matrei opened a new pull request, #16394: URL: https://github.com/apache/grails-core/pull/16394
Backport of #16332 (including the #16330 follow-up) to 7.0.x. ## Summary Interceptor `uri` matchers and the Spring Security `ipRestrictions` filter now match the path within the application exactly as URL mapping dispatch resolves it with `UrlPathHelper.getPathWithinApplication`: percent escapes are decoded once, matrix parameters (`;name=value`) are removed per segment, and the context path is stripped. Previously the raw request URI was matched, so an encoded (`/%61dmin/users`) or matrix-parameter (`/admin;x=1/users`) form of a path could be dispatched to a controller without the matcher for the plain path applying. `UrlMappingMatcher` still accepts patterns that begin with the context path. Interceptors pairing `match(uri:)` with an exclusion now also run when the application is deployed under a context path. ## Differences from the 8.0.x change - **`grails.interceptors.Matcher` is unchanged.** Groovy 4 compiles an interface default method as a trait, which hides `Matcher.THROWABLE` from `Interceptor` and `GrailsInterceptorHandlerInterceptorAdapter`. The context-path-aware `doesMatch(uri, info, method, contextPath)` overload is therefore on `UrlMappingMatcher` only, and custom matchers keep receiving the canonical path through the three-argument `doesMatch`. The spec that exercised the interface default method was dropped. - The `AntPathRequestMatcher` compat class and its build/test wiring do not exist on 7.0.x and are not included. - The upgrade note is added as section 18 of the Grails 6 to 7 upgrade guide. ## Testing - `:grails-interceptors:test` - `:grails-spring-security:test` - `:grails-interceptors:codeStyle`, `:grails-spring-security:codeStyle` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
