Conversation
…2945) * TOMEE-4707 drop the standalone HTTP server from openejb-http TomEE serves requests through Tomcat's connectors, so the hand written HTTP server in openejb-http is unused attack surface. Removes it, the unreachable Jetty backend, the httpejbd service and OpenEJBHttpRegistry. isTextXml and reformat move to HttpUtil. RsRegistryImpl and OpenEJBHttpWsRegistry extended OpenEJBHttpRegistry and were the non-Tomcat fallbacks in RESTService and WsService; both go, so openejb-standalone and arquillian-openejb-embedded lose embedded REST/WS wiring. Everything Tomcat needs stays: listeners, the registry, request, response and session, the servlet and filter adapters, ServerServlet and the CDI listeners. The tests that drove the removed transport over a socket go with it. * TOMEE-4707 drop what still pointed at httpejbd RESTService and WsService log a warning and skip deployment when no registry is available instead of failing with an NPE per application. The embedded Arquillian adapter no longer advertises an HTTP URL, openejb-standalone stops shipping the HTTP, CXF and CXF-RS modules, and the httpejbd aliases, debug flags, docs and test leftovers go. cdi-embedded excludes the CDI TCK tests that need an HTTP server; cdi-tomee runs them. * TOMEE-4707 run CDIApplicationTest on TomEE embedded Moves the shared JAX-RS test beans to arquillian-tomee-jaxrs-tests, where the tests using them run against Tomcat. * TOMEE-4707 drop httpejbd from the docs ApplicationComposer docs point to TomEE embedded and the Arquillian TomEE adapters for testing JAX-RS and JAX-WS endpoints over HTTP. * TOMEE-4707 drop the ApplicationComposer REST/WS examples rest-applicationcomposer, rest-applicationcomposer-mockito and applicationcomposer-jaxws-cdi relied on ApplicationComposer serving HTTP. * TOMEE-4707 run JAX-RS application, routing and provider tests on TomEE embedded Moves the Application/web.xml deployment, routing, provider and response tests from openejb-cxf-rs to arquillian-tomee-jaxrs-tests, where they deploy a war on Tomcat instead of the removed embedded HTTP server. * TOMEE-4707 run JAX-RS CDI, EJB, security and async tests on TomEE embedded Moves the ApplicationComposer/EJBContainer based cxf-rs tests to arquillian-tomee-jaxrs-tests. SecurityContextIsUsableTest logs in with BASIC auth against a webapp realm. * TOMEE-4707 run JAX-RS provider, JSON and bval tests on TomEE embedded The provider, exception mapper, Johnzon/JSON-B and bean validation tests of openejb-cxf-rs run in arquillian-tomee-jaxrs-tests; their altdd descriptors are WEB-INF descriptors of each test archive. * TOMEE-4707 run the web service examples on TomEE embedded The tests deploy each example with Arquillian to TomEE embedded and call the endpoints Tomcat serves; the READMEs show the Arquillian tests and their output. * TOMEE-4707 remove undeployed web service ports from PortAddressRegistry removePort returned early for every registered port and cleared the wrong map for the service QName, so @WebServiceRef lookups by SEI kept seeing ports of undeployed applications. * TOMEE-4707 run the REST examples on TomEE embedded The REST example tests deploy to TomEE embedded with Arquillian and call the endpoints over Tomcat; multiple-arquillian-adapters drops its embedded-remote variant. * TOMEE-4707 remove the unreachable embedded HTTP transport Without httpejbd nothing registers HttpListenerRegistry or SessionManager, so the request/response/session implementations, embedded servlet/filter/JSP registration and multipart support behind them are dead. LightweightWebAppBuilder keeps listeners, CDI and ServletContext events; HttpUtil keeps selectSingleAddress. * TOMEE-4707 run the JAX-RS event, jmx, cli and logging tests on TomEE embedded Observers and the log capture register from a webapp listener before the JAX-RS deployment. arquillian.xml enables the CXF JMX monitoring CxfUtilTest checks. * TOMEE-4707 run the JAX-WS tests on TomEE embedded openejb-cxf keeps GlobalFeatureConfigTest, the other tests need a deployed endpoint. DynamicPortTest only covered httpejbd.port=0. * TOMEE-4707 drop openejb-cxf-rs test leftovers * TOMEE-4707 skip REST and web service deployment when no registry is available * TOMEE-4707 run the in-JVM JAX-RS JMX and logging tests on TomEE embedded only, enable CXF monitoring on remote adapters * TOMEE-4707 observe the JAX-WS server events in-container in EventTest * TOMEE-4707 ship the enclosing test class in the JAX-RS test archives * TOMEE-4707 remove the openejb-http module The servlet bridge the REST, web service and CXF modules build on (HttpListener, HttpRequest, HttpResponse, the servlet adapters, HttpUtil) moves to openejb-server. ServerServlet, EEFilter and the CDI request listeners only run in Tomcat and move to tomee-catalina; a web.xml exposing ejbd over HTTP now uses org.apache.tomee.catalina.remote.ServerServlet. HttpSession, ServletSessionAdapter and BasicAuthHttpListenerWrapper only served