[ 
https://issues.apache.org/jira/browse/VELOCITY-1001?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Tagir Valeev updated VELOCITY-1001:
-----------------------------------
    Description: 
I've noticed that when we call a static method from the template, a
warning is issued like this:
82 [main] WARN org.apache.velocity.introspection - Cannot retrieve
method max from object of class java.lang.Class due to security
restrictions.

Nevertheless, the method is called correctly, and the template is
merged correctly. Here's a simple reproducer:

{{import org.apache.velocity.Template;}}
{{import org.apache.velocity.VelocityContext;}}
{{import org.apache.velocity.app.VelocityEngine;}}
{{import org.apache.velocity.runtime.RuntimeConstants;}}
{{import org.apache.velocity.runtime.resource.loader.StringResourceLoader;}}
{{import org.apache.velocity.util.introspection.SecureUberspector;}}

{{import java.io.StringWriter;}}

 

{{public class VelocityDemo {}}
{{    static {}}
{{        System.setProperty("org.slf4j.simpleLogger.logFile", "System.err");}}
{{        System.setProperty("org.slf4j.simpleLogger.defaultLogLevel", 
"warn");}}
{{        System.setProperty("org.slf4j.simpleLogger.showDateTime", "true");}}

        }

{{    private static final String TEMPLATE_NAME = "demo.vm";}}

{{    private static final String TEMPLATE = """}}
{{            Hello, $name!}}
{{            Your lucky number is $math.round($math.random() * 100).}}
{{            The bigger of 3 and 7 is $math.max(3, 7).}}
{{            """;}}

{{    public static void main(String[] args) {}}
{{        VelocityEngine engine = new VelocityEngine();}}
{{        engine.setProperty(RuntimeConstants.RESOURCE_LOADERS, "string");}}
{{        engine.setProperty("resource.loader.string.class",}}
{{StringResourceLoader.class.getName());}}
{{        engine.setProperty(RuntimeConstants.UBERSPECT_CLASSNAME,}}
{{SecureUberspector.class.getName());}}
{{        engine.init();}}

{{        
StringResourceLoader.getRepository().putStringResource(TEMPLATE_NAME,}}
{{TEMPLATE);}}
{{        VelocityContext context = new VelocityContext();}}
{{        context.put("name", "World");}}
{{        context.put("math", Math.class);}}

{{        Template template = engine.getTemplate(TEMPLATE_NAME);}}
{{        StringWriter out = new StringWriter();}}
{{        template.merge(context, out);}}
{{        System.out.println(out);}}
    }
{{}}}

+deps: org.apache.velocity:velocity-engine-core:2.4.1, 
org.slf4j:slf4j-simple:1.7.36

The output is the following:

{{55 [main] WARN org.apache.velocity.introspection - Cannot retrieve method 
random from object of class java.lang.Class due to security restrictions.}}
{{75 [main] WARN org.apache.velocity.introspection - Cannot retrieve method 
round from object of class java.lang.Class due to security restrictions.}}
{{82 [main] WARN org.apache.velocity.introspection - Cannot retrieve method max 
from object of class java.lang.Class due to security restrictions.}}
{{Hello, World!}}
{{Your lucky number is 53.}}
{{The bigger of 3 and 7 is 7.}}

The reason is that for static methods, the qualifier is set to the
java.lang.Class pointing to a class containing the method. The
introspector first looks for the method inside the java.lang.Class,
and only after that tries to find a static method in the target class.
The warning adds a lot of noise to our logs. We can filter it out on
our side, but it would be nice to fix it in Velocity.

  was:
I've noticed that when we call a static method from the template, a
warning is issued like this:
82 [main] WARN org.apache.velocity.introspection - Cannot retrieve
method max from object of class java.lang.Class due to security
restrictions.

Nevertheless, the method is called correctly, and the template is
merged correctly. Here's a simple reproducer:

{{import org.apache.velocity.Template;}}
{{import org.apache.velocity.VelocityContext;}}
{{import org.apache.velocity.app.VelocityEngine;}}
{{import org.apache.velocity.runtime.RuntimeConstants;}}
{{import org.apache.velocity.runtime.resource.loader.StringResourceLoader;}}
{{{}import 
org.apache.velocity.util.introspection.SecureUberspector;{}}}{{{}import 
java.io.StringWriter;{}}}{{{}public class VelocityDemo {{}}}
{{    static {}}
{{        System.setProperty("org.slf4j.simpleLogger.logFile", "System.err");}}
{{        System.setProperty("org.slf4j.simpleLogger.defaultLogLevel", 
"warn");}}
{{        System.setProperty("org.slf4j.simpleLogger.showDateTime", "true");}}
{{    }}}

{{    private static final String TEMPLATE_NAME = "demo.vm";}}{{    private 
static final String TEMPLATE = """}}
{{            Hello, $name!}}
{{            Your lucky number is $math.round($math.random() * 100).}}
{{            The bigger of 3 and 7 is $math.max(3, 7).}}
{{            """;}}

