[
https://issues.apache.org/jira/browse/TOMEE-4713?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Markus Jung updated TOMEE-4713:
-------------------------------
Description:
{{CXFJAXRSFilter}} decides per request whether a URL belongs to JAX-RS: it
pre-matches class level {{@Path}} templates, serves static files first, gives
mapped servlets priority by servlet name and detects welcome-file rewrites.
That duplicates what Tomcat's servlet mapper already does and has produced a
series of routing bugs (TOMEE-2148, TOMEE-2467, TOMEE-4406, TOMEE-4424,
TOMEE-4481, TOMEE-4659).
Each JAX-RS application is served by its own servlet instead, so the Servlet
mapping rules decide routing (Jakarta REST 4.0 section 2.3.2):
* A servlet declared for the application in web.xml keeps its name and init
parameters, its first mapping defines the application path. Otherwise the
servlet is named after the {{Application}} subclass,
{{jakarta.ws.rs.core.Application}} without one, so filters can be mapped to it
by servlet name.
* {{@ApplicationPath}}: {{<path>/*}}, including {{@ApplicationPath("/")}}.
* No declared mapping (TomEE extension, served from the context root): {{/}},
the default servlet slot. JSP, Faces and user servlets keep priority, the
container's default servlet keeps serving static files, directories and
includes, and unmatched requests end with a 404 the error pages apply to.
* {{openejb.jaxrs.root-as-default-servlet=true}} maps {{@ApplicationPath("/")}}
to {{/}} as well, for applications that serve static files, JSPs or Faces views
next to it.
* JAX-RS matches the canonical request URI, the path the container mapped and
applied its security constraints to (Servlet 6.1 section 3.5.2, Jakarta REST
3.7.1).
Behaviour changes:
* Static files under an application path belong to the application;
{{openejb.jaxrs.static-first}} has no effect.
* For an application without a declared mapping, Tomcat's mapper tries welcome
files, and the servlets their extension maps to, on a path ending with {{/}}
before the default servlet slot.
* Filters mapped to the servlet named {{default}} do not apply to requests an
application in the default servlet slot serves (a warning is logged).
* In the MicroProfile distribution the health endpoint puts every web
application without {{Application}} subclass in the default servlet slot.
Fixed along the way: unmatched paths return 404 instead of Tomcat's 405 for
PUT/DELETE (TOMEE-4659), {{@ApplicationPath}} endpoints stay reachable next to
a {{/*}} servlet (TOMEE-4481), {{@Context ServletConfig}} is injected, and
endpoint deployments configured through {{cxf.jaxrs.*}} properties no longer
answer 404. The JAX-RS TCK runs without replacing the default servlet.
was:
{{CXFJAXRSFilter}} decides per request whether a URL belongs to JAX-RS: it
pre-matches class level {{@Path}} templates, serves static files first, gives
mapped servlets priority by servlet name and detects welcome-file rewrites.
That duplicates what Tomcat's servlet mapper already does and has produced a
series of routing bugs (TOMEE-2148, TOMEE-2467, TOMEE-4406, TOMEE-4424,
TOMEE-4481, TOMEE-4659).
Each JAX-RS application is served by its own servlet instead, so the Servlet
mapping rules decide routing (Jakarta REST 4.0 section 2.3.2):
* A servlet declared for the application in web.xml keeps its name, init
parameters and mapping. Otherwise the servlet is named after the
{{Application}} subclass, {{jakarta.ws.rs.core.Application}} without one, so
filters can be mapped to it by servlet name.
* {{@ApplicationPath}}: {{<path>/*}}, including {{@ApplicationPath("/")}}.
* No declared mapping (TomEE extension, served from the context root): {{/}},
the default servlet slot. JSP, Faces and user servlets keep priority, the
container's default servlet keeps serving static files and directories, and
unmatched requests end with {{sendError}} so error pages apply.
* {{openejb.jaxrs.root-as-default-servlet=true}} maps {{@ApplicationPath("/")}}
to {{/}} as well, for applications that serve static files, JSPs or Faces views
next to it.
