matrei opened a new pull request, #16394:
URL: https://github.com/apache/grails-core/pull/16394

   Backport of #16332 (including the #16330 follow-up) to 7.0.x.
   
   ## Summary
   
   Interceptor `uri` matchers and the Spring Security `ipRestrictions` filter 
now match the path within the application exactly as URL mapping dispatch 
resolves it with `UrlPathHelper.getPathWithinApplication`: percent escapes are 
decoded once, matrix parameters (`;name=value`) are removed per segment, and 
the context path is stripped. Previously the raw request URI was matched, so an 
encoded (`/%61dmin/users`) or matrix-parameter (`/admin;x=1/users`) form of a 
path could be dispatched to a controller without the matcher for the plain path 
applying.
   
   `UrlMappingMatcher` still accepts patterns that begin with the context path. 
Interceptors pairing `match(uri:)` with an exclusion now also run when the 
application is deployed under a context path.
   
   ## Differences from the 8.0.x change
   
   - **`grails.interceptors.Matcher` is unchanged.** Groovy 4 compiles an 
interface default method as a trait, which hides `Matcher.THROWABLE` from 
`Interceptor` and `GrailsInterceptorHandlerInterceptorAdapter`. The 
context-path-aware `doesMatch(uri, info, method, contextPath)` overload is 
therefore on `UrlMappingMatcher` only, and custom matchers keep receiving the 
canonical path through the three-argument `doesMatch`. The spec that exercised 
the interface default method was dropped.
   - The `AntPathRequestMatcher` compat class and its build/test wiring do not 
exist on 7.0.x and are not included.
   - The upgrade note is added as section 18 of the Grails 6 to 7 upgrade guide.
   
   ## Testing
   
   - `:grails-interceptors:test`
   - `:grails-spring-security:test`
   - `:grails-interceptors:codeStyle`, `:grails-spring-security:codeStyle`
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to