32593 Commits

Author SHA1 Message Date
Brian Clozel 4e35a12209 Release v6.2.17 v6.2.17 2026-03-13 08:43:16 +01:00
Sébastien Deleuze 317a1f9909 Leverage ResourceHandlerUtils in ScriptTemplateView
This commit apply extra checks to ScriptTemplateView resource handling
with ResourceHandlerUtils, consistently with what is done with static
resource handling.

Closes gh-36459
2026-03-12 20:02:59 +01:00
Sébastien Deleuze de6601fdac Restore ScriptTemplateViewTests
Restore both WebMVC and WebFlux variants that were deleted
by mistake in commit 4db2f8ea1b.

This commit also removes the empty resource loader path, as it is not
needed for the main WEB-INF/ use case that is typically configured
explicitly by the user, and not needed to pass the restored tests.

Closes gh-36457
2026-03-12 19:53:26 +01:00
Sam Brannen 47dc1c4d93 Fix log message in ConfigurationClassBeanDefinitionReader
The log message now properly generates the fully-qualified method name
and includes the resolved bean name as well.

Closes gh-36453

(cherry picked from commit e634ced56b)
2026-03-12 16:25:03 +01:00
Juergen Hoeller d8c77934ff Upgrade to SnakeYAML 2.6, Protobuf 4.34, H2 2.4.240
(cherry picked from commit d8216d719b)
2026-03-11 15:55:42 +01:00
Juergen Hoeller 99fbce1254 Polishing (aligned with main) 2026-03-11 15:08:12 +01:00
Juergen Hoeller d1e69a9677 Upgrade to Reactor 2024.0.16 and Micrometer 1.15.10
Includes Jetty 12.0.33, Selenium 4.41, Mockito 5.22

Closes gh-36445
Closes gh-36446
2026-03-10 20:26:44 +01:00
Brian Clozel 8dc888e1b8 Guard against invalid id/event values in Server Sent Events
Prior to this commit, our implementation of Server Sent Events (SSE),
`SseEmitter` (MVC) and `ServerSentEvent` (WebFlux), would not guard
against invalid characters if the application mistakenly inserts such
characters in the `id` or `event` types.
Both implementations would also behave differently when it comes
to escaping comment multi-line events.

This commit ensures that both implementations handle multi-line comment
events and reject invalid characters in id/event types.
This commit also optimizes `String` concatenation and memory usage
when writing data.

Fixes gh-36440
2026-03-10 17:56:39 +01:00
Sam Brannen 131f94fbc5 Use link for first reference to @⁠Fallback in @⁠Bean Javadoc
See gh-36439

(cherry picked from commit 37e8aa76e9)
2026-03-10 17:54:05 +01:00
Sam Brannen d4f4c69318 Document @Fallback alongside Primary in the reference docs and @Bean Javadoc
Closes gh-36439

(cherry picked from commit 27686dc2e2)
2026-03-10 17:28:49 +01:00
Sam Brannen 74ab6625ac Document registration recommendations for BeanPostProcessor and BeanFactoryPostProcessor
Closes gh-34964

(cherry picked from commit 3b8efbe5a6)
2026-03-10 13:09:35 +01:00
Sam Brannen 7c27183a4f Polishing
(cherry picked from commit 6f2e59a995)
2026-03-10 13:09:26 +01:00
Sam Brannen 526f67cd83 Polish @⁠Bean Javadoc and reference docs
(cherry picked from commit 644a20ae2a)
2026-03-10 13:09:17 +01:00
Sam Brannen 88f081b1cd Resolve context initializers only once in AbstractTestContextBootstrapper
The internal buildMergedContextConfiguration() method in
AbstractTestContextBootstrapper originally resolved the
ApplicationContextInitializer set only once. However, the changes made
in commit 2244461778 introduced a regression resulting in the
initializers being resolved twice: once for validation and once for
actually building the merged context configuration. In addition, the
resolution for validation does not honor the inheritInitializers flag
in ContextConfigurationAttributes.

To address these issues, buildMergedContextConfiguration() once again
resolves the context initializers once via
ApplicationContextInitializerUtils.resolveInitializerClasses().

