The GitHub Actions job "Groovy Snapshot Canary Build" on grails-core.git/feat/default-security-headers has failed. Run started by GitHub user jdaugherty (triggered by jdaugherty).
Head commit for run: 8da7b05c58fd3ef2cca4509c7d7938dc48b6332d / James Daugherty <[email protected]> Count writer output in encoded bytes, resolve the HSTS scheme without the request URL The response wrapper compared writer output, counted in characters, against the container's buffer and Content-Length, which are both in bytes. Three-byte UTF-8 text therefore filled and committed an enlarged buffer before the callback fired, and the headers were dropped. Tomcat keeps an enlarged buffer on the recycled processor, so later requests were affected even on new connections. Writer output is now counted as its encoded length: exactly for UTF-8 and single-byte encodings, and at the encoding's maximum bytes per character otherwise. HSTS resolved the forwarded scheme through ServletServerHttpRequest.getURI(), which throws for request paths that java.net.URI rejects but Tomcat accepts through relaxedPathChars, turning those requests into 500s. The forwarded headers are now applied to the request's scheme alone. The upgrade note moves to its own section, the explicit-configuration wording in the security guide matches the behavior, and the docs no longer place the Grails character-encoding filter outside the security headers filter. REVERSE_PROXY_REQUEST_HEADERS is no longer public API. The Tomcat spec checks every default header value, covers multi-byte writer output, and uses @TempDir. Report URL: https://github.com/apache/grails-core/actions/runs/36015566146 With regards, GitHub Actions via GitBox
