Commit Graph
32682 Commits
Author SHA1 Message Date
dependabot[bot] 89ecaea937 Upgrade fast-xml-parser to 5.7.0
Closes gh-36691

(cherry picked from commit ac24766510)
2026-05-20 16:54:45 +02:00
Juergen Hoeller 444877a475 Polishing
(cherry picked from commit 8fe1de4595)
2026-05-13 19:57:29 +02:00
Juergen Hoeller 57b62dd73a Restrict SpringVersion.getVersion() to "major.minor.patch" format
Closes gh-36785

(cherry picked from commit c048074436)
2026-05-12 16:25:05 +02:00
Yanming Zhou 5f661f1b64 Fix typos for validateExistingTransaction
Closes gh-36767

Signed-off-by: Yanming Zhou <zhouyanming@gmail.com>

(cherry picked from commit cfb8dc6cc8)
2026-05-09 16:41:51 +02:00
Juergen Hoeller b0137977d8 Upgrade to Netty 4.1.133 2026-05-08 16:11:11 +02:00
Juergen Hoeller 425ce8625a Consistently expose map key quotes
Closes gh-36765

(cherry picked from commit d3152c11c7)
2026-05-08 16:10:16 +02:00
Juergen Hoeller 85c578b929 Avoid ResolvableType#forType contention for implicit cache cleanup
Closes gh-36745

(cherry picked from commit 856e1d5dc8)
2026-05-08 16:10:02 +02:00
Sam Brannen cf727bd7c8 Fix error message for invalid regex in SpEL
Closes gh-36756

(cherry picked from commit 987d6cca6d)
2026-05-06 13:55:18 +02:00
shenjianeng e8f08b4158 Refactor regex pattern caching using computeIfAbsent
Closes gh-36755

Signed-off-by: shenjianeng <ishenjianeng@qq.com>

(cherry picked from commit ec21dc0f91)
2026-05-06 13:55:03 +02:00
Brian Clozel c6b485c31d Do not warn against Root Servlet context location
Closes gh-36693
2026-05-05 11:54:02 +02:00
rstoyanchev b8ddd2c690 Avoid race in InMemoryWebSession
Closes gh-36742
2026-05-01 15:23:59 +01:00
rstoyanchev a42a6e0c6a Switch to JdkIdGenerator in AbstractWebSocketSession
Closes gh-36740
2026-05-01 14:23:00 +01:00
Brian Clozel 8a93a88962 Fix parsing failure for MIME types with quoted pairs
Prior to this commit, MIME types with parameter values that contain a
quoted pair would sometimes fail and parse an incomplete parameter
value.

This commit ensures that the quoted section of the parameter value is
correctly handled.

Fixes gh-36730
2026-04-30 16:26:12 +02:00
Juergen Hoeller fdcf4d50f0 Consistent wrapping of BeanCreationExceptions from instance suppliers
Closes gh-36725

(cherry picked from commit 08c5280843)
2026-04-30 14:50:04 +02:00
Juergen Hoeller 3c023114fb Polishing
(cherry picked from commit cd5fee5347)
2026-04-29 22:03:04 +02:00
Juergen Hoeller 8b5cbb7496 Detect custom deserialized NullValue instances
Closes gh-36727

(cherry picked from commit 916cb64581)
2026-04-29 22:02:13 +02:00
Brian Clozel a58fdeaf3f Fix PartGenerator token request while creating tmp file
Prior to this commit, the `PartGenerator` would allow requesting
additional part tokens while in the `CreateFileState`. This is invalid
as any new token emitted would be rejected and would fail the entire
process.
This would only happen if the tmp file creation is slow enough for a new
token to be parsed and emitted.

This commit ensures that no new part token is requested while creating
the temporary file.
This change also fixes lifecycle issues and ensures that buffer
resources are cleaned in case of errors.

Fixes gh-36694
2026-04-28 23:30:01 +02:00
Sigurd Gerke e4bfdfa229 Fix a regression on value class parameter handling
This commit fixes a regression introduced by gh-36449 for
nullable value class with an non-null value.

Closes gh-36720
Signed-off-by: Sigurd Gerke <sigurd.gerke@onedata.de>
2026-04-28 11:08:06 +02:00
Brian Clozel 46867fad81 Avoid cache collisions in CachingResourceResolver
Prior to this commit, there could be cache collisions in the
`CachingResourceResolver` because the cache key generation was
incomplete. This commit expands the cache key generation to avoid such
cases.

