diff --git a/.editorconfig b/.editorconfig new file mode 100644 index 0000000..7a57675 --- /dev/null +++ b/.editorconfig @@ -0,0 +1,14 @@ +# https://editorconfig.org +root = true + +[*] +charset = utf-8 +end_of_line = lf + +[*.{java,py}] +indent_style = space +indent_size = 4 + +[*.{yml,yaml}] +indent_style = space +indent_size = 2 diff --git a/.gitattributes b/.gitattributes new file mode 100644 index 0000000..26113f5 --- /dev/null +++ b/.gitattributes @@ -0,0 +1,15 @@ +# Normalize text to LF in the repository and working tree. +* text=auto eol=lf + +# Windows command scripts (for example a future Maven wrapper) need CRLF. +*.cmd text eol=crlf +*.bat text eol=crlf + +# Binary files: never convert or diff as text. +*.jar binary +*.class binary +*.jpg binary +*.jpeg binary +*.png binary +*.gif binary +*.ico binary diff --git a/.gitignore b/.gitignore index adc5f64..110f9aa 100644 --- a/.gitignore +++ b/.gitignore @@ -1,5 +1,5 @@ -*/target/** -/target/** +# Maven build output in every module +target/ # Intellij project files *.iml *.ipr @@ -15,12 +15,6 @@ maven-eclipse.xml nb-configuration.xml */nbproject/* -/jsp/target/ -/esapi/target/ -/target/ -/jakarta/target/ -/jakarta-test/target/ - # Python CI/compatibility tooling __pycache__/ *.pyc diff --git a/META-INF/MANIFEST.MF b/META-INF/MANIFEST.MF deleted file mode 100644 index 2aaee67..0000000 --- a/META-INF/MANIFEST.MF +++ /dev/null @@ -1,9 +0,0 @@ -Manifest-Version: 1.0 -Bnd-LastModified: 1533328833261 -Bundle-ManifestVersion: 2 -Bundle-Name: org.owasp.encoder -Bundle-SymbolicName: org.owasp.encoder -Bundle-Version: 1.2.1 -Created-By: 1.8.0_181 (Oracle Corporation) -Export-Package: org.owasp.encoder -Tool: Bnd-1.50.0 diff --git a/compatibility/consumers.py b/compatibility/consumers.py index 1bc5752..28b537a 100644 --- a/compatibility/consumers.py +++ b/compatibility/consumers.py @@ -147,6 +147,18 @@ def metadata(kind, jar, core): print('Metadata passed:', jar.name) +def check_sources_jar(kind, jar): + """The published sources JAR must carry the Java 9 module descriptor source.""" + source_jar = ROOT / kind / 'target' / (jar.name[:-len('.jar')] + '-sources.jar') + with zipfile.ZipFile(source_jar) as archive: + names = archive.namelist() + assert 'module-info.java' in names, (source_jar, 'missing module-info.java') + assert not any(name.endswith('.class') for name in names), source_jar + package = ARTIFACTS[kind][3].replace('.', '/') + '/' + assert any(name.startswith(package) and name.endswith('.java') for name in names), source_jar + print('Sources passed:', source_jar.name) + + def prepare(args): out = args.directory.resolve() if out.exists() and any(out.iterdir()): @@ -167,6 +179,7 @@ def prepare(args): shutil.copy2(candidates[0], target) jars[kind] = target for kind, jar in jars.items(): metadata(kind, jar, jars['core']) + for kind, jar in jars.items(): check_sources_jar(kind, jar) run('javac', '--release', '9', '-d', out / 'metadata', SOURCE / 'ModuleMetadata.java') run('java', '-cp', out / 'metadata', 'consumer.ModuleMetadata', *jars.values()) # javac's module discovery does not honor the runtime multi-release property. diff --git a/core/pom.xml b/core/pom.xml index 7893375..520c4eb 100644 --- a/core/pom.xml +++ b/core/pom.xml @@ -1,132 +1,132 @@ - - - - - 4.0.0 - - - org.owasp.encoder - encoder-parent - 1.5.0-SNAPSHOT - - - encoder - jar - - Java Encoder - - The OWASP Encoders package is a collection of high-performance low-overhead - contextual encoders, that when utilized correctly, is an effective tool in - preventing Web Application security vulnerabilities such as Cross-Site - Scripting. - - - - org.owasp.encoder - org.owasp.encoder - - - - - - org.apache.felix - org.apache.felix.framework - 5.6.12 - test - - - - com.fasterxml.jackson.core - jackson-databind - 2.22.3 - test - - - - org.jsoup - jsoup - 1.23.2 - test - - - - - - - - org.apache.maven.plugins - maven-jar-plugin - - - reactor-jar - process-classes - - jar - - - - - default-jar - none - - jar - - - - - - org.apache.maven.plugins - maven-failsafe-plugin - - - ${project.build.directory}/${project.build.finalName}.jar - - - - - osgi-compatibility - - integration-test - verify - - - - - - - + + + + + 4.0.0 + + + org.owasp.encoder + encoder-parent + 1.5.0-SNAPSHOT + + + encoder + jar + + Java Encoder + + The OWASP Encoders package is a collection of high-performance low-overhead + contextual encoders, that when utilized correctly, is an effective tool in + preventing Web Application security vulnerabilities such as Cross-Site + Scripting. + + + + org.owasp.encoder + org.owasp.encoder + + + + + + org.apache.felix + org.apache.felix.framework + 5.6.12 + test + + + + com.fasterxml.jackson.core + jackson-databind + 2.22.3 + test + + + + org.jsoup + jsoup + 1.23.2 + test + + + + + + + + org.apache.maven.plugins + maven-jar-plugin + + + reactor-jar + process-classes + + jar + + + + + default-jar + none + + jar + + + + + + org.apache.maven.plugins + maven-failsafe-plugin + + + ${project.build.directory}/${project.build.finalName}.jar + + + + + osgi-compatibility + + integration-test + verify + + + + + + + diff --git a/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java b/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java index e904ee1..6850f0c 100644 --- a/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java +++ b/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java @@ -41,6 +41,12 @@ * @author Jeff Ichnowski */ public class UnsupportedContextException extends RuntimeException { + /** + * The value the JVM computed for every released version (1.2 through + * 1.4.0), declared explicitly so serialized instances stay compatible. + */ + private static final long serialVersionUID = -1517019963198920181L; + /** * Sole constructor. * diff --git a/core/src/site/site.xml b/core/src/site/site.xml index 1b3cb62..174eb2f 100644 --- a/core/src/site/site.xml +++ b/core/src/site/site.xml @@ -1,4 +1,4 @@ - + + default-compile + + + ${project.basedir}/src/main/java + + + compile-java-9 compile @@ -438,6 +453,25 @@ + + org.codehaus.mojo + build-helper-maven-plugin + + + + add-java9-sources + generate-sources + + add-source + + + + ${project.basedir}/src/main/java9 + + + + + org.apache.maven.plugins maven-source-plugin @@ -457,6 +491,9 @@ 8 true + + module-info.java + @@ -565,6 +602,9 @@ 8 true + + module-info.java + diff --git a/src/main/config/checkstyle.xml b/src/main/config/checkstyle.xml index 0a5f0da..6656e95 100644 --- a/src/main/config/checkstyle.xml +++ b/src/main/config/checkstyle.xml @@ -1,4 +1,4 @@ - +