See gh-18528
Closes gh-36430

(cherry picked from commit 463138acbc)
2026-03-08 14:50:42 +01:00
Sam Brannen 5806a23bcf Address Checkstyle violation
(cherry picked from commit bbe733def7)
2026-03-05 11:44:13 +01:00
Sam Brannen 507399d9a8 Polish documentation for FrameworkServlet and HttpServletBean
(cherry picked from commit 50c29e64f8)
2026-03-05 11:25:11 +01:00
Juergen Hoeller cd9a430869 Polishing
(cherry picked from commit 4734c15d81)
2026-03-03 23:38:55 +01:00
Sam Brannen 0a933787a6 Exclude legacy @⁠javax.validation.Constraint from attribute override check
Prior to this commit, we only excluded @⁠jakarta.validation.Constraint
from the convention-based annotation attribute override check.

This commit additionally excludes the legacy
@⁠javax.validation.Constraint annotation from the convention-based
annotation attribute override check.

See gh-28760
See gh-28761
Closes gh-36412
2026-03-03 17:02:13 +01:00
cetf 2bbea84830 Fix format string argument count
Fixes: gh-36410
Signed-off-by: cetf <cetf9h@163.com>
2026-03-03 12:15:12 +01:00
dependabot[bot] b9517b8ed7 Upgrade fast-xml-parser to 5.3.8
Closes gh-36402

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

(cherry picked from commit a87b2e0146)
2026-03-01 13:14:49 +01:00
Sam Brannen f41786b6af Fix typo
(cherry picked from commit bd40f0e6bb)
2026-03-01 13:06:56 +01:00
Sam Brannen 2d10d513e1 Consistently refer to URLs and URIs in documentation
(cherry picked from commit 04186fdf0e)
2026-03-01 13:06:56 +01:00
Tran Ngoc Nhan c83fb69d9b Fix links to UriComponentsBuilder and polish examples
Closes gh-36403

Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com>

(cherry picked from commit b2b731b0ba)
2026-03-01 13:06:51 +01:00
Juergen Hoeller 566a42bec9 Remove prefixed FactoryBean name in ApplicationListenerDetector
Closes gh-36404

(cherry picked from commit a3b9098850)
2026-03-01 12:10:44 +01:00
Juergen Hoeller b426ef2d1b Polishing 2026-02-28 19:45:22 +01:00
Juergen Hoeller 728466dce0 Cancel late-executing tasks within revised closed handling
Closes gh-36362

(cherry picked from commit b6833ff31f)
2026-02-28 13:56:34 +01:00
Sam Brannen 455cb766a9 Further emphasize @⁠Configuration classes over XML and Groovy in testing chapter
See gh-36393

(cherry picked from commit 9eea227ab9)
2026-02-25 15:49:19 +01:00
Sam Brannen c77993acac Emphasize @⁠Configuration classes over XML and Groovy in testing chapter
Closes gh-36393

(cherry picked from commit 706c98228d)
2026-02-25 15:27:25 +01:00
Sam Brannen f3d0f9427a Upgrade to JUnit 5.14.3
Closes gh-36388
2026-02-25 11:00:24 +01:00
dependabot[bot] 688975e327 Upgrade fast-xml-parser to 5.3.6
Closes gh-36348

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
(cherry picked from commit ee6a115a18)
2026-02-25 10:29:02 +01:00
Juergen Hoeller b619e69130 Polishing (aligned with main) 2026-02-24 18:04:40 +01:00
Juergen Hoeller 972ba739aa Reject late-executing tasks after termination waiting
Closes gh-36362

(cherry picked from commit cff48fff2d)
2026-02-24 17:58:18 +01:00
Sam Brannen f87b5ee326 Polish contribution
See gh-36367

(cherry picked from commit b1cb9c5052)
2026-02-23 17:33:15 +01:00
Tran Ngoc Nhan 7768cee7a0 Polish SpEL operator examples in reference docs
Closes gh-36367

Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com>
(cherry picked from commit 057633edb5)
2026-02-23 17:33:07 +01:00
rstoyanchev 9042682b56 Optimal charset handling in AbstractHttpMessageConverter
Closes gh-36320
2026-02-23 15:44:26 +00:00
Brian Clozel 2d81a9fe9b Optimize MediaType(MediaType, Charset) constructor
Prior to this commit, the `MediaType` and `MimeType` "copy" constructors
would not leverage the fact that the existing instance has been
validated already (types, subtype and parameters have been checked
already for errors) and the entire validation would be performed again.
This would also allocate map instances in the process.

This commit ensures that the already validated information is reused
directly and that we avoid unnessecary operations and allocations for
such constructors.

Closes gh-36318
2026-02-23 15:40:18 +00:00
Brian Clozel a3f7179ab3 Fix InvalidMimeTypeException for compatible media types
The `AbstractMessageConverterMethodProcessor` is in charge of handling
controller method return values and to write those as HTTP response
messages. The content negotiation process is an important part.