Fixes gh-36713
2026-04-28 09:30:39 +02:00
Sam Brannen 371dcc5c13 Upgrade to JUnit 5.14.4
Closes gh-36707
2026-04-27 14:09:59 +03:00
Yanming Zhou dc032c1e33 Remove unnecessary invocations of toString()
Closes gh-36709

Signed-off-by: Yanming Zhou <zhouyanming@gmail.com>

(cherry picked from commit bfb88cfc1c)
2026-04-27 14:06:20 +03:00
Yanming Zhou 626907bbfd Update copyright headers in remaining source files
Closes gh-36703

Signed-off-by: Yanming Zhou <zhouyanming@gmail.com>

(cherry picked from commit c4dfb24116)
2026-04-27 14:05:50 +03:00
Brian Clozel 8d51f47357 Enfoce single version removal in content versioning
Prior to this commit, content based version strategies would remove all
instances of the version string in the request path when trying to
resolve the original resource with the chain.
This can cause issues in rare cases where there is a collision between
the content version and some other version string in the request path.

Because this strategy is based on the contents of the file itself, we
should only remove the last instance of the version string and then
attempt to resolve the original file.

Fixes gh-36698
2026-04-23 15:08:06 +02:00
Brian Clozel fb0c78ae27 Warn against unsafe static resource locations
Prior to this commit, `ResourceHandlerUtils` would perform resource
location checks to ensure that the configured location is valid. This
commit also ensures that we log a WARN message if the application
chooses a well-known unsafe location like "classpath:" or the root
Servlet context for serving static resources.

Closes gh-36693
2026-04-23 10:47:34 +02:00
Juergen Hoeller 9f431e2eac Polishing
(cherry picked from commit 8965d9bccf)
2026-04-21 20:41:11 +02:00
Juergen Hoeller cba8f225d9 Consistently ignore exceptions for Xerces-specific properties
Closes gh-36682

(cherry picked from commit af7a5716e8)
2026-04-21 20:41:06 +02:00
Stéphane Nicoll 515152b645 Next development version (v6.2.19-SNAPSHOT) 2026-04-17 08:32:54 +02:00
Juergen Hoeller f6671e77e2 Upgrade to Reactor 2024.0.17 and Micrometer 1.15.11
Closes gh-36660
Closes gh-36661
2026-04-16 23:47:49 +02:00
rstoyanchev b338fdd99d Add doOnDiscard in MultipartHttpMessageReader
Closes gh-36563
2026-04-16 21:19:13 +01:00
Sam Brannen 4e3f264f34 Add missing tests for WebRequestDataBinder
See gh-36625

(cherry picked from commit 63817ce202)
2026-04-16 16:36:27 +02:00
Sam Brannen 9e0b83ead3 Polish WebRequestDataBinderTests
(cherry picked from commit 61bd79017f)
2026-04-16 16:36:18 +02:00
Sam Brannen af4b1229a5 Extract ServletRequestParameterPropertyValuesTests
(cherry picked from commit c9b88b4ebd)
2026-04-16 15:08:23 +02:00
Sam Brannen 623ccd1a4f Revise "Skip binding entirely when field is not allowed"
This commit reverts the changes made to WebDataBinder's doBind()
implementation in e4d03f6625 and instead implements the skipping logic
directly in checkFieldDefaults(), checkFieldMarkers(), and
adaptEmptyArrayIndices() by preemptively checking if the corresponding
field is allowed.

This commit also improves the Javadoc and adds missing tests.

See gh-36625
Fixes gh-36627

(cherry picked from commit 68c575ab14)
2026-04-16 15:08:09 +02:00
Sam Brannen 69068ba33d Further clarify semantics of HttpMethod.valueOf()
See gh-36652

(cherry picked from commit cb320468db)
2026-04-14 16:19:43 +02:00
angry2.k f182f9a76b Clarify semantics of HttpMethod.valueOf()
HttpMethod.valueOf() performs a case-sensitive lookup of predefined
HttpMethod constants. For example, valueOf("GET") resolves to
HttpMethod.GET, whereas valueOf("get") results in a newly created
HttpMethod instance.
Update the Javadoc to explicitly document this behavior.

