Align SpEL's default max auto-grow size with Spring data binding

Prior to this commit, the SpelParserConfiguration constructors that
omit an explicit maximumAutoGrowSize left collection auto-growing
effectively unbounded, defaulting to Integer.MAX_VALUE. That default
was inconsistent with the auto-grow limit applied elsewhere in the
framework for data binding (see
DataBinder.DEFAULT_AUTO_GROW_COLLECTION_LIMIT).

To address that, this commit introduces a new
SpelParserConfiguration.DEFAULT_MAX_AUTO_GROW_SIZE constant (set to 256
to match DataBinder.DEFAULT_AUTO_GROW_COLLECTION_LIMIT) and switches
the constructors that previously hard-coded Integer.MAX_VALUE to use
this new default instead. Constructors that accept an explicit
maximumAutoGrowSize are unaffected.

In addition, SpelParserConfiguration now enforces that a user-supplied
maximumAutoGrowSize is not a negative value, consistent with the
preconditions already enforced for maximumExpressionLength,
maximumOperations, maximumBigPowerBits, and maximumNestingDepth. A
value of 0 remains supported (effectively disabling collection
auto-growing) and is now documented as such in the Javadoc.

The Spring Framework reference documentation has also been updated to
describe the new default, and tests have been added to IndexingTests to
verify the default, the ability to override it, and the new
precondition.

Closes gh-36995
This commit is contained in:
Sam Brannen
2026-08-21 14:11:04 +02:00
parent 68d438c9ff
commit fb240829b3
3 changed files with 102 additions and 9 deletions
@@ -554,6 +554,14 @@ Kotlin::
----
======
When collection auto-growing is enabled, a collection cannot automatically grow beyond
256 elements by default; however, the `maximumAutoGrowSize` value is configurable. This
default is aligned with `DataBinder.DEFAULT_AUTO_GROW_COLLECTION_LIMIT`, for consistency
with the auto-grow limit used for data binding in Spring MVC and Spring WebFlux. If you
create a `SpelExpressionParser` programmatically, you can specify a custom
`maximumAutoGrowSize` when creating the `SpelParserConfiguration` that you provide to the
`SpelExpressionParser`.
By default, a SpEL expression cannot contain more than 10,000 characters; however, the
`maxExpressionLength` is configurable. If you create a `SpelExpressionParser`
programmatically, you can specify a custom `maxExpressionLength` when creating the