diff --git a/.editorconfig b/.editorconfig
new file mode 100644
index 0000000..7a57675
--- /dev/null
+++ b/.editorconfig
@@ -0,0 +1,14 @@
+# https://editorconfig.org
+root = true
+
+[*]
+charset = utf-8
+end_of_line = lf
+
+[*.{java,py}]
+indent_style = space
+indent_size = 4
+
+[*.{yml,yaml}]
+indent_style = space
+indent_size = 2
diff --git a/.gitattributes b/.gitattributes
new file mode 100644
index 0000000..26113f5
--- /dev/null
+++ b/.gitattributes
@@ -0,0 +1,15 @@
+# Normalize text to LF in the repository and working tree.
+* text=auto eol=lf
+
+# Windows command scripts (for example a future Maven wrapper) need CRLF.
+*.cmd text eol=crlf
+*.bat text eol=crlf
+
+# Binary files: never convert or diff as text.
+*.jar binary
+*.class binary
+*.jpg binary
+*.jpeg binary
+*.png binary
+*.gif binary
+*.ico binary
diff --git a/.gitignore b/.gitignore
index adc5f64..110f9aa 100644
--- a/.gitignore
+++ b/.gitignore
@@ -1,5 +1,5 @@
-*/target/**
-/target/**
+# Maven build output in every module
+target/
# Intellij project files
*.iml
*.ipr
@@ -15,12 +15,6 @@ maven-eclipse.xml
nb-configuration.xml
*/nbproject/*
-/jsp/target/
-/esapi/target/
-/target/
-/jakarta/target/
-/jakarta-test/target/
-
# Python CI/compatibility tooling
__pycache__/
*.pyc
diff --git a/META-INF/MANIFEST.MF b/META-INF/MANIFEST.MF
deleted file mode 100644
index 2aaee67..0000000
--- a/META-INF/MANIFEST.MF
+++ /dev/null
@@ -1,9 +0,0 @@
-Manifest-Version: 1.0
-Bnd-LastModified: 1533328833261
-Bundle-ManifestVersion: 2
-Bundle-Name: org.owasp.encoder
-Bundle-SymbolicName: org.owasp.encoder
-Bundle-Version: 1.2.1
-Created-By: 1.8.0_181 (Oracle Corporation)
-Export-Package: org.owasp.encoder
-Tool: Bnd-1.50.0
diff --git a/compatibility/consumers.py b/compatibility/consumers.py
index 1bc5752..28b537a 100644
--- a/compatibility/consumers.py
+++ b/compatibility/consumers.py
@@ -147,6 +147,18 @@ def metadata(kind, jar, core):
print('Metadata passed:', jar.name)
+def check_sources_jar(kind, jar):
+ """The published sources JAR must carry the Java 9 module descriptor source."""
+ source_jar = ROOT / kind / 'target' / (jar.name[:-len('.jar')] + '-sources.jar')
+ with zipfile.ZipFile(source_jar) as archive:
+ names = archive.namelist()
+ assert 'module-info.java' in names, (source_jar, 'missing module-info.java')
+ assert not any(name.endswith('.class') for name in names), source_jar
+ package = ARTIFACTS[kind][3].replace('.', '/') + '/'
+ assert any(name.startswith(package) and name.endswith('.java') for name in names), source_jar
+ print('Sources passed:', source_jar.name)
+
+
def prepare(args):
out = args.directory.resolve()
if out.exists() and any(out.iterdir()):
@@ -167,6 +179,7 @@ def prepare(args):
shutil.copy2(candidates[0], target)
jars[kind] = target
for kind, jar in jars.items(): metadata(kind, jar, jars['core'])
+ for kind, jar in jars.items(): check_sources_jar(kind, jar)
run('javac', '--release', '9', '-d', out / 'metadata', SOURCE / 'ModuleMetadata.java')
run('java', '-cp', out / 'metadata', 'consumer.ModuleMetadata', *jars.values())
# javac's module discovery does not honor the runtime multi-release property.
diff --git a/core/pom.xml b/core/pom.xml
index 7893375..520c4eb 100644
--- a/core/pom.xml
+++ b/core/pom.xml
@@ -1,132 +1,132 @@
-
-
-
-
- 4.0.0
-
-
- org.owasp.encoder
- encoder-parent
- 1.5.0-SNAPSHOT
-
-
- encoder
- jar
-
- Java Encoder
-
- The OWASP Encoders package is a collection of high-performance low-overhead
- contextual encoders, that when utilized correctly, is an effective tool in
- preventing Web Application security vulnerabilities such as Cross-Site
- Scripting.