the standalone server and go. * TOMEE-4707 check for the REST and web service registries once, when the services start Without a registry RESTService and WsService return from start() before they register themselves or observe deployments, so the deployment paths no longer need null checks. WsService registers the PortAddressRegistry first, @WebServiceRef clients need it even when no endpoint can be published. * TOMEE-4707 drop the REST and web service options of the ApplicationComposer The ApplicationComposer has no HTTP server. @EnableServices loses jaxrs/jaxws, FilteredServiceManager its jaxrs/jaxws aliases and ApplicationComposers its @JaxrsProviders handling; @RandomPort("http") fails instead of injecting a port nothing listens on. The applicationcomposer-maven-plugin ships openejb-ejbd instead of openejb-cxf-rs. * TOMEE-4707 remove what is left of the embedded HTTP transport SWClassLoader.getWebResource served the removed embedded web resources, the itests "http" mode targeted httpejbd, and the cdi-embedded TCK no longer needs CXF. * TOMEE-4707 use ArquillianUtil to detect TomEE embedded in the JAX-RS tests * TOMEE-4707 stop managing Jetty versions The Jetty dependency management was for the Jetty backend of openejb-http. Nothing uses Jetty directly anymore, so tomee-security and the MicroProfile Rest Client TCK drop their workarounds against it and HtmlUnit resolves a consistent Jetty 9.4. * TOMEE-4707 treat @RandomPort("http") like any other name * TOMEE-4707 drop what only the embedded HTTP transport used - Proxys, AppFinder.AppOrWebContextTransformer, LogCategory.HTTPSERVER, LightweightWebAppBuilder.LightServletContext and EmbeddedServletContextCreated - the HttpRequest/HttpResponse members of the removed HTTP parser - CxfRsHttpListener's static resource handling (CXFJAXRSFilter calls doInvoke) - the cxf-rs auth/realm settings, TomcatRsRegistry ignores them - @JaxrsProviders.applicationName and its METHOD target - the regex REST wildcard: openejb.rest.wildcard defaults to "*" A missing REST or web service registry is logged at INFO, the webprofile ships openejb-cxf without a WsRegistry. * TOMEE-4707 tidy the tests moved to TomEE embedded WsJMXTest runs again and ServerDestroyedTest checks the ServerDestroyed event. SuspendedTest and CdiHandlersTest wait with a bound instead of racing the server, RsInterceptorInjectionTest checks isUserInRole again, and httpejbd/EJBContainer leftovers are gone. * TOMEE-4707 drop the JSP and server service leftovers from the cdi-embedded TCK TckTlds and tomee-catalina only served the JSP support of the removed HTTP server. The builtin servlet decorator tests need servlet objects the embedded container no longer registers, and javaee-full tests are already skipped by group. * TOMEE-4707 align the docs with the removed embedded HTTP server * TOMEE-4707 drop leftovers from the examples moved to TomEE embedded * TOMEE-4707 drop build leftovers of the removed HTTP server The openejb-standalone NOTICE/LICENSE no longer list CXF, XmlSchema and libre-wsdl4j, its itest profile no longer runs the http mode, and dependabot no longer ignores Jetty, which no pom declares. --------- Co-authored-by: Markus Jung <jungm@apache.org> (cherry picked from commit 5c6b5a3)
…SNAPSHOT javamail, mp-jsonb-configuration, mtom, multiple-arquillian-adapters and rest-on-ejb resolve tomee-plus-api and arquillian-tomee-embedded through tomee.version.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #2945 to
tomee-10.x.TomEE serves HTTP through Tomcat, so the hand written HTTP server in
openejb-httpis unused attack surface. This removes the module:HttpListener,HttpRequest/HttpResponse, the servlet adapters) moves toopenejb-server.ServerServlet,EEFilterand the CDI request listeners move totomee-catalina; aweb.xmlexposing ejbd over HTTP now usesorg.apache.tomee.catalina.remote.ServerServlet.httpejbd, the Jetty backend,OpenEJBHttpRegistry,RsRegistryImplandOpenEJBHttpWsRegistryare gone. Without Tomcat's registriesRESTService/WsServicedon't deploy endpoints (logged at INFO);@WebServiceRefclients keep working.openejb-standalone,arquillian-openejb-embeddedand the ApplicationComposer have no HTTP server:@EnableServices(jaxrs/jaxws)and the ApplicationComposer's@JaxrsProvidershandling are removed, and@RandomPort("http")is an ordinary name (it just setshttp.port). Tests and examples that need HTTP run on TomEE embedded.cxf-rsauth/realmservice properties andcxf.jaxrs.static-resources-list.openejb.rest.wildcarddefaults to*.Differences from the
mainchange:openejb-http(noopenejb-jakarta-dataon 10.x).10.3.0-SNAPSHOT;javamail,mp-jsonb-configuration,mtom,multiple-arquillian-adaptersandrest-on-ejbhadtomee.versionstuck at10.2.1-SNAPSHOTand are bumped, since they now resolvetomee-plus-apiandarquillian-tomee-embeddedthrough it.SECURITY.mdandexamples/multiple-arquillian-adapters/README.adocdon't exist on 10.x and stay absent.Note that #2945 is a breaking change that was meant for the next major.