[
https://issues.apache.org/jira/browse/TOMEE-4707?focusedWorklogId=1044794&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1044794
]
ASF GitHub Bot logged work on TOMEE-4707:
-----------------------------------------
Author: ASF GitHub Bot
Created on: 30/Sep/26 09:24
Start Date: 30/Sep/26 09:24
Worklog Time Spent: 10m
Work Description: jungm opened a new pull request, #2981:
URL: https://github.com/apache/tomee/pull/2981
Backport of #2945 to `tomee-10.x`.
TomEE serves HTTP through Tomcat, so the hand written HTTP server in
`openejb-http` is unused attack surface. This removes the module:
- The servlet bridge REST, web services and CXF build on (`HttpListener`,
`HttpRequest`/`HttpResponse`, the servlet adapters) moves to `openejb-server`.
`ServerServlet`, `EEFilter` and the CDI request listeners move to
`tomee-catalina`; a `web.xml` exposing ejbd over HTTP now uses
`org.apache.tomee.catalina.remote.ServerServlet`.
- `httpejbd`, the Jetty backend, `OpenEJBHttpRegistry`, `RsRegistryImpl` and
`OpenEJBHttpWsRegistry` are gone. Without Tomcat's registries
`RESTService`/`WsService` don't deploy endpoints (logged at INFO);
`@WebServiceRef` clients keep working.
- `openejb-standalone`, `arquillian-openejb-embedded` and the
ApplicationComposer have no HTTP server: `@EnableServices(jaxrs/jaxws)` and the
ApplicationComposer's `@JaxrsProviders` handling are removed, and
`@RandomPort("http")` is an ordinary name (it just sets `http.port`). Tests and
examples that need HTTP run on TomEE embedded.
- Settings only the embedded transport read are gone: the `cxf-rs`
`auth`/`realm` service properties and `cxf.jaxrs.static-resources-list`.
`openejb.rest.wildcard` defaults to `*`.
- The root pom no longer manages Jetty versions.
Differences from the `main` change:
- The BOMs only drop `openejb-http` (no `openejb-jakarta-data` on 10.x).
- The MicroProfile Rest Client TCK keeps its explicit Jetty 9.2 / WireMock 2
setup, which doesn't depend on the root pom's Jetty management.
- The examples moved to TomEE embedded use `10.3.0-SNAPSHOT`; `javamail`,
`mp-jsonb-configuration`, `mtom`, `multiple-arquillian-adapters` and
`rest-on-ejb` had `tomee.version` stuck at `10.2.1-SNAPSHOT` and are bumped,
since they now resolve `tomee-plus-api` and `arquillian-tomee-embedded` through
it.
- `SECURITY.md` and `examples/multiple-arquillian-adapters/README.adoc`
don't exist on 10.x and stay absent.
Note that #2945 is a breaking change that was meant for the next major.
Issue Time Tracking
-------------------
Worklog Id: (was: 1044794)
Time Spent: 1h 20m (was: 1h 10m)
> Drop the standalone HTTP server from openejb-http
> -------------------------------------------------
>
> Key: TOMEE-4707
> URL: https://issues.apache.org/jira/browse/TOMEE-4707
> Project: TomEE
> Issue Type: Task
> Reporter: Richard Zowalla
> Priority: Major
> Fix For: 11.0.0
>
> Time Spent: 1h 20m
> Remaining Estimate: 0h
>
> openejb\-http carries a standalone HTTP server that TomEE itself never uses:
> requests arrive through Tomcat's connectors. It parses HTTP off a socket by
> hand, which is a large and rarely exercised attack surface for no benefit, so
> it is removed for 11.
> Removed from openejb\-http:* The homebrew server: {{OpenEJBHttpServer}},
> {{OpenEJBHttpEjbServer}},
> {{HttpServer}}, {{HttpServerFactory}}, {{HttpEjbServer}} and
> {{ServerServiceAdapter}}, plus the {{httpejbd}} ServerService descriptor.
> * The Jetty backend: {{JettyHttpServer}} and {{JettyHttpEjbServer}}, and the
> optional Jetty dependencies and OSGi import. {{HttpServerFactory}} only chose
> it when Jetty 6's {{org.mortbay.jetty.Connector}} was loadable, which never
> happens, so it was already unreachable.
> * The unreferenced {{ServletIntputStreamAdapter}} and
> {{ServletOutputStreamAdapter}}.
> * {{OpenEJBHttpRegistry}}, whose base URIs came from the {{httpejbd}} service
> configuration.
> Migrated:
> * {{OpenEJBHttpServer.isTextXml}} and {{reformat}}, used by
> {{HttpRequestImpl}}
> and {{HttpResponseImpl}} to pretty print XML when dumping, move to
> {{HttpUtil}}.
> * {{RsRegistryImpl}} and {{OpenEJBHttpWsRegistry}} extended
> {{OpenEJBHttpRegistry}} and were the non\-Tomcat fallbacks in
> {{RESTService.beforeStart\(\)}} and {{WsService.start\(\)}}. Both registries
> and
> both fallbacks are removed; under Tomcat, {{TomcatRsRegistry}} and
> {{TomcatWsRegistry}} are used and are unaffected.
> Kept: everything Tomcat needs. {{HttpListener}}, {{HttpListenerRegistry}}, the
> request, response and session abstractions with their implementations, the
> servlet and filter adapters, {{ServerServlet}}, the CDI listeners,
> {{BasicAuthHttpListenerWrapper}}, {{SessionManager}} and {{HttpUtil}}.
> Consequence: openejb\-standalone and arquillian\-openejb\-embedded no longer
> have
> embedded REST or web service wiring. That is accepted for a major release.
> Tests: the suites that drove the removed transport over a socket are removed
> with it \({{HttpEjbServerTest}}, which aggregated the EJBD over HTTP suites,
> {{AsyncHttpTest}}, {{CustomHttpMethodTest}}, {{FilterRegistrationTest}},
> {{OpenEJBHttpServerTest}}, {{ResourcesTest}}, {{ServletRegistrationTest}},
> {{HttpResponseImplSessionTest}}, and the already empty {{JettyTest}}\). The
> remaining 14 tests pass, and openejb\-rest, openejb\-webservices,
> openejb\-cxf\-rs,
> openejb\-cxf\-transport, tomee\-catalina, tomee\-jaxrs, tomee\-webservices,
> openejb\-standalone and arquillian\-openejb\-embedded all build.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)