-
-
-
- org.owasp.encoder
- org.owasp.encoder
-
-
-
-
-
- org.apache.felix
- org.apache.felix.framework
- 5.6.12
- test
-
-
-
- com.fasterxml.jackson.core
- jackson-databind
- 2.22.3
- test
-
-
-
- org.jsoup
- jsoup
- 1.23.2
- test
-
-
-
-
-
-
-
- org.apache.maven.plugins
- maven-jar-plugin
-
-
- reactor-jar
- process-classes
-
- jar
-
-
-
-
- default-jar
- none
-
- jar
-
-
-
-
-
- org.apache.maven.plugins
- maven-failsafe-plugin
-
-
- ${project.build.directory}/${project.build.finalName}.jar
-
-
-
-
- osgi-compatibility
-
- integration-test
- verify
-
-
-
-
-
-
-
+
+
+
+
+ 4.0.0
+
+
+ org.owasp.encoder
+ encoder-parent
+ 1.5.0-SNAPSHOT
+
+
+ encoder
+ jar
+
+ Java Encoder
+
+ The OWASP Encoders package is a collection of high-performance low-overhead
+ contextual encoders, that when utilized correctly, is an effective tool in
+ preventing Web Application security vulnerabilities such as Cross-Site
+ Scripting.
+
+
+
+ org.owasp.encoder
+ org.owasp.encoder
+
+
+
+
+
+ org.apache.felix
+ org.apache.felix.framework
+ 5.6.12
+ test
+
+
+
+ com.fasterxml.jackson.core
+ jackson-databind
+ 2.22.3
+ test
+
+
+
+ org.jsoup
+ jsoup
+ 1.23.2
+ test
+
+
+
+
+
+
+
+ org.apache.maven.plugins
+ maven-jar-plugin
+
+
+ reactor-jar
+ process-classes
+
+ jar
+
+
+
+
+ default-jar
+ none
+
+ jar
+
+
+
+
+
+ org.apache.maven.plugins
+ maven-failsafe-plugin
+
+
+ ${project.build.directory}/${project.build.finalName}.jar
+
+
+
+
+ osgi-compatibility
+
+ integration-test
+ verify
+
+
+
+
+
+
+
diff --git a/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java b/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java
index e904ee1..6850f0c 100644
--- a/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java
+++ b/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java
@@ -41,6 +41,12 @@
* @author Jeff Ichnowski
*/
public class UnsupportedContextException extends RuntimeException {
+ /**
+ * The value the JVM computed for every released version (1.2 through
+ * 1.4.0), declared explicitly so serialized instances stay compatible.
+ */
+ private static final long serialVersionUID = -1517019963198920181L;
+
/**
* Sole constructor.
*
diff --git a/core/src/site/site.xml b/core/src/site/site.xml
index 1b3cb62..174eb2f 100644
--- a/core/src/site/site.xml
+++ b/core/src/site/site.xml
@@ -1,4 +1,4 @@
-
+
+ default-compile
+
+
+ ${project.basedir}/src/main/java
+
+
+
compile-java-9
compile
@@ -438,6 +453,25 @@
+
+ org.codehaus.mojo
+ build-helper-maven-plugin
+
+
+
+ add-java9-sources
+ generate-sources
+
+ add-source
+
+
+
+ ${project.basedir}/src/main/java9
+
+
+
+
+
org.apache.maven.plugins
maven-source-plugin
@@ -457,6 +491,9 @@
8
true
+
+ module-info.java
+
@@ -565,6 +602,9 @@
8
true
+
+ module-info.java
+
diff --git a/src/main/config/checkstyle.xml b/src/main/config/checkstyle.xml
index 0a5f0da..6656e95 100644
--- a/src/main/config/checkstyle.xml
+++ b/src/main/config/checkstyle.xml
@@ -1,4 +1,4 @@
-
+