From 725b80a9616387bda8ec139b28d38ce7fe53fc03 Mon Sep 17 00:00:00 2001 From: Volodymyr Borysenko Date: Fri, 25 Sep 2026 23:25:33 -0700 Subject: [PATCH 1/4] Normalize line endings and XML encodings; remove legacy files (#123) - Add .gitattributes (LF text, CRLF only for Windows command scripts such as a future Maven wrapper, binary for images and archives) and a minimal .editorconfig (UTF-8, LF, indentation for Java, Python and YAML). - Renormalize core/pom.xml, the only CRLF text file, to LF. With CR ignored, its diff is only the XML declaration line. - Declare UTF-8 in the ten XML files that declared US-ASCII or ISO-8859-1 (POMs, site descriptors, checkstyle.xml). All of them are pure ASCII, so no content byte changes. - Remove the unused root META-INF/MANIFEST.MF, a stale bnd 1.50 manifest for 1.2.1 that nothing references; the build writes its manifests to target/classes. - Clear the executable bit on pom.xml, the only executable file. - Replace five overlapping target patterns in .gitignore with target/. The one binary fixture (src/site/resources/images/owasp.jpg) is untouched. --- .editorconfig | 14 ++ .gitattributes | 15 ++ .gitignore | 10 +- META-INF/MANIFEST.MF | 9 -- core/pom.xml | 264 ++++++++++++++++----------------- core/src/site/site.xml | 2 +- esapi/pom.xml | 2 +- esapi/src/site/site.xml | 2 +- jakarta/pom.xml | 2 +- jakarta/src/site/site.xml | 2 +- jsp/pom.xml | 2 +- jsp/src/site/site.xml | 2 +- pom.xml | 2 +- src/main/config/checkstyle.xml | 2 +- 14 files changed, 172 insertions(+), 158 deletions(-) create mode 100644 .editorconfig create mode 100644 .gitattributes delete mode 100644 META-INF/MANIFEST.MF mode change 100755 => 100644 pom.xml diff --git a/.editorconfig b/.editorconfig new file mode 100644 index 0000000..7a57675 --- /dev/null +++ b/.editorconfig @@ -0,0 +1,14 @@ +# https://editorconfig.org +root = true + +[*] +charset = utf-8 +end_of_line = lf + +[*.{java,py}] +indent_style = space +indent_size = 4 + +[*.{yml,yaml}] +indent_style = space +indent_size = 2 diff --git a/.gitattributes b/.gitattributes new file mode 100644 index 0000000..26113f5 --- /dev/null +++ b/.gitattributes @@ -0,0 +1,15 @@ +# Normalize text to LF in the repository and working tree. +* text=auto eol=lf + +# Windows command scripts (for example a future Maven wrapper) need CRLF. +*.cmd text eol=crlf +*.bat text eol=crlf + +# Binary files: never convert or diff as text. +*.jar binary +*.class binary +*.jpg binary +*.jpeg binary +*.png binary +*.gif binary +*.ico binary diff --git a/.gitignore b/.gitignore index adc5f64..110f9aa 100644 --- a/.gitignore +++ b/.gitignore @@ -1,5 +1,5 @@ -*/target/** -/target/** +# Maven build output in every module +target/ # Intellij project files *.iml *.ipr @@ -15,12 +15,6 @@ maven-eclipse.xml nb-configuration.xml */nbproject/* -/jsp/target/ -/esapi/target/ -/target/ -/jakarta/target/ -/jakarta-test/target/ - # Python CI/compatibility tooling __pycache__/ *.pyc diff --git a/META-INF/MANIFEST.MF b/META-INF/MANIFEST.MF deleted file mode 100644 index 2aaee67..0000000 --- a/META-INF/MANIFEST.MF +++ /dev/null @@ -1,9 +0,0 @@ -Manifest-Version: 1.0 -Bnd-LastModified: 1533328833261 -Bundle-ManifestVersion: 2 -Bundle-Name: org.owasp.encoder -Bundle-SymbolicName: org.owasp.encoder -Bundle-Version: 1.2.1 -Created-By: 1.8.0_181 (Oracle Corporation) -Export-Package: org.owasp.encoder -Tool: Bnd-1.50.0 diff --git a/core/pom.xml b/core/pom.xml index 7893375..520c4eb 100644 --- a/core/pom.xml +++ b/core/pom.xml @@ -1,132 +1,132 @@ - - - - - 4.0.0 - - - org.owasp.encoder - encoder-parent - 1.5.0-SNAPSHOT - - - encoder - jar - - Java Encoder - - The OWASP Encoders package is a collection of high-performance low-overhead - contextual encoders, that when utilized correctly, is an effective tool in - preventing Web Application security vulnerabilities such as Cross-Site - Scripting. - - - - org.owasp.encoder - org.owasp.encoder - - - - - - org.apache.felix - org.apache.felix.framework - 5.6.12 - test - - - - com.fasterxml.jackson.core - jackson-databind - 2.22.3 - test - - - - org.jsoup - jsoup - 1.23.2 - test - - - - - - - - org.apache.maven.plugins - maven-jar-plugin - - - reactor-jar - process-classes - - jar - - - - - default-jar - none - - jar - - - - - - org.apache.maven.plugins - maven-failsafe-plugin - - - ${project.build.directory}/${project.build.finalName}.jar - - - - - osgi-compatibility - - integration-test - verify - - - - - - - + + + + + 4.0.0 + + + org.owasp.encoder + encoder-parent + 1.5.0-SNAPSHOT + + + encoder + jar + + Java Encoder + + The OWASP Encoders package is a collection of high-performance low-overhead + contextual encoders, that when utilized correctly, is an effective tool in + preventing Web Application security vulnerabilities such as Cross-Site + Scripting. + + + + org.owasp.encoder + org.owasp.encoder + + + + + + org.apache.felix + org.apache.felix.framework + 5.6.12 + test + + + + com.fasterxml.jackson.core + jackson-databind + 2.22.3 + test + + + + org.jsoup + jsoup + 1.23.2 + test + + + + + + + + org.apache.maven.plugins + maven-jar-plugin + + + reactor-jar + process-classes + + jar + + + + + default-jar + none + + jar + + + + + + org.apache.maven.plugins + maven-failsafe-plugin + + + ${project.build.directory}/${project.build.finalName}.jar + + + + + osgi-compatibility + + integration-test + verify + + + + + + + diff --git a/core/src/site/site.xml b/core/src/site/site.xml index 1b3cb62..174eb2f 100644 --- a/core/src/site/site.xml +++ b/core/src/site/site.xml @@ -1,4 +1,4 @@ - + + default-compile + + + ${project.basedir}/src/main/java + + + compile-java-9 compile @@ -438,6 +453,25 @@ + + org.codehaus.mojo + build-helper-maven-plugin + + + + add-java9-sources + generate-sources + + add-source + + + + ${project.basedir}/src/main/java9 + + + + + org.apache.maven.plugins maven-source-plugin @@ -457,6 +491,9 @@ 8 true + + module-info.java + @@ -565,6 +602,9 @@ 8 true + + module-info.java + From 2d709d43272bc0d0ed7017f0d5647a40bd4a3184 Mon Sep 17 00:00:00 2001 From: Volodymyr Borysenko Date: Fri, 25 Sep 2026 23:28:07 -0700 Subject: [PATCH 3/4] Declare UnsupportedContextException's historical serialVersionUID (#123) The class relied on the JVM-computed serialVersionUID. serialver gives -1517019963198920181L for every released core from 1.2 through 1.4.0 and for the current class, so declaring that value keeps serialized instances compatible while protecting it from future structural changes. UnsupportedContextExceptionTest pins the value and round-trips an instance. Manually, an instance serialized with the released 1.4.0 JAR deserializes with this class. --- .../encoder/UnsupportedContextException.java | 6 ++ .../UnsupportedContextExceptionTest.java | 64 +++++++++++++++++++ 2 files changed, 70 insertions(+) create mode 100644 core/src/test/java/org/owasp/encoder/UnsupportedContextExceptionTest.java diff --git a/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java b/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java index e904ee1..6850f0c 100644 --- a/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java +++ b/core/src/main/java/org/owasp/encoder/UnsupportedContextException.java @@ -41,6 +41,12 @@ * @author Jeff Ichnowski */ public class UnsupportedContextException extends RuntimeException { + /** + * The value the JVM computed for every released version (1.2 through + * 1.4.0), declared explicitly so serialized instances stay compatible. + */ + private static final long serialVersionUID = -1517019963198920181L; + /** * Sole constructor. * diff --git a/core/src/test/java/org/owasp/encoder/UnsupportedContextExceptionTest.java b/core/src/test/java/org/owasp/encoder/UnsupportedContextExceptionTest.java new file mode 100644 index 0000000..6b98f89 --- /dev/null +++ b/core/src/test/java/org/owasp/encoder/UnsupportedContextExceptionTest.java @@ -0,0 +1,64 @@ +// Copyright (c) 2026 OWASP +// All rights reserved. +// +// Redistribution and use in source and binary forms, with or without +// modification, are permitted provided that the following conditions +// are met: +// +// * Redistributions of source code must retain the above +// copyright notice, this list of conditions and the following +// disclaimer. +// +// * Redistributions in binary form must reproduce the above +// copyright notice, this list of conditions and the following +// disclaimer in the documentation and/or other materials +// provided with the distribution. +// +// * Neither the name of the OWASP nor the names of its +// contributors may be used to endorse or promote products +// derived from this software without specific prior written +// permission. +// +// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS +// FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE +// COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, +// INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES +// (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR +// SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +// HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, +// STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +// ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED +// OF THE POSSIBILITY OF SUCH DAMAGE. + +package org.owasp.encoder; + +import java.io.ByteArrayInputStream; +import java.io.ByteArrayOutputStream; +import java.io.ObjectInputStream; +import java.io.ObjectOutputStream; +import java.io.ObjectStreamClass; +import junit.framework.TestCase; + +/** + * UnsupportedContextException must stay serialization compatible with the + * released versions, which all used the JVM-computed serialVersionUID below. + */ +public class UnsupportedContextExceptionTest extends TestCase { + + public void testSerialVersionUidMatchesReleasedVersions() { + assertEquals(-1517019963198920181L, + ObjectStreamClass.lookup(UnsupportedContextException.class).getSerialVersionUID()); + } + + public void testSerializationRoundTrip() throws Exception { + ByteArrayOutputStream bytes = new ByteArrayOutputStream(); + ObjectOutputStream out = new ObjectOutputStream(bytes); + out.writeObject(new UnsupportedContextException("no-such-context")); + out.close(); + ObjectInputStream in = new ObjectInputStream(new ByteArrayInputStream(bytes.toByteArray())); + UnsupportedContextException copy = (UnsupportedContextException) in.readObject(); + assertEquals("no-such-context", copy.getMessage()); + } +} From 22757e1789cc4c3f920e668bfcf9a7a1dfd400f0 Mon Sep 17 00:00:00 2001 From: Volodymyr Borysenko Date: Fri, 25 Sep 2026 23:30:03 -0700 Subject: [PATCH 4/4] Remove unused Servlet API test dependencies from the adapters (#123) javax.servlet:javax.servlet-api (jsp) and jakarta.servlet: jakarta.servlet-api (jakarta) were test-scoped, but no test or packaged check uses them. dependency:analyze reports both as unused declared dependencies. Without them, core, jsp and jakarta pass clean verify, including the parameterized tag contracts, the TLD descriptor tests and ModulePathIT. The packaged-consumer preparation and its 15 guard tests also pass. The packaged-consumer harness keeps its own Servlet API JARs in compatibility/dependencies, where the module-path and Felix consumers do need them. The optional jakarta-test application is unchanged. --- jakarta/pom.xml | 6 ------ jsp/pom.xml | 6 ------ 2 files changed, 12 deletions(-) diff --git a/jakarta/pom.xml b/jakarta/pom.xml index b4b432c..0492127 100644 --- a/jakarta/pom.xml +++ b/jakarta/pom.xml @@ -86,12 +86,6 @@ 4.0.0 test - - jakarta.servlet - jakarta.servlet-api - 6.0.0 - test - diff --git a/jsp/pom.xml b/jsp/pom.xml index 6cde749..9d1a86e 100644 --- a/jsp/pom.xml +++ b/jsp/pom.xml @@ -86,12 +86,6 @@ 2.2.5 test - - javax.servlet - javax.servlet-api - 3.0.1 - test -