TOMEE-4707 drop the standalone HTTP server from openejb-http - #2945
Conversation
TomEE serves requests through Tomcat's connectors, so the hand written HTTP server in openejb-http is unused attack surface. Removes it, the unreachable Jetty backend, the httpejbd service and OpenEJBHttpRegistry. isTextXml and reformat move to HttpUtil. RsRegistryImpl and OpenEJBHttpWsRegistry extended OpenEJBHttpRegistry and were the non-Tomcat fallbacks in RESTService and WsService; both go, so openejb-standalone and arquillian-openejb-embedded lose embedded REST/WS wiring. Everything Tomcat needs stays: listeners, the registry, request, response and session, the servlet and filter adapters, ServerServlet and the CDI listeners. The tests that drove the removed transport over a socket go with it.
jungm
left a comment
There was a problem hiding this comment.
The socket server is gone, but several things still depend on httpejbd. CI builds with -DskipTests, so none of this shows up there. Fixes follow on this branch.
Broken, tests fail on this branch
RESTService.java:1072: without theRsRegistryImplfallback,rsRegistryis null outside Tomcat anddeployApplication(L543) NPEs.SimplePojoTestandCDIApplicationTest(openejb-cxf-rs) fail.FilteredServiceManager.java:45:@EnableServicesjaxrs/jaxws/httpstill map tohttpejbd. ~57 tests in openejb-cxf-rs, 11 in openejb-cxf and ~25 examples callhttp://localhost:<httpejbd.port>and getConnectException.- arquillian-openejb-embedded
ServiceManagers.java:37:protocolMetaDatalooks uphttpejbd, so it is always null and@ArquillianResource URLinjection fails.ArquillianResourceURLTestandSessionDestroyTestfail.
Broken, from reading the code
OpenEJBDeployableContainer.java:275:metaDatais always null now, butmetaData.getContexts()runs before the null check at L291. NPE for WARs with servlets inweb.xml.- Nothing constructs
HttpListenerRegistryany more, so theHttpServletRequest/HttpSessionthread-local proxies (incl.openejb.http.mock-request) andEmbeddedServletContextare no longer registered.@Inject HttpServletRequestis null in embedded mode; affectstck/cdi-embedded. WsService.java:176:wsRegistryis null outside Tomcat, so@WebServiceendpoints are silently not published.- EJB-over-HTTP (
/ejbon 4204 viaServerServiceAdapter) is also gone from openejb-standalone. Not in the description;assembly/openejb-standalone/src/main/conf/README.txt,start.examplesCLI help and severaldocs/*.adocstill documenthttpejbd.
Leftovers
openejb-standalone/pom.xmlstill bundles openejb-http, openejb-cxf and openejb-cxf-rs.- Now unreachable:
HttpRequestImpl.readMessage,HttpResponseImpl,HttpSessionImpl,SessionManager,OpenEJBAsyncContext,FilterListener,HttpListenerRegistry(incl. static resource serving),HttpUtil.add/removeServlet/Filter. HttpUtil.isTextXml/reformatwere moved instead of deleted; their only callers are unreachable.reformatalso usesTransformerFactorywithout secure processing.ApplicationComposers:@RandomPort("http")→httpejbd.portandhttpDebug→httpejbd.print/indent.xmlare no-ops.- Stale refs:
ServletContextListenerRegistrationTest(@EnableServices({"httpejbd"})),AppScopeInitEventTest(@EnableServices("http")),FilteredServiceManagerTest,ServiceManager,TomEEServiceManager,tck/cdi-embedded. openejb-http/pom.xml:openejb-itests-client/idb test deps,reserve-activemq-port+ ActiveMQ surefire props, and test resources (META-INF/resources/foo.txt,other/foo.txt,conf/instantdb.properties) were only used by the deleted tests.- Unused
HttpListenerRegistryimport inRESTServiceandWsService.