Behaviour changes:
* Static files under an application path belong to the application;
{{openejb.jaxrs.static-first}} is removed.
* For an application without a declared mapping, Tomcat's mapper tries welcome
files, and the servlets their extension maps to, on a path ending with {{/}}
before the default servlet slot.
* Filters mapped to the servlet named {{default}} do not apply to requests an
application in the default servlet slot serves (a warning is logged).
Fixed along the way: unmatched paths return 404 instead of Tomcat's 405 for
PUT/DELETE (TOMEE-4659), {{@ApplicationPath}} endpoints stay reachable next to
a {{/*}} servlet (TOMEE-4481), {{@Context ServletConfig}} is injected, and
endpoint deployments configured through {{cxf.jaxrs.*}} properties no longer
answer 404. The JAX-RS TCK runs without replacing the default servlet.
> Serve JAX-RS applications through a servlet mapping instead of CXFJAXRSFilter
> -----------------------------------------------------------------------------
>
> Key: TOMEE-4713
> URL: https://issues.apache.org/jira/browse/TOMEE-4713
> Project: TomEE
> Issue Type: Improvement
> Reporter: Markus Jung
> Assignee: Markus Jung
> Priority: Major
> Fix For: 11.0.0
>
>
> {{CXFJAXRSFilter}} decides per request whether a URL belongs to JAX-RS: it
> pre-matches class level {{@Path}} templates, serves static files first, gives
> mapped servlets priority by servlet name and detects welcome-file rewrites.
> That duplicates what Tomcat's servlet mapper already does and has produced a
> series of routing bugs (TOMEE-2148, TOMEE-2467, TOMEE-4406, TOMEE-4424,
> TOMEE-4481, TOMEE-4659).
> Each JAX-RS application is served by its own servlet instead, so the Servlet
> mapping rules decide routing (Jakarta REST 4.0 section 2.3.2):
> * A servlet declared for the application in web.xml keeps its name and init
> parameters, its first mapping defines the application path. Otherwise the
> servlet is named after the {{Application}} subclass,
> {{jakarta.ws.rs.core.Application}} without one, so filters can be mapped to
> it by servlet name.
> * {{@ApplicationPath}}: {{<path>/*}}, including {{@ApplicationPath("/")}}.
> * No declared mapping (TomEE extension, served from the context root): {{/}},
> the default servlet slot. JSP, Faces and user servlets keep priority, the
> container's default servlet keeps serving static files, directories and
> includes, and unmatched requests end with a 404 the error pages apply to.
> * {{openejb.jaxrs.root-as-default-servlet=true}} maps
> {{@ApplicationPath("/")}} to {{/}} as well, for applications that serve
> static files, JSPs or Faces views next to it.
> * JAX-RS matches the canonical request URI, the path the container mapped and
> applied its security constraints to (Servlet 6.1 section 3.5.2, Jakarta REST
> 3.7.1).
> Behaviour changes:
> * Static files under an application path belong to the application;
> {{openejb.jaxrs.static-first}} has no effect.
> * For an application without a declared mapping, Tomcat's mapper tries
> welcome files, and the servlets their extension maps to, on a path ending
> with {{/}} before the default servlet slot.
> * Filters mapped to the servlet named {{default}} do not apply to requests an
> application in the default servlet slot serves (a warning is logged).
> * In the MicroProfile distribution the health endpoint puts every web
> application without {{Application}} subclass in the default servlet slot.
> Fixed along the way: unmatched paths return 404 instead of Tomcat's 405 for
> PUT/DELETE (TOMEE-4659), {{@ApplicationPath}} endpoints stay reachable next
> to a {{/*}} servlet (TOMEE-4481), {{@Context ServletConfig}} is injected, and
> endpoint deployments configured through {{cxf.jaxrs.*}} properties no longer
> answer 404. The JAX-RS TCK runs without replacing the default servlet.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)