Tagir Valeev created VELOCITY-1001:
--------------------------------------

             Summary: An unwanted warning message in logs when calling a static 
method with SecureUberspector on
                 Key: VELOCITY-1001
                 URL: https://issues.apache.org/jira/browse/VELOCITY-1001
             Project: Velocity
          Issue Type: Bug
          Components: Engine
    Affects Versions: 2.4.1
            Reporter: Tagir Valeev


I've noticed that when we call a static method from the template, a
warning is issued like this:
82 [main] WARN org.apache.velocity.introspection - Cannot retrieve
method max from object of class java.lang.Class due to security
restrictions.

Nevertheless, the method is called correctly, and the template is
merged correctly. Here's a simple reproducer:

import org.apache.velocity.Template;
import org.apache.velocity.VelocityContext;
import org.apache.velocity.app.VelocityEngine;
import org.apache.velocity.runtime.RuntimeConstants;
import org.apache.velocity.runtime.resource.loader.StringResourceLoader;
import org.apache.velocity.util.introspection.SecureUberspector;

import java.io.StringWriter;

public class VelocityDemo {
    static {
        System.setProperty("org.slf4j.simpleLogger.logFile", "System.err");
        System.setProperty("org.slf4j.simpleLogger.defaultLogLevel", "warn");
        System.setProperty("org.slf4j.simpleLogger.showDateTime", "true");
    }

    private static final String TEMPLATE_NAME = "demo.vm";

    private static final String TEMPLATE = """
            Hello, $name!
            Your lucky number is $math.round($math.random() * 100).
            The bigger of 3 and 7 is $math.max(3, 7).
            """;

    public static void main(String[] args) {
        VelocityEngine engine = new VelocityEngine();
        engine.setProperty(RuntimeConstants.RESOURCE_LOADERS, "string");
        engine.setProperty("resource.loader.string.class",
StringResourceLoader.class.getName());
        engine.setProperty(RuntimeConstants.UBERSPECT_CLASSNAME,
SecureUberspector.class.getName());
        engine.init();

        StringResourceLoader.getRepository().putStringResource(TEMPLATE_NAME,
TEMPLATE);


        VelocityContext context = new VelocityContext();
        context.put("name", "World");
        context.put("math", Math.class);

        Template template = engine.getTemplate(TEMPLATE_NAME);
        StringWriter out = new StringWriter();
        template.merge(context, out);

        System.out.println(out);
    }
}

+deps: org.apache.velocity:velocity-engine-core:2.4.1,
org.slf4j:slf4j-simple:1.7.36

The output is the following:

55 [main] WARN org.apache.velocity.introspection - Cannot retrieve
method random from object of class java.lang.Class due to security
restrictions.
75 [main] WARN org.apache.velocity.introspection - Cannot retrieve
method round from object of class java.lang.Class due to security
restrictions.
82 [main] WARN org.apache.velocity.introspection - Cannot retrieve
method max from object of class java.lang.Class due to security
restrictions.
Hello, World!
Your lucky number is 53.
The bigger of 3 and 7 is 7.

The reason is that for static methods, the qualifier is set to the
java.lang.Class pointing to a class containing the method. The
introspector first looks for the method inside the java.lang.Class,
and only after that tries to find a static method in the target class.
The warning adds a lot of noise to our logs. We can filter it out on
our side, but it would be nice to fix it in Velocity.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to