RESTService and WsService log a warning and skip deployment when no registry is available instead of failing with an NPE per application. The embedded Arquillian adapter no longer advertises an HTTP URL, openejb-standalone stops shipping the HTTP, CXF and CXF-RS modules, and the httpejbd aliases, debug flags, docs and test leftovers go. cdi-embedded excludes the CDI TCK tests that need an HTTP server; cdi-tomee runs them.
Moves the shared JAX-RS test beans to arquillian-tomee-jaxrs-tests, where the tests using them run against Tomcat.
ApplicationComposer docs point to TomEE embedded and the Arquillian TomEE adapters for testing JAX-RS and JAX-WS endpoints over HTTP.
rest-applicationcomposer, rest-applicationcomposer-mockito and applicationcomposer-jaxws-cdi relied on ApplicationComposer serving HTTP.
…E embedded Moves the Application/web.xml deployment, routing, provider and response tests from openejb-cxf-rs to arquillian-tomee-jaxrs-tests, where they deploy a war on Tomcat instead of the removed embedded HTTP server.
…edded Moves the ApplicationComposer/EJBContainer based cxf-rs tests to arquillian-tomee-jaxrs-tests. SecurityContextIsUsableTest logs in with BASIC auth against a webapp realm.
The provider, exception mapper, Johnzon/JSON-B and bean validation tests of openejb-cxf-rs run in arquillian-tomee-jaxrs-tests; their altdd descriptors are WEB-INF descriptors of each test archive.
The tests deploy each example with Arquillian to TomEE embedded and call the endpoints Tomcat serves; the READMEs show the Arquillian tests and their output.
removePort returned early for every registered port and cleared the wrong map for the service QName, so @WebServiceRef lookups by SEI kept seeing ports of undeployed applications.
The REST example tests deploy to TomEE embedded with Arquillian and call the endpoints over Tomcat; multiple-arquillian-adapters drops its embedded-remote variant.
Without httpejbd nothing registers HttpListenerRegistry or SessionManager, so the request/response/session implementations, embedded servlet/filter/JSP registration and multipart support behind them are dead. LightweightWebAppBuilder keeps listeners, CDI and ServletContext events; HttpUtil keeps selectSingleAddress.
…embedded Observers and the log capture register from a webapp listener before the JAX-RS deployment. arquillian.xml enables the CXF JMX monitoring CxfUtilTest checks.
openejb-cxf keeps GlobalFeatureConfigTest, the other tests need a deployed endpoint. DynamicPortTest only covered httpejbd.port=0.
|
Pushed follow-ups for the review above:
The ported tests surfaced pre-existing bugs:
Side note: CI doesn't run the CDI TCK ( |
…ded only, enable CXF monitoring on remote adapters
# Conflicts: # examples/jsonb-configuration/pom.xml # examples/jsonb-custom-serializer/pom.xml # examples/mp-jsonb-configuration/pom.xml # examples/multiple-arquillian-adapters/pom.xml # examples/rest-applicationcomposer-mockito/pom.xml # examples/rest-applicationcomposer/pom.xml # examples/rest-cdi/pom.xml # examples/rest-on-ejb/pom.xml # examples/rest-xml-json/pom.xml # examples/simple-rest/pom.xml
The servlet bridge the REST, web service and CXF modules build on (HttpListener, HttpRequest, HttpResponse, the servlet adapters, HttpUtil) moves to openejb-server. ServerServlet, EEFilter and the CDI request listeners only run in Tomcat and move to tomee-catalina; a web.xml exposing ejbd over HTTP now uses org.apache.tomee.catalina.remote.ServerServlet. HttpSession, ServletSessionAdapter and BasicAuthHttpListenerWrapper only served the standalone server and go.
…he services start Without a registry RESTService and WsService return from start() before they register themselves or observe deployments, so the deployment paths no longer need null checks. WsService registers the PortAddressRegistry first, @WebServiceRef clients need it even when no endpoint can be published.