The `MimeTypeUtils#sortBySpecificity` is in charge of sorting inbound
"Accept" media types by their specificity and reject them if the list
is too large, in order to protect the application from ddos attacks.

Prior to this commit, the content negotiation process would first get
the sorted "Accept" media types, the producible media types as
advertized by message converters - and collect the intersection of both
in a new list (also sorted by specificity). If the "Accept" list is
large enough (but under the limit), the list of compatible media types
could exceed that limit because duplicates could be introduced in that
list: several converters can produce the same content type.

This commit ensures that compatible media types are collected in a set
to avoid duplicates. Without that, exceeding the limit at this point
will throw an `InvalidMimeTypeException` that's not handled by the
processor and result in a server error.

Fixes gh-36300
2026-02-20 18:43:02 +01:00
rstoyanchev 50ef3b0a29 Update Javadoc of RestClient.Builder defaultStatusHandler
See gh-36248
2026-02-19 11:45:33 +00:00
Juergen Hoeller 1c7e79026f Skip serialization of potentially non-serializable cached state
Closes gh-36346

(cherry picked from commit 22bd8bd704)
2026-02-17 22:19:43 +01:00
Juergen Hoeller c8735efb9d Polishing (aligned with main) 2026-02-17 19:08:15 +01:00
Juergen Hoeller 999bbe3959 Polishing 2026-02-17 18:41:07 +01:00
Juergen Hoeller acab61f9a7 Consistent adaptation of HTTP headers on Servlet responses
Closes gh-36345
2026-02-17 18:40:50 +01:00
Juergen Hoeller bfa81290b3 Polishing 2026-02-17 12:18:31 +01:00
Juergen Hoeller 2c7ed5e5f1 Align validation groups check with InvocableHandlerMethod in spring-web
Closes gh-36337
2026-02-17 12:15:07 +01:00
Brian Clozel 474d520182 Fix MultipartParser & PartGenerator memory leak
Prior to this commit, the reactive `MultipartParser` and `PartGenerator`
types were leaking memory at runtime in specific cases:

* many HTTP clients must send multipart requests to be parsed and close
  the connection while uploading
* the `PartGenerator` must be configured to write file parts to
  temporary files on disk
* concurrency, upload speed must be important to trigger cases where the
  file system is not fast enough to consume incoming buffers

The `MultipartParser` parses and emits `BodyToken` to its sink
(here, the `PartGenerator`). By definition, Reactor's `FluxSink` when
created with `Flux.create(FluxSink)` will use a "buffer" strategy and
will queue emitted elements if they cannot be consumed.

Here, the cancellation signal does dispose internal states in the
`MultiPartParser` and `PartGenerator` but does not clear the internal
queue in `FluxSink`.

This commit ensures that an operation is registered to release buffers
on the discard event.

Fixes gh-36262
2026-02-13 18:45:05 +01:00
Juergen Hoeller 50bffe7ddc Detect all common size exceptions from Tomcat and Commons FileUpload 2.x
Closes gh-36317

(cherry picked from commit e8e24e65d2)
2026-02-13 16:32:56 +01:00
Brian Clozel 6d849bd9b0 Next development version (v6.2.17-SNAPSHOT) 2026-02-12 10:03:33 +01:00
Christian Schuster 8334388e20 avoid unnecessary locking in ConcurrentReferenceHashMap's implementation of computeIfAbsent and computeIfPresent
Signed-off-by: Christian Schuster <christian@dnup.de>

Closes gh-36308

(cherry picked from commit a9b1d6335e)
2026-02-11 18:08:59 +01:00
Brian Clozel 757b713f22 Use updated message in HttpEntityMethodProcessor
Prior to this commit, the `HttpEntityMethodProcessor` would create a new
`ServletServerHttpRequest` input message to parse the native Servlet
request, but would not reuse it for reading the request body using the
message converters.

In gh-32471, we applied a change that updates HTTP headers accordingly
when request parameters are read. But not reusing the input message
means that we are losing this update when instantiating the resulting
`HttpEntity`.

This commit ensures that `HttpEntityMethodProcessor` uses the input
message it just created when decoding the request body.

Fixes gh-36298
2026-02-11 14:07:21 +01:00
rstoyanchev a065563484 Optimize RequestMappingInfo hashcode calculation
Precalculated hashcode makes sense for infos in the registry, but
matched infos created on the fly don't need it.

Closes gh-36279
2026-02-11 09:42:01 +00:00