This is an automated email from the ASF dual-hosted git repository.

coheigea pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/cxf.git


The following commit(s) were added to refs/heads/main by this push:
     new 42209052fe5 Add bundleresource to URIResolver default allowed URL 
schemes (#3551)
42209052fe5 is described below

commit 42209052fe58a036a7afbab15dd65373902d1fcb
Author: François de Parscau <[email protected]>
AuthorDate: Thu Oct 8 09:20:32 2026 +0200

    Add bundleresource to URIResolver default allowed URL schemes (#3551)
    
    OSGi containers such as Apache Felix and Karaf expose bundle entries
    through bundleresource:// URLs. These were rejected by the URIResolver
    scheme allowlist, even though getLocalSchemes() already treats them
    as local. Allow them by default and add a unit test.
    
    Co-authored-by: Claude Sonnet 5.5 <[email protected]>
---
 .../main/java/org/apache/cxf/resource/URIResolver.java   |  2 +-
 .../java/org/apache/cxf/resource/URIResolverTest.java    | 16 ++++++++++++++++
 2 files changed, 17 insertions(+), 1 deletion(-)

diff --git a/core/src/main/java/org/apache/cxf/resource/URIResolver.java 
b/core/src/main/java/org/apache/cxf/resource/URIResolver.java
index 3828e95ab9c..6ce9a927692 100644
--- a/core/src/main/java/org/apache/cxf/resource/URIResolver.java
+++ b/core/src/main/java/org/apache/cxf/resource/URIResolver.java
@@ -68,7 +68,7 @@ public class URIResolver implements AutoCloseable {
     private static final Set<String> DEFAULT_ALLOWED_URL_SCHEMES =
         Collections.unmodifiableSet(
             new HashSet<>(Arrays.asList("file", "http", "https", "jar", "zip", 
"wsjar", "local", "classpath", "vfs",
-                    "resource")));
+                    "resource", "bundleresource")));
     private static final Set<String> NETWORK_URL_SCHEMES =
         Collections.unmodifiableSet(new HashSet<>(Arrays.asList("http", 
"https", "ftp")));
     private static final Set<String> ARCHIVE_URL_SCHEMES =
diff --git a/core/src/test/java/org/apache/cxf/resource/URIResolverTest.java 
b/core/src/test/java/org/apache/cxf/resource/URIResolverTest.java
index 9cf74f079d2..bf1b42bab53 100644
--- a/core/src/test/java/org/apache/cxf/resource/URIResolverTest.java
+++ b/core/src/test/java/org/apache/cxf/resource/URIResolverTest.java
@@ -19,11 +19,14 @@
 
 package org.apache.cxf.resource;
 
+import java.io.IOException;
 import java.io.InputStream;
 import java.io.OutputStream;
 import java.net.ServerSocket;
 import java.net.Socket;
 import java.net.URL;
+import java.net.URLConnection;
+import java.net.URLStreamHandler;
 import java.nio.charset.StandardCharsets;
 import java.util.Set;
 
@@ -206,6 +209,19 @@ public class URIResolverTest {
         }
     }
 
+    @Test
+    public void testBundleResourceProtocolAllowedByDefault() throws Exception {
+        assertTrue(URIResolver.getAllowedSchemes().contains("bundleresource"));
+        // no bundleresource handler is registered outside OSGi, so supply one 
to build the URL
+        URL url = new URL(null, "bundleresource://1.fwk123/wsdl/foo.wsdl", new 
URLStreamHandler() {
+            @Override
+            protected URLConnection openConnection(URL u) throws IOException {
+                throw new IOException("not supported");
+            }
+        });
+        URIResolver.checkAllowedScheme(url);
+    }
+
     @Test
     public void testHttpProtocolStillAllowed() throws Exception {
         checkingThreadThrowable = null;

Reply via email to