ruthst00 opened a new pull request, #16492: URL: https://github.com/apache/grails-core/pull/16492
## Description <!-- Describe your change and the problem it solves. Link to the related issue(s) if they exist. --> **Root Cause**: `TEMPLATE_MODEL` is a plain request attribute that persists across action boundaries on the same request. When a controller action called `render(template:..., model:...)` and then forwarded to another action (or when a template included another action via `g:include`), the interceptor on the second/included action could read the first action's `TEMPLATE_MODEL` — a leak. **Changes Made:** 1. **`RequestForwarder.groovy`** — Added `TEMPLATE_MODEL` removal both before the forward dispatch and in the `finally` block after it, mirroring the existing `MODEL_AND_VIEW` cleanup. 2. **`UrlMappingUtils.java`** — In `includeForUrlMappingInfoHelper`, added save/remove/restore of `TEMPLATE_MODEL` around the include dispatch, mirroring the existing `MODEL_AND_VIEW` save/restore pattern. 3. **`RequestForwarderSpec.groovy`** — Added a new unit test verifying that `TEMPLATE_MODEL` is cleared before the forward (not visible to the forwarded action) and removed after the forward completes. 4. **`UrlMappingUtilsSpec.groovy`** — Added two new unit tests: one verifying `TEMPLATE_MODEL` is null during the include and restored to the outer value after; another verifying that a `TEMPLATE_MODEL` set by the included action is removed after the include returns. 5. **`RenderTemplateController.groovy`** (both `views-functional-tests` and `hibernate7/views-functional-tests`) — Added `forwardAfterTemplate`, `forwardTarget`, `includeAfterTemplate`, and `includeTarget` actions to exercise the leak scenarios end-to-end. 6. **`ModelInterceptor.groovy`** (both test apps) — Added `modelByAction` map to track the model seen per action name, enabling the include test to assert on the included action's model independently. 7. **`ModelInterceptorIntSpec.groovy`** (both test apps) — Added two new integration test cases: one asserting `latestModel == null` after a forward (the forwarded action sees no leaked model), and one asserting `modelByAction['includeTarget'] == null` (the included action sees no leaked model). Fixes issue in [#16453](https://github.com/apache/grails-core/pull/16453) found after merge to 8.0.x Generated with [Claude Sonnet 4.6](https://www.anthropic.com/claude/sonnet) via [Cline API Provider](https://cline.bot/) ## Contributor Checklist Please review the following checklist before submitting your pull request. Pull requests that do not meet these requirements may be closed without review. ### Issue and Scope - [X] This PR is linked to an existing issue that has been **acknowledged or approved** by the project team. If no approved issue exists, please give background on why this change is necessary. Tickets are preferred for release change log history. - [X] This PR addresses the **complete scope** of the linked issue. Partial implementations or unfinished work should not be submitted for review. - [X] This PR contains a **single, focused change**. Unrelated changes should be submitted as separate pull requests. - [X] This PR targets the **correct branch** for the type of change: - **Patch release branches** (e.g., `7.0.x`): Bug fixes only. No new features or API changes. - **Minor release branches** (e.g., `7.1.x`): New features are welcome, but breaking existing APIs must be avoided. - **Major release branches** (e.g., `8.0.x`): Reserved for major changes. Breaking API changes are permitted. ### Code Quality - [X] I have **added or updated tests** that cover the changes introduced in this PR. All code contributions are expected to include appropriate test coverage. - [X] I have verified that all existing tests pass by running `./gradlew build --rerun-tasks`. - [ ] My code follows the project's **code style** guidelines. I have run `./gradlew codeStyle` and resolved any violations. See [Code Style](../CONTRIBUTING.md#code-style) for details. - [X] This PR does **not** include mass reformatting, style-only changes, or large-scale refactoring unless it was **explicitly approved** in the linked issue. Unsolicited reformatting will not be accepted. - [X] If generative AI tooling was used in preparing this contribution, a quality model was used to ensure contributions are **consistent with the project's quality standards**. ### Licensing and Attribution - [X] All contributed code is provided under the [Apache License 2.0](https://www.apache.org/licenses/LICENSE-2.0), and new source files include the appropriate **Apache license header**. - [X] I have the necessary rights to submit this contribution and confirm it is my own original work (see [Legal Notice](../CONTRIBUTING.md#i-want-to-contribute)). - [X] If generative AI tooling was used in preparing this contribution, I have followed the [Apache Software Foundation's policy on generative tooling](https://www.apache.org/legal/generative-tooling.html) and have properly attributed its use. ### Documentation - [ ] If this PR introduces user-facing changes, I have included or updated the relevant documentation. - [ ] If this PR adds a new feature, I have updated the **What's New** section of the Grails Guide. - [ ] If this PR introduces breaking changes or changes that require user action during an upgrade, I have updated the **Upgrade Notes** for the corresponding version in the Grails Guide. - [X] The PR description clearly explains **what** was changed and **why**. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
