was not executing multiple consumers
and was instead executing the first consumer multiple times.

This commit fixes both issues.

Fixes gh-36332
2026-02-16 18:48:26 +01:00
rstoyanchev d712ec3d49 Minor optimization in Tomcat header adapters
get method skips containsKey and instead checks if the enumeration
has elements, which should give the same behavior other than for
headers without values.

See gh-36334
2026-02-16 17:38:01 +00:00
rstoyanchev 5baa4fdd69 Further optimize Servlet header adapters
- Optimize get method for request headers
- Update keySet methods to use custom extension of AbstractSet
- Drop use of native Tomcat headers, which could be an issue for
request and response wrappers that override header methods.
The performance of Servlet adapters should be similar for the
commonly used methods, and it should be possible to optimize
further for the future in HttpHeaders (e.g. by adding a
set alternative to put), and requesting Servlet API refinements.

Closes gh-36334
2026-02-16 17:37:51 +00:00
rstoyanchev 9273a11a2c Stub Servlet headers adapter methods not needed in HttpHeaders
See gh-36334
2026-02-16 17:37:27 +00:00
rstoyanchev 7ea11baff9 Pass-through handling of Servlet headers
See gh-36334
2026-02-16 17:37:09 +00:00
Sam Brannen 655fd2e2bf Document that SpEL expressions using Optional w/ null-safe & Elvis operators are not compilable
Closes gh-36331
2026-02-15 12:26:54 +01:00
Brian Clozel a31574a0a2 Fix MultipartParser & PartGenerator memory leak
Prior to this commit, the reactive `MultipartParser` and `PartGenerator`
types were leaking memory at runtime in specific cases:

* many HTTP clients must send multipart requests to be parsed and close
  the connection while uploading
* the `PartGenerator` must be configured to write file parts to
  temporary files on disk
* concurrency, upload speed must be important to trigger cases where the
  file system is not fast enough to consume incoming buffers

The `MultipartParser` parses and emits `BodyToken` to its sink
(here, the `PartGenerator`). By definition, Reactor's `FluxSink` when
created with `Flux.create(FluxSink)` will use a "buffer" strategy and
will queue emitted elements if they cannot be consumed.

Here, the cancellation signal does dispose internal states in the
`MultiPartParser` and `PartGenerator` but does not clear the internal
queue in `FluxSink`.

This commit ensures that an operation is registered to release buffers
on the discard event.

Fixes gh-36262
2026-02-13 18:33:47 +01:00
Juergen Hoeller 44f3e7b427 Fix Checkstyle violation
See gh-36317
2026-02-13 16:34:58 +01:00
Juergen Hoeller e8e24e65d2 Detect all common size exceptions from Tomcat and Commons FileUpload 2.x
Closes gh-36317
2026-02-13 16:19:46 +01:00
Sam Brannen 9a002a77b2 Stop referring to "Java-8" features in documentation
See gh-36310
2026-02-13 15:21:31 +01:00
Brian Clozel 97e96895db Optimize MediaType(MediaType, Charset) constructor
Prior to this commit, the `MediaType` and `MimeType` "copy" constructors
would not leverage the fact that the existing instance has been
validated already (types, subtype and parameters have been checked
already for errors) and the entire validation would be performed again.
This would also allocate map instances in the process.

This commit ensures that the already validated information is reused
directly and that we avoid unnessecary operations and allocations for
such constructors.

Closes gh-36318
2026-02-13 14:49:34 +01:00
Juergen Hoeller e98c2fe488 Reuse AnnotatedMethod annotation cache in derived instances
Closes gh-36322
2026-02-13 13:55:24 +01:00
Juergen Hoeller 75705bcbb1 Restore early MessageConsumer creation for temporary queue
Closes gh-36321
2026-02-13 13:55:08 +01:00
rstoyanchev 47a2e7059e Optimal charset handling in AbstractHttpMessageConverter
Closes gh-36320
2026-02-13 12:39:03 +00:00
Sam Brannen 14b6339351 Consistently support @⁠Autowired as a meta-annotation
Prior to this commit, the findAutowiredAnnotation() method in
AutowiredAnnotationBeanPostProcessor fully supported finding
@⁠Autowired as a meta-annotation; however, the isRequired() method in
QualifierAnnotationAutowireCandidateResolver only found @⁠Autowired as
a "directly present" annotation without any support for
meta-annotations.

