This is an automated email from the ASF dual-hosted git repository.
coheigea pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/cxf.git
The following commit(s) were added to refs/heads/main by this push:
new 42209052fe5 Add bundleresource to URIResolver default allowed URL
schemes (#3551)
42209052fe5 is described below
commit 42209052fe58a036a7afbab15dd65373902d1fcb
Author: François de Parscau <[email protected]>
AuthorDate: Thu Oct 8 09:20:32 2026 +0200
Add bundleresource to URIResolver default allowed URL schemes (#3551)
OSGi containers such as Apache Felix and Karaf expose bundle entries
through bundleresource:// URLs. These were rejected by the URIResolver
scheme allowlist, even though getLocalSchemes() already treats them
as local. Allow them by default and add a unit test.
Co-authored-by: Claude Sonnet 5.5 <[email protected]>
---
.../main/java/org/apache/cxf/resource/URIResolver.java | 2 +-
.../java/org/apache/cxf/resource/URIResolverTest.java | 16 ++++++++++++++++
2 files changed, 17 insertions(+), 1 deletion(-)
diff --git a/core/src/main/java/org/apache/cxf/resource/URIResolver.java
b/core/src/main/java/org/apache/cxf/resource/URIResolver.java
index 3828e95ab9c..6ce9a927692 100644
--- a/core/src/main/java/org/apache/cxf/resource/URIResolver.java
+++ b/core/src/main/java/org/apache/cxf/resource/URIResolver.java
@@ -68,7 +68,7 @@ public class URIResolver implements AutoCloseable {
private static final Set<String> DEFAULT_ALLOWED_URL_SCHEMES =
Collections.unmodifiableSet(
new HashSet<>(Arrays.asList("file", "http", "https", "jar", "zip",
"wsjar", "local", "classpath", "vfs",
- "resource")));
+ "resource", "bundleresource")));
private static final Set<String> NETWORK_URL_SCHEMES =
Collections.unmodifiableSet(new HashSet<>(Arrays.asList("http",
"https", "ftp")));
private static final Set<String> ARCHIVE_URL_SCHEMES =
diff --git a/core/src/test/java/org/apache/cxf/resource/URIResolverTest.java
b/core/src/test/java/org/apache/cxf/resource/URIResolverTest.java
index 9cf74f079d2..bf1b42bab53 100644
--- a/core/src/test/java/org/apache/cxf/resource/URIResolverTest.java
+++ b/core/src/test/java/org/apache/cxf/resource/URIResolverTest.java
@@ -19,11 +19,14 @@
package org.apache.cxf.resource;
+import java.io.IOException;
import java.io.InputStream;
import java.io.OutputStream;
import java.net.ServerSocket;
import java.net.Socket;
import java.net.URL;
+import java.net.URLConnection;
+import java.net.URLStreamHandler;
import java.nio.charset.StandardCharsets;
import java.util.Set;
@@ -206,6 +209,19 @@ public class URIResolverTest {
}
}
+ @Test
+ public void testBundleResourceProtocolAllowedByDefault() throws Exception {
+ assertTrue(URIResolver.getAllowedSchemes().contains("bundleresource"));
+ // no bundleresource handler is registered outside OSGi, so supply one
to build the URL
+ URL url = new URL(null, "bundleresource://1.fwk123/wsdl/foo.wsdl", new
URLStreamHandler() {
+ @Override
+ protected URLConnection openConnection(URL u) throws IOException {
+ throw new IOException("not supported");
+ }
+ });
+ URIResolver.checkAllowedScheme(url);
+ }
+
@Test
public void testHttpProtocolStillAllowed() throws Exception {
checkingThreadThrowable = null;