snoopdave opened a new pull request, #200: URL: https://github.com/apache/roller/pull/200
## Summary - **Planet is now off by default** (`planet.aggregator.enabled=false`). Few sites use the aggregator. Until now, turning it off only hid the admin menu: the Planet admin actions and the `/planetrss` feed still answered. Now, while it is off, the Planet admin actions are refused and `/planetrss` returns 404. - **New `@RequiresPost` annotation and `RequiresPostInterceptor`** in the Roller interceptor stack. An action method marked `@RequiresPost` refuses any request that is not a POST. Unmarked methods are unaffected. The Planet save and delete methods are marked; their forms already submit by POST, so the UI is unchanged. - **`UISecurityEnforced.isFeatureEnabled()`**, a default method checked first by `UISecurityInterceptor`, lets an optional feature switch off all of its actions in one place. `PlanetUIAction` ties it to `planet.aggregator.enabled`. Struts 2.5 has no built-in `@HttpPost`; the annotation and interceptor are small, and the Jakarta/Struts 7 line can switch to the framework's own once it lands. ## Upgrade note Sites that use Planet must set `planet.aggregator.enabled=true` in `roller-custom.properties` when they upgrade, or the Planet pages and feed will be unavailable. ## Testing - New `RequiresPostInterceptorTest` (5) and `PlanetAvailabilityTest` (6): POST-only marked methods, unmarked methods unaffected, the Planet setting's default and effect on actions and `/planetrss`, and the stack configuration. - `mvn -pl app test` on JDK 11: 336 tests, 0 failures, 1 skipped. Targets `roller-6.1.x` for 6.1.7. A matching change for `master` will follow. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
