mirror of
https://github.com/spring-projects/spring-framework.git
synced 2026-09-17 08:24:13 +00:00
Property accessors resolved via SpEL's ReflectivePropertyAccessor and DataBindingPropertyAccessor may be JavaBean-style accessors or plain accessor methods used to support data classes such as Java records and Kotlin data classes. However, neither accessor can determine, via reflection, whether such a method is a side-effect-free read or an action that happens to return a value. For example, File.delete() is a public method that returns a boolean and therefore looks like a plain "property". To better inform users, this commit updates the Javadoc for ReflectivePropertyAccessor, DataBindingPropertyAccessor, and SimpleEvaluationContext (as well as in the SpEL reference documentation) to clarify that restricting a SimpleEvaluationContext to read-only data binding governs only whether assignment to a property is permitted and does not guarantee that reading a property is free of side effects. The reference documentation's "Security Considerations" section now also defines what makes a method "accessor-shaped", with concrete examples of safe versus side-effecting methods that share that shape (for example, File.delete(), Queue.poll(), and AtomicInteger.incrementAndGet()). Building on that clarification, this commit introduces a new "Object Design" section to the SpEL reference documentation, analogous to the "Model Design" guidance for web data binding. This new section recommends that any object reachable from an untrusted SpEL expression (not only the root object) be a purpose-built, immutable type with a deliberately limited surface area, and that its accessor-shaped methods be audited for unsafe side effects. The new section also notes that reachability is transitive through both property navigation and indexing (for example, rootObject.child.grandchild or rootObject.items[0]). In any case, it remains the responsibility of the code that exposes a root object or other reachable object to an expression from an untrusted source to ensure that none of its accessor-shaped methods perform an unsafe action. Closes gh-37102