Skip to content

Complete forUri deprecation across registry and tag APIs without removing 1.x support #130

Description

@jmanico

Reviewed 2026-09-25 (America/Los_Angeles) against main at bd249f5. Execution order and cross-issue ownership: #169. Batch 01.

This scope replaces the dated implementation prescriptions in the original report and earlier comments; linked historical evidence remains useful but must be rechecked before implementation.

Current state and scope

#161 already clarified Encode and TLD context guidance. Re-audit current Javadocs/TLDs rather than repeating that work. Remaining API surfaces include Encoders.URI, Encoders.forName("uri"), and the JSP/Jakarta ForUriTag classes.

Completed in batch 01

Contributor PR #170 was reviewed, approved, and merged as 98608dd52c46e4f250e5eff4d3a6fda218a22dd3, with all 20 checks passing. Coordinated follow-up #172 merged as fe5e0ad174481c2f23a566aa33069a0e45562785, also with all 20 checks passing, completing the URL/context guidance alongside #100.

Encoders.URI, both ForUriTag classes, and all eight legacy tag/function descriptions now carry deprecation guidance. Encoders.forName("uri") remains recognized. Existing methods, tag names/URIs, and core/registry/tag runtime output remain intact throughout 1.x; a regression checks retained facade/Writer/registry output. Generated Javadoc deprecation descriptions and the public adapter contract were inspected, 31-file JSP/Jakarta parity passed, and deprecation diagnostics remain nonfatal. Shared migration guidance explicitly separates component encoding, application URL validation, and enclosing-context encoding; supplied to #128. Removal remains a decision in #142.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: encodingOutput-context API semantics and migration guidance.documentationenhancementpriority: P1High priority: security contracts, CI protection or consumer compatibility.security-reviewSecurity-sensitive scope or acceptance criteria; not a vulnerability classification.triage: readyScope reviewed; actionable within its batch, subject to the normal PR process.

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions