Richard Zowalla created TOMEE-4707:
--------------------------------------

             Summary: Drop the standalone HTTP server from openejb-http
                 Key: TOMEE-4707
                 URL: https://issues.apache.org/jira/browse/TOMEE-4707
             Project: TomEE
          Issue Type: Task
            Reporter: Richard Zowalla
             Fix For: 11.0.0


openejb\-http carries a standalone HTTP server that TomEE itself never uses:
requests arrive through Tomcat's connectors. It parses HTTP off a socket by
hand, which is a large and rarely exercised attack surface for no benefit, so
it is removed for 11.

Removed from openejb\-http:* The homebrew server: {{OpenEJBHttpServer}}, 
{{OpenEJBHttpEjbServer}},
{{HttpServer}}, {{HttpServerFactory}}, {{HttpEjbServer}} and
{{ServerServiceAdapter}}, plus the {{httpejbd}} ServerService descriptor.
* The Jetty backend: {{JettyHttpServer}} and {{JettyHttpEjbServer}}, and the
optional Jetty dependencies and OSGi import. {{HttpServerFactory}} only chose
it when Jetty 6's {{org.mortbay.jetty.Connector}} was loadable, which never
happens, so it was already unreachable.
* The unreferenced {{ServletIntputStreamAdapter}} and
{{ServletOutputStreamAdapter}}.
* {{OpenEJBHttpRegistry}}, whose base URIs came from the {{httpejbd}} service
configuration.

Migrated:

* {{OpenEJBHttpServer.isTextXml}} and {{reformat}}, used by {{HttpRequestImpl}}
and {{HttpResponseImpl}} to pretty print XML when dumping, move to
{{HttpUtil}}.
* {{RsRegistryImpl}} and {{OpenEJBHttpWsRegistry}} extended
{{OpenEJBHttpRegistry}} and were the non\-Tomcat fallbacks in
{{RESTService.beforeStart\(\)}} and {{WsService.start\(\)}}. Both registries and
both fallbacks are removed; under Tomcat, {{TomcatRsRegistry}} and
{{TomcatWsRegistry}} are used and are unaffected.

Kept: everything Tomcat needs. {{HttpListener}}, {{HttpListenerRegistry}}, the
request, response and session abstractions with their implementations, the
servlet and filter adapters, {{ServerServlet}}, the CDI listeners,
{{BasicAuthHttpListenerWrapper}}, {{SessionManager}} and {{HttpUtil}}.

Consequence: openejb\-standalone and arquillian\-openejb\-embedded no longer 
have
embedded REST or web service wiring. That is accepted for a major release.

Tests: the suites that drove the removed transport over a socket are removed
with it \({{HttpEjbServerTest}}, which aggregated the EJBD over HTTP suites,
{{AsyncHttpTest}}, {{CustomHttpMethodTest}}, {{FilterRegistrationTest}},
{{OpenEJBHttpServerTest}}, {{ResourcesTest}}, {{ServletRegistrationTest}},
{{HttpResponseImplSessionTest}}, and the already empty {{JettyTest}}\). The
remaining 14 tests pass, and openejb\-rest, openejb\-webservices, 
openejb\-cxf\-rs,
openejb\-cxf\-transport, tomee\-catalina, tomee\-jaxrs, tomee\-webservices,
openejb\-standalone and arquillian\-openejb\-embedded all build.





--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to