[
https://issues.apache.org/jira/browse/VELOCITY-1001?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Tagir Valeev updated VELOCITY-1001:
-----------------------------------
Description:
I've noticed that when we call a static method from the template, a
warning is issued like this:
82 [main] WARN org.apache.velocity.introspection - Cannot retrieve
method max from object of class java.lang.Class due to security
restrictions.
Nevertheless, the method is called correctly, and the template is
merged correctly. Here's a simple reproducer:
{{import org.apache.velocity.Template;}}
{{import org.apache.velocity.VelocityContext;}}
{{import org.apache.velocity.app.VelocityEngine;}}
{{import org.apache.velocity.runtime.RuntimeConstants;}}
{{import org.apache.velocity.runtime.resource.loader.StringResourceLoader;}}
{{{}import
org.apache.velocity.util.introspection.SecureUberspector;{}}}{{{}import
java.io.StringWriter;{}}}{{{}public class VelocityDemo {{}}}
{{ static {}}
{{ System.setProperty("org.slf4j.simpleLogger.logFile", "System.err");}}
{{ System.setProperty("org.slf4j.simpleLogger.defaultLogLevel",
"warn");}}
{{ System.setProperty("org.slf4j.simpleLogger.showDateTime", "true");}}
{{ }}}{{ private static final String TEMPLATE_NAME = "demo.vm";}}{{
private static final String TEMPLATE = """}}
{{ Hello, $name!}}
{{ Your lucky number is $math.round($math.random() * 100).}}
{{ The bigger of 3 and 7 is $math.max(3, 7).}}
{{ """;}}{{ public static void main(String[] args) {}}
{{ VelocityEngine engine = new VelocityEngine();}}
{{ engine.setProperty(RuntimeConstants.RESOURCE_LOADERS, "string");}}
{{ engine.setProperty("resource.loader.string.class",}}
{{StringResourceLoader.class.getName());}}
{{ engine.setProperty(RuntimeConstants.UBERSPECT_CLASSNAME,}}
{{SecureUberspector.class.getName());}}
{{ engine.init();}}{{
StringResourceLoader.getRepository().putStringResource(TEMPLATE_NAME,}}
{{TEMPLATE);}}
{{ VelocityContext context = new VelocityContext();}}
{{ context.put("name", "World");}}
{{ context.put("math", Math.class);}}{{ Template template =
engine.getTemplate(TEMPLATE_NAME);}}
{{ StringWriter out = new StringWriter();}}
{{ template.merge(context, out);}}{{ System.out.println(out);}}
{{ }}}
{{}}}
+deps: org.apache.velocity:velocity-engine-core:2.4.1,
org.slf4j:slf4j-simple:1.7.36
The output is the following:
{{55 [main] WARN org.apache.velocity.introspection - Cannot retrieve method
random from object of class java.lang.Class due to security restrictions.}}
{{75 [main] WARN org.apache.velocity.introspection - Cannot retrieve method
round from object of class java.lang.Class due to security restrictions.}}
{{82 [main] WARN org.apache.velocity.introspection - Cannot retrieve method max
from object of class java.lang.Class due to security restrictions.}}
{{Hello, World!}}
{{Your lucky number is 53.}}
{{The bigger of 3 and 7 is 7.}}
The reason is that for static methods, the qualifier is set to the
java.lang.Class pointing to a class containing the method. The
introspector first looks for the method inside the java.lang.Class,
and only after that tries to find a static method in the target class.
The warning adds a lot of noise to our logs. We can filter it out on
our side, but it would be nice to fix it in Velocity.
was:
I've noticed that when we call a static method from the template, a
warning is issued like this:
82 [main] WARN org.apache.velocity.introspection - Cannot retrieve
method max from object of class java.lang.Class due to security
restrictions.
Nevertheless, the method is called correctly, and the template is
merged correctly. Here's a simple reproducer:
{{import org.apache.velocity.Template;
import org.apache.velocity.VelocityContext;
import org.apache.velocity.app.VelocityEngine;
import org.apache.velocity.runtime.RuntimeConstants;
import org.apache.velocity.runtime.resource.loader.StringResourceLoader;
import org.apache.velocity.util.introspection.SecureUberspector;
import java.io.StringWriter;
public class VelocityDemo {
static {
System.setProperty("org.slf4j.simpleLogger.logFile", "System.err");
System.setProperty("org.slf4j.simpleLogger.defaultLogLevel", "warn");
System.setProperty("org.slf4j.simpleLogger.showDateTime", "true");
}
private static final String TEMPLATE_NAME = "demo.vm";
private static final String TEMPLATE = """
Hello, $name!
Your lucky number is $math.round($math.random() * 100).
The bigger of 3 and 7 is $math.max(3, 7).
