snoopdave opened a new pull request, #199:
URL: https://github.com/apache/roller/pull/199

   ## Summary
   
   Weblog templates are rendered under the Velocity `SecureUberspector`, which 
governs method access — but until now the pojo wrappers still exposed the 
wrapped objects themselves through their public `getPojo()` methods, making 
every getter and setter on those objects reachable from a weblog template.
   
   - **`WeblogWrapper.getPojo()` and `WeblogEntryWrapper.getPojo()` are now 
package-private.** Velocity introspection reaches public methods only, so the 
wrapped objects drop out of the template-visible surface entirely.
   - **Java rendering code that still needs the wrapped objects goes through a 
new `Wrappers` accessor** (`pojos.wrapper.Wrappers.unwrap(...)`), which is 
never placed in a template context. The two callers — `SiteModel`'s entries 
pager and `UtilitiesModel`'s authorization checks — are updated to use it.
   
   ## Testing
   
   - New `WrapperPojoConfinementTest` (3 tests): the wrapper surface hands out 
no wrapped object types, a template cannot resolve `$weblog.pojo` / 
`$entry.pojo` (verified against the real engine configured with 
`SecureUberspector`), and the Java-side access still returns the same objects.
   - `mvn -pl app test` on JDK 11: 328 tests, 0 failures, 1 skipped.
   
   Targets `roller-6.1.x` for 6.1.7.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to