For consistency and to avoid bugs, this commit revises
QualifierAnnotationAutowireCandidateResolver so that we always support
@⁠Autowired as a meta-annotation.

Closes gh-36315
2026-02-12 16:38:24 +01:00
Juergen Hoeller bc2e89a786 Cache ResponseBody annotation presence per controller class
See gh-36311
2026-02-12 13:44:54 +01:00
Sam Brannen 4abbddf601 Avoid duplicate required attribute lookup for @⁠Autowired annotations
This commit revises AutowiredAnnotationBeanPostProcessor so that
determineRequiredStatus(MergedAnnotation<?>) only looks up the required
attribute once.

Closes gh-36314
2026-02-12 13:19:06 +01:00
Sam Brannen 926bcbd9a6 Stop referring to obsolete ListenableFuture in documentation
ListenableFuture as deprecated for removal in 6.0 and removed in 7.0.

See gh-33808
See gh-33809
See commit cb8ed43be1
Closes gh-36313
2026-02-12 13:19:06 +01:00
Sam Brannen cb8ed43be1 Stop referring to "JDK 8" features in documentation
See gh-36310
2026-02-12 12:27:51 +01:00
Juergen Hoeller 1703388074 Cache ResponseBody annotation presence per controller class
Closes gh-36311
2026-02-12 12:20:14 +01:00
Sam Brannen d84c4a39e2 Stop referring to "Java 8" features in documentation
Closes gh-36310
2026-02-12 12:11:02 +01:00
Sam Brannen 6f03c186b9 Polishing 2026-02-12 11:51:39 +01:00
Brian Clozel e10d37ad54 Next development version (v7.0.5-SNAPSHOT) 2026-02-12 10:39:15 +01:00
Juergen Hoeller 4734837fe4 Upgrade to Netty 4.2.10, Hibernate ORM 7.2.4, Checkstyle 13.2 2026-02-11 22:41:52 +01:00
Juergen Hoeller 4a13655aa5 Polishing 2026-02-11 19:22:27 +01:00
Brian Clozel 5ef9972528 Allow to disable defaults in HttpMessageConverters
The builder for `HttpMessageConverters` allows for auto-detection of
message converters on the classpath and their default registration when
`registerDefaults()` is called. Once called, there is no way to undo
this.

This commit adds a new `disableDefaults()` method to disable the default
registration and take full control over the list of message converters.

Closes gh-36303
2026-02-11 18:37:12 +01:00
Christian Schuster a9b1d6335e avoid unnecessary locking in ConcurrentReferenceHashMap's implementation of computeIfAbsent and computeIfPresent
Signed-off-by: Christian Schuster <christian@dnup.de>
2026-02-11 17:53:26 +01:00
Sam Brannen 98d4046e4b Document that @⁠Validated & @⁠Lazy may be used as meta-annotations
See gh-36305
See gh-36306
2026-02-11 17:37:06 +01:00
Sam Brannen 282fee5c95 Consistently find @⁠Lazy as a meta-annotation at arbitrary depths
Prior to this commit, AnnotationConfigUtils looked up @⁠Lazy as a
meta-annotation at arbitrary depths (e.g., when used as a
meta-meta-annotation); however,
ContextAnnotationAutowireCandidateResolver only found @Lazy as a
"directly present" meta-annotation.

For consistency, this commit revises
ContextAnnotationAutowireCandidateResolver so that it also finds @⁠Lazy
as a meta-annotation at arbitrary depths.

Closes gh-36306
2026-02-11 17:33:15 +01:00
Sam Brannen 0d4737aeec Polishing 2026-02-11 17:26:15 +01:00