""";
public static void main(String[] args) {
VelocityEngine engine = new VelocityEngine();
engine.setProperty(RuntimeConstants.RESOURCE_LOADERS, "string");
engine.setProperty("resource.loader.string.class",
StringResourceLoader.class.getName());
engine.setProperty(RuntimeConstants.UBERSPECT_CLASSNAME,
SecureUberspector.class.getName());
engine.init();
StringResourceLoader.getRepository().putStringResource(TEMPLATE_NAME,
TEMPLATE);
VelocityContext context = new VelocityContext();
context.put("name", "World");
context.put("math", Math.class);
Template template = engine.getTemplate(TEMPLATE_NAME);
StringWriter out = new StringWriter();
template.merge(context, out);
System.out.println(out);
}
}}}
+deps: org.apache.velocity:velocity-engine-core:2.4.1,
org.slf4j:slf4j-simple:1.7.36
The output is the following:
55 [main] WARN org.apache.velocity.introspection - Cannot retrieve
method random from object of class java.lang.Class due to security
restrictions.
75 [main] WARN org.apache.velocity.introspection - Cannot retrieve
method round from object of class java.lang.Class due to security
restrictions.
82 [main] WARN org.apache.velocity.introspection - Cannot retrieve
method max from object of class java.lang.Class due to security
restrictions.
Hello, World!
Your lucky number is 53.
The bigger of 3 and 7 is 7.
The reason is that for static methods, the qualifier is set to the
java.lang.Class pointing to a class containing the method. The
introspector first looks for the method inside the java.lang.Class,
and only after that tries to find a static method in the target class.
The warning adds a lot of noise to our logs. We can filter it out on
our side, but it would be nice to fix it in Velocity.
> An unwanted warning message in logs when calling a static method with
> SecureUberspector on
> ------------------------------------------------------------------------------------------
>
> Key: VELOCITY-1001
> URL: https://issues.apache.org/jira/browse/VELOCITY-1001
> Project: Velocity
> Issue Type: Bug
> Components: Engine
> Affects Versions: 2.4.1
> Reporter: Tagir Valeev
> Priority: Minor
>
> I've noticed that when we call a static method from the template, a
> warning is issued like this:
> 82 [main] WARN org.apache.velocity.introspection - Cannot retrieve
> method max from object of class java.lang.Class due to security
> restrictions.
> Nevertheless, the method is called correctly, and the template is
> merged correctly. Here's a simple reproducer:
> {{import org.apache.velocity.Template;}}
> {{import org.apache.velocity.VelocityContext;}}
> {{import org.apache.velocity.app.VelocityEngine;}}
> {{import org.apache.velocity.runtime.RuntimeConstants;}}
> {{import org.apache.velocity.runtime.resource.loader.StringResourceLoader;}}
> {{{}import
> org.apache.velocity.util.introspection.SecureUberspector;{}}}{{{}import
> java.io.StringWriter;{}}}{{{}public class VelocityDemo {{}}}
> {{ static {}}
> {{ System.setProperty("org.slf4j.simpleLogger.logFile",
> "System.err");}}
> {{ System.setProperty("org.slf4j.simpleLogger.defaultLogLevel",
> "warn");}}
> {{ System.setProperty("org.slf4j.simpleLogger.showDateTime", "true");}}
> {{ }}}{{ private static final String TEMPLATE_NAME = "demo.vm";}}{{
> private static final String TEMPLATE = """}}
> {{ Hello, $name!}}
> {{ Your lucky number is $math.round($math.random() * 100).}}
> {{ The bigger of 3 and 7 is $math.max(3, 7).}}
> {{ """;}}{{ public static void main(String[] args) {}}
> {{ VelocityEngine engine = new VelocityEngine();}}
> {{ engine.setProperty(RuntimeConstants.RESOURCE_LOADERS, "string");}}
> {{ engine.setProperty("resource.loader.string.class",}}
> {{StringResourceLoader.class.getName());}}
> {{ engine.setProperty(RuntimeConstants.UBERSPECT_CLASSNAME,}}
> {{SecureUberspector.class.getName());}}
> {{ engine.init();}}{{
> StringResourceLoader.getRepository().putStringResource(TEMPLATE_NAME,}}
> {{TEMPLATE);}}
> {{ VelocityContext context = new VelocityContext();}}
> {{ context.put("name", "World");}}
> {{ context.put("math", Math.class);}}{{ Template template =
> engine.getTemplate(TEMPLATE_NAME);}}
> {{ StringWriter out = new StringWriter();}}
> {{ template.merge(context, out);}}{{ System.out.println(out);}}
> {{ }}}
> {{}}}
> +deps: org.apache.velocity:velocity-engine-core:2.4.1,
> org.slf4j:slf4j-simple:1.7.36
> The output is the following:
> {{55 [main] WARN org.apache.velocity.introspection - Cannot retrieve method
> random from object of class java.lang.Class due to security restrictions.}}
> {{75 [main] WARN org.apache.velocity.introspection - Cannot retrieve method
> round from object of class java.lang.Class due to security restrictions.}}
> {{82 [main] WARN org.apache.velocity.introspection - Cannot retrieve method
> max from object of class java.lang.Class due to security restrictions.}}
> {{Hello, World!}}
> {{Your lucky number is 53.}}
> {{The bigger of 3 and 7 is 7.}}
> The reason is that for static methods, the qualifier is set to the
> java.lang.Class pointing to a class containing the method. The
> introspector first looks for the method inside the java.lang.Class,
> and only after that tries to find a static method in the target class.
> The warning adds a lot of noise to our logs. We can filter it out on
> our side, but it would be nice to fix it in Velocity.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]