jungm opened a new pull request, #2981:
URL: https://github.com/apache/tomee/pull/2981

   Backport of #2945 to `tomee-10.x`.
   
   TomEE serves HTTP through Tomcat, so the hand written HTTP server in 
`openejb-http` is unused attack surface. This removes the module:
   
   - The servlet bridge REST, web services and CXF build on (`HttpListener`, 
`HttpRequest`/`HttpResponse`, the servlet adapters) moves to `openejb-server`. 
`ServerServlet`, `EEFilter` and the CDI request listeners move to 
`tomee-catalina`; a `web.xml` exposing ejbd over HTTP now uses 
`org.apache.tomee.catalina.remote.ServerServlet`.
   - `httpejbd`, the Jetty backend, `OpenEJBHttpRegistry`, `RsRegistryImpl` and 
`OpenEJBHttpWsRegistry` are gone. Without Tomcat's registries 
`RESTService`/`WsService` don't deploy endpoints (logged at INFO); 
`@WebServiceRef` clients keep working.
   - `openejb-standalone`, `arquillian-openejb-embedded` and the 
ApplicationComposer have no HTTP server: `@EnableServices(jaxrs/jaxws)` and the 
ApplicationComposer's `@JaxrsProviders` handling are removed, and 
`@RandomPort("http")` is an ordinary name (it just sets `http.port`). Tests and 
examples that need HTTP run on TomEE embedded.
   - Settings only the embedded transport read are gone: the `cxf-rs` 
`auth`/`realm` service properties and `cxf.jaxrs.static-resources-list`. 
`openejb.rest.wildcard` defaults to `*`.
   - The root pom no longer manages Jetty versions.
   
   Differences from the `main` change:
   - The BOMs only drop `openejb-http` (no `openejb-jakarta-data` on 10.x).
   - The MicroProfile Rest Client TCK keeps its explicit Jetty 9.2 / WireMock 2 
setup, which doesn't depend on the root pom's Jetty management.
   - The examples moved to TomEE embedded use `10.3.0-SNAPSHOT`; `javamail`, 
`mp-jsonb-configuration`, `mtom`, `multiple-arquillian-adapters` and 
`rest-on-ejb` had `tomee.version` stuck at `10.2.1-SNAPSHOT` and are bumped, 
since they now resolve `tomee-plus-api` and `arquillian-tomee-embedded` through 
it.
   - `SECURITY.md` and `examples/multiple-arquillian-adapters/README.adoc` 
don't exist on 10.x and stay absent.
   
   Note that #2945 is a breaking change that was meant for the next major.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to