[
https://issues.apache.org/jira/browse/TOMEE-4728?focusedWorklogId=1046163&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1046163
]
ASF GitHub Bot logged work on TOMEE-4728:
-----------------------------------------
Author: ASF GitHub Bot
Created on: 07/Oct/26 12:50
Start Date: 07/Oct/26 12:50
Worklog Time Spent: 10m
Work Description: jungm opened a new pull request, #3064:
URL: https://github.com/apache/tomee/pull/3064
Fixes [TOMEE-4728](https://issues.apache.org/jira/browse/TOMEE-4728)
## Summary
A webapp declaring `@ApplicationPath("/api")` with its own pre-matching
filter in `getClasses()` gets the MicroProfile Health endpoint (TOMEE-4716) in
a separate container application at `/`. That application was deployed with the
providers collected from the declared applications, so the filter ran for
`/health` too.
```diff
RESTService.deployApplications
additionalProviders = webapp-wide providers
+ webAppProviders = copy of additionalProviders
for each declared Application
additionalProviders += its getClasses()/getSingletons() providers
deploy it with additionalProviders
if no declared Application at "/" and container resources exist
- deploy InternalApplication(health) with additionalProviders
+ deploy InternalApplication(health) with webAppProviders
```
## Evidence
`HealthEndpointTest.applicationWithItsOwnProvider`
(`tomee-microprofile-itests`):
```text
deploy @ApplicationPath("/api") listing HelloResource + @PreMatching filter
aborting with 503
GET /test/api/hello → 503 (filter applies in its own application)
GET /test/health → 200
GET /test/health/live → 200
```
- **Before:** `HealthEndpointTest.applicationWithItsOwnProvider:139
expected:<200> but was:<503>`
**After:** green, with the rest of `tomee-microprofile-itests` (12 tests),
`microprofile-jwt-itests` (51, 3 skipped), `openejb-rest` and `openejb-cxf-rs`
## Merge Danger
**Door:** two-way
**Blast Radius:** health-endpoint
Only the container application deployed next to declared applications not at
`/` changes, which means MicroProfile distributions with health. Webapp-wide
(scanned) providers still apply to it. A provider that a declared application
lists only in its own `getClasses()`/`getSingletons()` no longer runs for
`/health`.
Issue Time Tracking
-------------------
Worklog Id: (was: 1046163)
Remaining Estimate: 0h
Time Spent: 10m
> MicroProfile Health endpoint runs the providers of a declared JAX-RS
> application
> --------------------------------------------------------------------------------
>
> Key: TOMEE-4728
> URL: https://issues.apache.org/jira/browse/TOMEE-4728
> Project: TomEE
> Issue Type: Bug
> Reporter: Markus Jung
> Priority: Major
> Time Spent: 10m
> Remaining Estimate: 0h
>
> Since TOMEE-4716, {{RESTService}} deploys the MicroProfile Health endpoint
> ({{MicroProfileHealthChecksEndpoint}}) in its own {{InternalApplication}} at
> the context root when the webapp declares JAX-RS applications, but none at
> the context root.
> That application is deployed with {{additionalProviders}}, the collection
> that the loop over the declared applications fills with the providers each
> one lists in {{getClasses()}} / {{getSingletons()}}. So a provider meant for
> one application, e.g. an unbound {{@PreMatching}} {{ContainerRequestFilter}}
> of an application at {{/api}}, also runs for {{/health}}, {{/health/live}},
> {{/health/ready}} and {{/health/started}}.
> With a filter that aborts every request it doesn't recognize, all health
> endpoints answer with that filter's response instead of the health checks.
> Seen with an MCP server application whose pre-matching filter answers {{503}}
> with an empty body outside its own application: every {{/health}} request
> returns {{503}}, and the endpoint method never runs.
> Fix: deploy the container application with only the webapp-wide providers,
> those collected before the declared applications add their own.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)