[ 
https://issues.apache.org/jira/browse/TOMEE-4707?focusedWorklogId=1044170&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1044170
 ]

ASF GitHub Bot logged work on TOMEE-4707:
-----------------------------------------

                Author: ASF GitHub Bot
            Created on: 26/Sep/26 14:57
            Start Date: 26/Sep/26 14:57
    Worklog Time Spent: 10m 
      Work Description: jungm commented on PR #2945:
URL: https://github.com/apache/tomee/pull/2945#issuecomment-5847257644

   Finished the removal, `openejb-http` is gone now:
   
   - Merged `main` (conflicts in the example poms from TOMEE-3234).
   - `openejb-http` deleted: the servlet bridge moved to `openejb-server`, the 
Tomcat-only classes to `tomee-catalina`; `HttpSession`, `ServletSessionAdapter` 
and `BasicAuthHttpListenerWrapper` were dead and are removed.
   - `WsService` registers `PortAddressRegistry` before checking for a 
`WsRegistry`, so `@WebServiceRef` clients work outside TomEE again. Both 
services check their registry once in `start()`, the other null checks are gone.
   - ApplicationComposer: `@EnableServices(jaxrs/jaxws)`, the jaxrs/jaxws 
service aliases and `@JaxrsProviders` handling removed, `@RandomPort("http")` 
fails fast. `applicationcomposer-maven-plugin` ships `openejb-ejbd` instead of 
`openejb-cxf-rs`.
   - Leftovers removed: `SWClassLoader.getWebResource`, the itests `http` mode, 
CXF deps of the cdi-embedded TCK, stale docs; the JAX-RS tests use 
`ArquillianUtil` for the embedded check.
   - Jetty dependency management dropped, it only existed for the 
`openejb-http` Jetty backend.
   
   Verified: `clean install -DskipTests -Pstyle,rat`; tests of openejb-core 
(4118), openejb-junit5, the server modules, 
tomee-catalina/jaxrs/webservices/embedded, the OpenEJB Arquillian adapter; 
Arquillian on TomEE embedded: JAX-RS 169, JAX-WS 32, web profile 159, all 
green. tomee-remote suites not run.
   
   Not covered: the cdi-embedded TCK doesn't start on this branch with or 
without these changes (HtmlUnit's xalan misses its serializer, then a cdi-tck 
api/impl mismatch). The standalone assembly's NOTICE still lists libraries it 
no longer bundles (CXF and older ones), separate cleanup.
   




Issue Time Tracking
-------------------

    Worklog Id:     (was: 1044170)
    Time Spent: 0.5h  (was: 20m)

> Drop the standalone HTTP server from openejb-http
> -------------------------------------------------
>
>                 Key: TOMEE-4707
>                 URL: https://issues.apache.org/jira/browse/TOMEE-4707
>             Project: TomEE
>          Issue Type: Task
>            Reporter: Richard Zowalla
>            Priority: Major
>             Fix For: 11.0.0
>
>          Time Spent: 0.5h
>  Remaining Estimate: 0h
>
> openejb\-http carries a standalone HTTP server that TomEE itself never uses:
> requests arrive through Tomcat's connectors. It parses HTTP off a socket by
> hand, which is a large and rarely exercised attack surface for no benefit, so
> it is removed for 11.
> Removed from openejb\-http:* The homebrew server: {{OpenEJBHttpServer}}, 
> {{OpenEJBHttpEjbServer}},
> {{HttpServer}}, {{HttpServerFactory}}, {{HttpEjbServer}} and
> {{ServerServiceAdapter}}, plus the {{httpejbd}} ServerService descriptor.
> * The Jetty backend: {{JettyHttpServer}} and {{JettyHttpEjbServer}}, and the
> optional Jetty dependencies and OSGi import. {{HttpServerFactory}} only chose
> it when Jetty 6's {{org.mortbay.jetty.Connector}} was loadable, which never
> happens, so it was already unreachable.
> * The unreferenced {{ServletIntputStreamAdapter}} and
> {{ServletOutputStreamAdapter}}.
> * {{OpenEJBHttpRegistry}}, whose base URIs came from the {{httpejbd}} service
> configuration.
> Migrated:
> * {{OpenEJBHttpServer.isTextXml}} and {{reformat}}, used by 
> {{HttpRequestImpl}}
> and {{HttpResponseImpl}} to pretty print XML when dumping, move to
> {{HttpUtil}}.
> * {{RsRegistryImpl}} and {{OpenEJBHttpWsRegistry}} extended
> {{OpenEJBHttpRegistry}} and were the non\-Tomcat fallbacks in
> {{RESTService.beforeStart\(\)}} and {{WsService.start\(\)}}. Both registries 
> and
> both fallbacks are removed; under Tomcat, {{TomcatRsRegistry}} and
> {{TomcatWsRegistry}} are used and are unaffected.
> Kept: everything Tomcat needs. {{HttpListener}}, {{HttpListenerRegistry}}, the
> request, response and session abstractions with their implementations, the
> servlet and filter adapters, {{ServerServlet}}, the CDI listeners,
> {{BasicAuthHttpListenerWrapper}}, {{SessionManager}} and {{HttpUtil}}.
> Consequence: openejb\-standalone and arquillian\-openejb\-embedded no longer 
> have
> embedded REST or web service wiring. That is accepted for a major release.
> Tests: the suites that drove the removed transport over a socket are removed
> with it \({{HttpEjbServerTest}}, which aggregated the EJBD over HTTP suites,
> {{AsyncHttpTest}}, {{CustomHttpMethodTest}}, {{FilterRegistrationTest}},
> {{OpenEJBHttpServerTest}}, {{ResourcesTest}}, {{ServletRegistrationTest}},
> {{HttpResponseImplSessionTest}}, and the already empty {{JettyTest}}\). The
> remaining 14 tests pass, and openejb\-rest, openejb\-webservices, 
> openejb\-cxf\-rs,
> openejb\-cxf\-transport, tomee\-catalina, tomee\-jaxrs, tomee\-webservices,
> openejb\-standalone and arquillian\-openejb\-embedded all build.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to