{{    public static void main(String[] args) {}}
{{        VelocityEngine engine = new VelocityEngine();}}
{{        engine.setProperty(RuntimeConstants.RESOURCE_LOADERS, "string");}}
{{        engine.setProperty("resource.loader.string.class",}}
{{StringResourceLoader.class.getName());}}
{{        engine.setProperty(RuntimeConstants.UBERSPECT_CLASSNAME,}}
{{SecureUberspector.class.getName());}}
{{        engine.init();}}{{        
StringResourceLoader.getRepository().putStringResource(TEMPLATE_NAME,}}
{{TEMPLATE);}}
{{        VelocityContext context = new VelocityContext();}}
{{        context.put("name", "World");}}
{{        context.put("math", Math.class);}}{{        Template template = 
engine.getTemplate(TEMPLATE_NAME);}}
{{        StringWriter out = new StringWriter();}}
{{        template.merge(context, out);}}
{{        System.out.println(out);}}
    }
{{}}}

+deps: org.apache.velocity:velocity-engine-core:2.4.1, 
org.slf4j:slf4j-simple:1.7.36

The output is the following:

{{55 [main] WARN org.apache.velocity.introspection - Cannot retrieve method 
random from object of class java.lang.Class due to security restrictions.}}
{{75 [main] WARN org.apache.velocity.introspection - Cannot retrieve method 
round from object of class java.lang.Class due to security restrictions.}}
{{82 [main] WARN org.apache.velocity.introspection - Cannot retrieve method max 
from object of class java.lang.Class due to security restrictions.}}
{{Hello, World!}}
{{Your lucky number is 53.}}
{{The bigger of 3 and 7 is 7.}}

The reason is that for static methods, the qualifier is set to the
java.lang.Class pointing to a class containing the method. The
introspector first looks for the method inside the java.lang.Class,
and only after that tries to find a static method in the target class.
The warning adds a lot of noise to our logs. We can filter it out on
our side, but it would be nice to fix it in Velocity.


> An unwanted warning message in logs when calling a static method with 
> SecureUberspector on
> ------------------------------------------------------------------------------------------
>
>                 Key: VELOCITY-1001
>                 URL: https://issues.apache.org/jira/browse/VELOCITY-1001
>             Project: Velocity
>          Issue Type: Bug
>          Components: Engine
>    Affects Versions: 2.4.1
>            Reporter: Tagir Valeev
>            Priority: Minor
>
> I've noticed that when we call a static method from the template, a
> warning is issued like this:
> 82 [main] WARN org.apache.velocity.introspection - Cannot retrieve
> method max from object of class java.lang.Class due to security
> restrictions.
> Nevertheless, the method is called correctly, and the template is
> merged correctly. Here's a simple reproducer:
> {{import org.apache.velocity.Template;}}
> {{import org.apache.velocity.VelocityContext;}}
> {{import org.apache.velocity.app.VelocityEngine;}}
> {{import org.apache.velocity.runtime.RuntimeConstants;}}
> {{import org.apache.velocity.runtime.resource.loader.StringResourceLoader;}}
> {{import org.apache.velocity.util.introspection.SecureUberspector;}}
> {{import java.io.StringWriter;}}
>  
> {{public class VelocityDemo {}}
> {{    static {}}
> {{        System.setProperty("org.slf4j.simpleLogger.logFile", 
> "System.err");}}
> {{        System.setProperty("org.slf4j.simpleLogger.defaultLogLevel", 
> "warn");}}
> {{        System.setProperty("org.slf4j.simpleLogger.showDateTime", "true");}}
>         }
> {{    private static final String TEMPLATE_NAME = "demo.vm";}}
> {{    private static final String TEMPLATE = """}}
> {{            Hello, $name!}}
> {{            Your lucky number is $math.round($math.random() * 100).}}
> {{            The bigger of 3 and 7 is $math.max(3, 7).}}
> {{            """;}}
> {{    public static void main(String[] args) {}}
> {{        VelocityEngine engine = new VelocityEngine();}}
> {{        engine.setProperty(RuntimeConstants.RESOURCE_LOADERS, "string");}}
> {{        engine.setProperty("resource.loader.string.class",}}
> {{StringResourceLoader.class.getName());}}
> {{        engine.setProperty(RuntimeConstants.UBERSPECT_CLASSNAME,}}
> {{SecureUberspector.class.getName());}}
> {{        engine.init();}}
> {{        
> StringResourceLoader.getRepository().putStringResource(TEMPLATE_NAME,}}
> {{TEMPLATE);}}
> {{        VelocityContext context = new VelocityContext();}}
> {{        context.put("name", "World");}}
> {{        context.put("math", Math.class);}}
> {{        Template template = engine.getTemplate(TEMPLATE_NAME);}}
> {{        StringWriter out = new StringWriter();}}
> {{        template.merge(context, out);}}
> {{        System.out.println(out);}}
>     }
> {{}}}
> +deps: org.apache.velocity:velocity-engine-core:2.4.1, 
> org.slf4j:slf4j-simple:1.7.36
> The output is the following:
> {{55 [main] WARN org.apache.velocity.introspection - Cannot retrieve method 
> random from object of class java.lang.Class due to security restrictions.}}
> {{75 [main] WARN org.apache.velocity.introspection - Cannot retrieve method 
> round from object of class java.lang.Class due to security restrictions.}}
> {{82 [main] WARN org.apache.velocity.introspection - Cannot retrieve method 
> max from object of class java.lang.Class due to security restrictions.}}
> {{Hello, World!}}
> {{Your lucky number is 53.}}
> {{The bigger of 3 and 7 is 7.}}
> The reason is that for static methods, the qualifier is set to the
> java.lang.Class pointing to a class containing the method. The
> introspector first looks for the method inside the java.lang.Class,
> and only after that tries to find a static method in the target class.
> The warning adds a lot of noise to our logs. We can filter it out on
> our side, but it would be nice to fix it in Velocity.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to