From e0189c53559bb1b4496524fec2e83fb57d0862c0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?St=C3=A9phane=20Nicoll?= Date: Tue, 6 Oct 2026 14:30:03 +0200 Subject: [PATCH] Upgrade to Tomcat 11.0.26 Closes gh-52002 --- gradle.properties | 2 +- ...JerseyAutoConfigurationServletContainerTests.java | 2 +- .../tomcat/autoconfigure/TomcatServerProperties.java | 4 ++-- .../reactive/TomcatReactiveWebServerFactory.java | 2 +- .../servlet/TomcatServletWebServerFactory.java | 6 +++--- .../TomcatWebServerFactoryCustomizerTests.java | 12 ++---------- 6 files changed, 10 insertions(+), 18 deletions(-) diff --git a/gradle.properties b/gradle.properties index b53ea936117..8d9d6a39d00 100644 --- a/gradle.properties +++ b/gradle.properties @@ -23,6 +23,6 @@ nullabilityPluginVersion=0.0.15 snakeYamlVersion=2.5 springFrameworkVersion=7.0.10-SNAPSHOT springFramework60xVersion=6.0.23 -tomcatVersion=11.0.24 +tomcatVersion=11.0.26 kotlin.stdlib.default.dependency=false diff --git a/module/spring-boot-jersey/src/test/java/org/springframework/boot/jersey/autoconfigure/JerseyAutoConfigurationServletContainerTests.java b/module/spring-boot-jersey/src/test/java/org/springframework/boot/jersey/autoconfigure/JerseyAutoConfigurationServletContainerTests.java index 5eeab6d9945..215a883df1e 100644 --- a/module/spring-boot-jersey/src/test/java/org/springframework/boot/jersey/autoconfigure/JerseyAutoConfigurationServletContainerTests.java +++ b/module/spring-boot-jersey/src/test/java/org/springframework/boot/jersey/autoconfigure/JerseyAutoConfigurationServletContainerTests.java @@ -100,7 +100,7 @@ class JerseyAutoConfigurationServletContainerTests { jerseyServlet.setOverridable(false); context.addChild(jerseyServlet); String pattern = UDecoder.URLDecode("/*", StandardCharsets.UTF_8); - context.addServletMappingDecoded(pattern, servletName); + context.addServletMapping(pattern, servletName); } }; diff --git a/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/autoconfigure/TomcatServerProperties.java b/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/autoconfigure/TomcatServerProperties.java index 90c6e551820..882194189a2 100644 --- a/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/autoconfigure/TomcatServerProperties.java +++ b/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/autoconfigure/TomcatServerProperties.java @@ -753,8 +753,8 @@ public class TomcatServerProperties { * Internal proxies that are to be trusted. Can be set as a comma separate list of * CIDR or as a regular expression. */ - private String internalProxies = "192.168.0.0/16, 172.16.0.0/12, 169.254.0.0/16, fc00::/7, " - + "10.0.0.0/8, 100.64.0.0/10, 127.0.0.0/8, fe80::/10, ::1/128"; + private String internalProxies = "10.0.0.0/8, 192.168.0.0/16, 169.254.0.0/16, 100.64.0.0/10, " + + "fc00::/7, 172.16.0.0/12, ::1/128, 127.0.0.0/8, fe80::/10"; /** * Header that holds the incoming protocol, usually named "X-Forwarded-Proto". diff --git a/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/reactive/TomcatReactiveWebServerFactory.java b/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/reactive/TomcatReactiveWebServerFactory.java index 0d52aa95c49..0de918ff58d 100644 --- a/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/reactive/TomcatReactiveWebServerFactory.java +++ b/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/reactive/TomcatReactiveWebServerFactory.java @@ -91,7 +91,7 @@ public class TomcatReactiveWebServerFactory extends TomcatWebServerFactory loader.setDelegate(true); context.setLoader(loader); Tomcat.addServlet(context, "httpHandlerServlet", servlet).setAsyncSupported(true); - context.addServletMappingDecoded("/", "httpHandlerServlet"); + context.addServletMapping("/", "httpHandlerServlet"); host.addChild(context); configureContext(context); } diff --git a/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/servlet/TomcatServletWebServerFactory.java