See gh-36642
Closes gh-36652

Signed-off-by: angry-2k <edkev@kakao.com>

(cherry picked from commit df828458fa)
2026-04-14 16:19:35 +02:00
Sam Brannen 9d144487e7 Improve SpEL tests for Elvis and Ternary operators
(cherry picked from commit 21f3b964fe)
2026-04-12 14:31:15 +02:00
Sébastien Deleuze b07bc2cb99 Apply nullable value class fix to InvocableHandlerMethod
See gh-36643
2026-04-10 16:24:36 +02:00
T45K 57d4765131 Fix nullable value class handling in CoroutinesUtils
Closes gh-36643
Signed-off-by: T45K <tasktas9@gmail.com>
2026-04-10 16:22:55 +02:00
Brian Clozel cbdec804a5 Allow null id/event in ServerSentEvent
The builder itself does not allow `null` values so this shouldn't be
necessary, but because the offending change was introduced late in the
6.2.x line, we'll be more flexible here.

Fixes gh-36634
2026-04-10 14:43:29 +02:00
Sam Brannen 438b1011fe Revise documentation for @⁠ActiveProfiles and ActiveProfilesResolver
See gh-36269
See gh-36600

(cherry picked from commit 99b78adce3)
2026-04-09 12:59:42 +02:00
Mohak-Nagaraju c5e560574c Document that spring.profiles.active is ignored by @⁠ActiveProfiles
The Spring TestContext Framework does not honor the
`spring.profiles.active` system property when determining
active profiles for a test class if @⁠ActiveProfiles is
used.

This commit documents that behavior in the @⁠ActiveProfiles
and DefaultActiveProfilesResolver Javadoc, as well as in
the reference manual. A SystemPropertyActiveProfilesResolver
example is also added showing how to allow
`spring.profiles.active` to override @⁠ActiveProfiles.

See gh-36269
Closes gh-36600

Signed-off-by: Mohak Nagaraju <98132980+Mohak-Nagaraju@users.noreply.github.com>
(cherry picked from commit 644731c9f6)
2026-04-09 12:59:34 +02:00
Brian Clozel 589e58e400 Skip binding entirely when field is not allowed
Prior to this commit, fields that are not allowed for binding were
always skipped and would not be bound. But the field and default marker
support (with the "_" and "!" prefixes) would be still considered and
could trigger collection instantiation/autogrow.

While this does not cause unwanted binding, this allocates memory for no
reason. This commit revisits the binding algorithm to only consider
default and field marker support if the regular field is allowed.

Fixes gh-36627
2026-04-09 11:06:46 +02:00
Sam Brannen 6101419d80 Support @⁠Sql with DataSource wrapped in a TransactionAwareDataSourceProxy
Prior to this commit, SqlScriptsTestExecutionListener unwrapped data
sources wrapped in an InfrastructureProxy or a scoped proxy, but it did
not unwrap a data source wrapped in a TransactionAwareDataSourceProxy.
Consequently, the sameDataSource() check failed in the latter case,
preventing execution of @⁠Sql scripts.

To address that, this commit revises sameDataSource() to unwrap a
TransactionAwareDataSourceProxy as well, analogous to the
implementations of setDataSource() in DataSourceTransactionManager,
JpaTransactionManager, and HibernateTransactionManager.

Closes gh-36611

(cherry picked from commit 6251b2c0c9)
2026-04-09 10:36:55 +02:00
Juergen Hoeller 63cd96fa5f Revise target bean exception with consistent message formatting 2026-04-08 15:48:17 +02:00
Juergen Hoeller 923ec6a8e1 Upgrade to Groovy 4.0.31 and Mockito 5.23 2026-04-08 15:09:57 +02:00
Juergen Hoeller 241a7dca02 Polishing
(cherry picked from commit 1687d90a8c)
2026-04-08 15:09:33 +02:00
Juergen Hoeller d675132ac0 Improve SpringValidatorAdapter and MethodValidationAdapter performance
Closes gh-36621

(cherry picked from commit b8f1005897)
2026-04-08 13:57:27 +02:00
Juergen Hoeller 2801c7e23e Avoid MessageFormat rendering for exception messages in binding errors
Closes gh-36609

(cherry picked from commit 0150c4ba06)
2026-04-08 13:57:22 +02:00
Sam Brannen d356e7a238 Improve Javadoc for MergedAnnotations
(cherry picked from commit b560c7b85d)
2026-04-08 12:36:44 +02:00
Brian Clozel df198987e0 Allow unlimited caching in ContentCachingRequestWrapper
Prior to this commit the `ContentCachingRequestWrapper(HttpServletRequest)`
constructor was deprecated; this variant caches by default an unlimited
amount of data. The replacement
`ContentCachingRequestWrapper(HttpServletRequest, int)` allows such
behavior in 7.0 but that change has not been bacported to 6.2.x.

This commit ensures that the replacement constructor can be safely used
in 6.2.x, preparing for the 7.0.x upgrade.

Fixes gh-36620
2026-04-08 11:29:27 +02:00