Upgrade to Tomcat 11.0.26

Closes gh-52002
This commit is contained in:
Stéphane Nicoll
2026-10-06 15:05:16 +02:00
parent ddb4fb7244
commit e0189c5355
6 changed files with 10 additions and 18 deletions
+1 -1
View File
@@ -23,6 +23,6 @@ nullabilityPluginVersion=0.0.15
snakeYamlVersion=2.5
springFrameworkVersion=7.0.10-SNAPSHOT
springFramework60xVersion=6.0.23
tomcatVersion=11.0.24
tomcatVersion=11.0.26
kotlin.stdlib.default.dependency=false
@@ -100,7 +100,7 @@ class JerseyAutoConfigurationServletContainerTests {
jerseyServlet.setOverridable(false);
context.addChild(jerseyServlet);
String pattern = UDecoder.URLDecode("/*", StandardCharsets.UTF_8);
context.addServletMappingDecoded(pattern, servletName);
context.addServletMapping(pattern, servletName);
}
};
@@ -753,8 +753,8 @@ public class TomcatServerProperties {
* Internal proxies that are to be trusted. Can be set as a comma separate list of
* CIDR or as a regular expression.
*/
private String internalProxies = "192.168.0.0/16, 172.16.0.0/12, 169.254.0.0/16, fc00::/7, "
+ "10.0.0.0/8, 100.64.0.0/10, 127.0.0.0/8, fe80::/10, ::1/128";
private String internalProxies = "10.0.0.0/8, 192.168.0.0/16, 169.254.0.0/16, 100.64.0.0/10, "
+ "fc00::/7, 172.16.0.0/12, ::1/128, 127.0.0.0/8, fe80::/10";
/**
* Header that holds the incoming protocol, usually named "X-Forwarded-Proto".
@@ -91,7 +91,7 @@ public class TomcatReactiveWebServerFactory extends TomcatWebServerFactory
loader.setDelegate(true);
context.setLoader(loader);
Tomcat.addServlet(context, "httpHandlerServlet", servlet).setAsyncSupported(true);
context.addServletMappingDecoded("/", "httpHandlerServlet");
context.addServletMapping("/", "httpHandlerServlet");
host.addChild(context);
configureContext(context);
}
@@ -255,7 +255,7 @@ public class TomcatServletWebServerFactory extends TomcatWebServerFactory
// Otherwise the default location of a Spring DispatcherServlet cannot be set
defaultServlet.setOverridable(true);
context.addChild(defaultServlet);
context.addServletMappingDecoded("/", "default");
context.addServletMapping("/", "default");
}
private void addJspServlet(Context context) {
@@ -266,8 +266,8 @@ public class TomcatServletWebServerFactory extends TomcatWebServerFactory
this.settings.getJsp().getInitParameters().forEach(jspServlet::addInitParameter);
jspServlet.setLoadOnStartup(3);
context.addChild(jspServlet);
context.addServletMappingDecoded("*.jsp", "jsp");
context.addServletMappingDecoded("*.jspx", "jsp");
context.addServletMapping("*.jsp", "jsp");
context.addServletMapping("*.jspx", "jsp");
}
private void addJasperInitializer(TomcatEmbeddedContext context) {
@@ -38,7 +38,6 @@ import org.springframework.boot.autoconfigure.web.WebProperties;
import org.springframework.boot.context.properties.bind.Bindable;
import org.springframework.boot.context.properties.bind.Binder;
import org.springframework.boot.context.properties.source.ConfigurationPropertySources;
import org.springframework.boot.testsupport.classpath.ClassPathOverrides;
import org.springframework.boot.testsupport.web.servlet.DirtiesUrlFactories;
import org.springframework.boot.tomcat.TomcatWebServer;
import org.springframework.boot.tomcat.servlet.TomcatServletWebServerFactory;
@@ -50,7 +49,6 @@ import org.springframework.test.context.support.TestPropertySourceUtils;
import org.springframework.util.unit.DataSize;
import static org.assertj.core.api.Assertions.assertThat;
import static org.assertj.core.api.Assertions.assertThatNoException;
/**
* Tests for {@link TomcatWebServerFactoryCustomizer}
@@ -212,12 +210,6 @@ class TomcatWebServerFactoryCustomizerTests {
(server) -> assertThat(server.getTomcat().getConnector().getMaxPartHeaderSize()).isEqualTo(4096));
}
@Test
@ClassPathOverrides("org.apache.tomcat.embed:tomcat-embed-core:11.0.7")
void customizerIsCompatibleWithTomcatVersionsWithoutMaxPartCountAndMaxPartHeaderSize() {
assertThatNoException().isThrownBy(this::customizeAndRunServer);
}
@Test
void defaultMaxHttpRequestHeaderSize() {
customizeAndRunServer((server) -> assertThat(
@@ -440,8 +432,8 @@ class TomcatWebServerFactoryCustomizerTests {
assertThat(remoteIpValve.getRemoteIpHeader()).isEqualTo("X-Forwarded-For");
assertThat(remoteIpValve.getHostHeader()).isEqualTo("X-Forwarded-Host");
assertThat(remoteIpValve.getPortHeader()).isEqualTo("X-Forwarded-Port");
String expectedInternalProxies = "192.168.0.0/16, 172.16.0.0/12, 169.254.0.0/16, fc00::/7, 10.0.0.0/8, "
+ "100.64.0.0/10, 127.0.0.0/8, fe80::/10, ::1/128";
String expectedInternalProxies = "10.0.0.0/8, 192.168.0.0/16, 169.254.0.0/16, 100.64.0.0/10, fc00::/7, "
+ "172.16.0.0/12, ::1/128, 127.0.0.0/8, fe80::/10";
assertThat(remoteIpValve.getInternalProxies()).isEqualTo(expectedInternalProxies);
}