b/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/servlet/TomcatServletWebServerFactory.java index 5297b1fb096..38dcd7d1210 100644 --- a/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/servlet/TomcatServletWebServerFactory.java +++ b/module/spring-boot-tomcat/src/main/java/org/springframework/boot/tomcat/servlet/TomcatServletWebServerFactory.java @@ -255,7 +255,7 @@ public class TomcatServletWebServerFactory extends TomcatWebServerFactory // Otherwise the default location of a Spring DispatcherServlet cannot be set defaultServlet.setOverridable(true); context.addChild(defaultServlet); - context.addServletMappingDecoded("/", "default"); + context.addServletMapping("/", "default"); } private void addJspServlet(Context context) { @@ -266,8 +266,8 @@ public class TomcatServletWebServerFactory extends TomcatWebServerFactory this.settings.getJsp().getInitParameters().forEach(jspServlet::addInitParameter); jspServlet.setLoadOnStartup(3); context.addChild(jspServlet); - context.addServletMappingDecoded("*.jsp", "jsp"); - context.addServletMappingDecoded("*.jspx", "jsp"); + context.addServletMapping("*.jsp", "jsp"); + context.addServletMapping("*.jspx", "jsp"); } private void addJasperInitializer(TomcatEmbeddedContext context) { diff --git a/module/spring-boot-tomcat/src/test/java/org/springframework/boot/tomcat/autoconfigure/TomcatWebServerFactoryCustomizerTests.java b/module/spring-boot-tomcat/src/test/java/org/springframework/boot/tomcat/autoconfigure/TomcatWebServerFactoryCustomizerTests.java index 22490800481..3ce86476fe6 100644 --- a/module/spring-boot-tomcat/src/test/java/org/springframework/boot/tomcat/autoconfigure/TomcatWebServerFactoryCustomizerTests.java +++ b/module/spring-boot-tomcat/src/test/java/org/springframework/boot/tomcat/autoconfigure/TomcatWebServerFactoryCustomizerTests.java @@ -38,7 +38,6 @@ import org.springframework.boot.autoconfigure.web.WebProperties; import org.springframework.boot.context.properties.bind.Bindable; import org.springframework.boot.context.properties.bind.Binder; import org.springframework.boot.context.properties.source.ConfigurationPropertySources; -import org.springframework.boot.testsupport.classpath.ClassPathOverrides; import org.springframework.boot.testsupport.web.servlet.DirtiesUrlFactories; import org.springframework.boot.tomcat.TomcatWebServer; import org.springframework.boot.tomcat.servlet.TomcatServletWebServerFactory; @@ -50,7 +49,6 @@ import org.springframework.test.context.support.TestPropertySourceUtils; import org.springframework.util.unit.DataSize; import static org.assertj.core.api.Assertions.assertThat; -import static org.assertj.core.api.Assertions.assertThatNoException; /** * Tests for {@link TomcatWebServerFactoryCustomizer} @@ -212,12 +210,6 @@ class TomcatWebServerFactoryCustomizerTests { (server) -> assertThat(server.getTomcat().getConnector().getMaxPartHeaderSize()).isEqualTo(4096)); } - @Test - @ClassPathOverrides("org.apache.tomcat.embed:tomcat-embed-core:11.0.7") - void customizerIsCompatibleWithTomcatVersionsWithoutMaxPartCountAndMaxPartHeaderSize() { - assertThatNoException().isThrownBy(this::customizeAndRunServer); - } - @Test void defaultMaxHttpRequestHeaderSize() { customizeAndRunServer((server) -> assertThat( @@ -440,8 +432,8 @@ class TomcatWebServerFactoryCustomizerTests { assertThat(remoteIpValve.getRemoteIpHeader()).isEqualTo("X-Forwarded-For"); assertThat(remoteIpValve.getHostHeader()).isEqualTo("X-Forwarded-Host"); assertThat(remoteIpValve.getPortHeader()).isEqualTo("X-Forwarded-Port"); - String expectedInternalProxies = "192.168.0.0/16, 172.16.0.0/12, 169.254.0.0/16, fc00::/7, 10.0.0.0/8, " - + "100.64.0.0/10, 127.0.0.0/8, fe80::/10, ::1/128"; + String expectedInternalProxies = "10.0.0.0/8, 192.168.0.0/16, 169.254.0.0/16, 100.64.0.0/10, fc00::/7, " + + "172.16.0.0/12, ::1/128, 127.0.0.0/8, fe80::/10"; assertThat(remoteIpValve.getInternalProxies()).isEqualTo(expectedInternalProxies); }