-
-
Notifications
You must be signed in to change notification settings - Fork 128
Complete forUri deprecation across registry and tag APIs without removing 1.x support #130
Copy link
Copy link
Closed
Labels
area: encodingOutput-context API semantics and migration guidance.Output-context API semantics and migration guidance.documentationenhancementpriority: P1High priority: security contracts, CI protection or consumer compatibility.High priority: security contracts, CI protection or consumer compatibility.security-reviewSecurity-sensitive scope or acceptance criteria; not a vulnerability classification.Security-sensitive scope or acceptance criteria; not a vulnerability classification.triage: readyScope reviewed; actionable within its batch, subject to the normal PR process.Scope reviewed; actionable within its batch, subject to the normal PR process.
Description
Activity
Metadata
Metadata
Assignees
Labels
area: encodingOutput-context API semantics and migration guidance.Output-context API semantics and migration guidance.documentationenhancementpriority: P1High priority: security contracts, CI protection or consumer compatibility.High priority: security contracts, CI protection or consumer compatibility.security-reviewSecurity-sensitive scope or acceptance criteria; not a vulnerability classification.Security-sensitive scope or acceptance criteria; not a vulnerability classification.triage: readyScope reviewed; actionable within its batch, subject to the normal PR process.Scope reviewed; actionable within its batch, subject to the normal PR process.
Reviewed 2026-09-25 (America/Los_Angeles) against
mainatbd249f5. Execution order and cross-issue ownership: #169. Batch 01.This scope replaces the dated implementation prescriptions in the original report and earlier comments; linked historical evidence remains useful but must be rechecked before implementation.
Current state and scope
#161 already clarified
Encodeand TLD context guidance. Re-audit current Javadocs/TLDs rather than repeating that work. Remaining API surfaces includeEncoders.URI,Encoders.forName("uri"), and the JSP/JakartaForUriTagclasses.@deprecatedtext; document registry lookup retention and mark all four TLD tag/function descriptions consistently.forUriComponent, application-level whole-URL validation/scheme restrictions, and encoding for the enclosing HTML context. Do not imply URI parsing alone validates a URL's use.Completed in batch 01
Contributor PR #170 was reviewed, approved, and merged as
98608dd52c46e4f250e5eff4d3a6fda218a22dd3, with all 20 checks passing. Coordinated follow-up #172 merged asfe5e0ad174481c2f23a566aa33069a0e45562785, also with all 20 checks passing, completing the URL/context guidance alongside #100.Encoders.URI, bothForUriTagclasses, and all eight legacy tag/function descriptions now carry deprecation guidance.Encoders.forName("uri")remains recognized. Existing methods, tag names/URIs, and core/registry/tag runtime output remain intact throughout 1.x; a regression checks retained facade/Writer/registry output. Generated Javadoc deprecation descriptions and the public adapter contract were inspected, 31-file JSP/Jakarta parity passed, and deprecation diagnostics remain nonfatal. Shared migration guidance explicitly separates component encoding, application URL validation, and enclosing-context encoding; supplied to #128. Removal remains a decision in #142.