…mposer The ApplicationComposer has no HTTP server. @EnableServices loses jaxrs/jaxws, FilteredServiceManager its jaxrs/jaxws aliases and ApplicationComposers its @JaxrsProviders handling; @RandomPort("http") fails instead of injecting a port nothing listens on. The applicationcomposer-maven-plugin ships openejb-ejbd instead of openejb-cxf-rs.
SWClassLoader.getWebResource served the removed embedded web resources, the itests "http" mode targeted httpejbd, and the cdi-embedded TCK no longer needs CXF.
The Jetty dependency management was for the Jetty backend of openejb-http. Nothing uses Jetty directly anymore, so tomee-security and the MicroProfile Rest Client TCK drop their workarounds against it and HtmlUnit resolves a consistent Jetty 9.4.
|
Finished the removal,
Verified: Not covered: the cdi-embedded TCK doesn't start on this branch with or without these changes (HtmlUnit's xalan misses its serializer, then a cdi-tck api/impl mismatch). The standalone assembly's NOTICE still lists libraries it no longer bundles (CXF and older ones), separate cleanup. |
- Proxys, AppFinder.AppOrWebContextTransformer, LogCategory.HTTPSERVER, LightweightWebAppBuilder.LightServletContext and EmbeddedServletContextCreated - the HttpRequest/HttpResponse members of the removed HTTP parser - CxfRsHttpListener's static resource handling (CXFJAXRSFilter calls doInvoke) - the cxf-rs auth/realm settings, TomcatRsRegistry ignores them - @JaxrsProviders.applicationName and its METHOD target - the regex REST wildcard: openejb.rest.wildcard defaults to "*" A missing REST or web service registry is logged at INFO, the webprofile ships openejb-cxf without a WsRegistry.
WsJMXTest runs again and ServerDestroyedTest checks the ServerDestroyed event. SuspendedTest and CdiHandlersTest wait with a bound instead of racing the server, RsInterceptorInjectionTest checks isUserInRole again, and httpejbd/EJBContainer leftovers are gone.
…edded TCK TckTlds and tomee-catalina only served the JSP support of the removed HTTP server. The builtin servlet decorator tests need servlet objects the embedded container no longer registers, and javaee-full tests are already skipped by group.
The openejb-standalone NOTICE/LICENSE no longer list CXF, XmlSchema and libre-wsdl4j, its itest profile no longer runs the http mode, and dependabot no longer ignores Jetty, which no pom declares.
|
Review pass pushed as 7 commits (b962f93..d8ed75b):
Found with 9 rounds of multi-agent review (runtime, tests, examples/docs and build lanes, every finding challenged by a skeptic) until no finding survived. Verified against branch-built jars: arquillian JAX-RS tests 169 run / 10 skipped, JAX-WS 33 run / 2 skipped, migrated examples pass. cdi-embedded is only compile-checked, its harness is broken on main too. Out of scope: Ready for review. |
TomEE serves HTTP through Tomcat, so the hand written HTTP server in
openejb-httpis unused attack surface. This removes the module:HttpListener,HttpRequest/HttpResponse, the servlet adapters) moves toopenejb-server.ServerServlet,EEFilterand the CDI request listeners move totomee-catalina; aweb.xmlexposing ejbd over HTTP now usesorg.apache.tomee.catalina.remote.ServerServlet.httpejbd, the Jetty backend,OpenEJBHttpRegistry,RsRegistryImplandOpenEJBHttpWsRegistryare gone. Without Tomcat's registriesRESTService/WsServicedon't deploy endpoints (logged at INFO);@WebServiceRefclients keep working.openejb-standalone,arquillian-openejb-embeddedand the ApplicationComposer have no HTTP server:@EnableServices(jaxrs/jaxws)and the ApplicationComposer's@JaxrsProvidershandling are removed, and@RandomPort("http")is an ordinary name (it just setshttp.port). Tests and examples that need HTTP run on TomEE embedded.cxf-rsauth/realmservice properties andcxf.jaxrs.static-resources-list.openejb.rest.wildcarddefaults to*.Breaking, meant for the next major.