matrei opened a new pull request, #16460:
URL: https://github.com/apache/grails-core/pull/16460
## Description
Fixes #16459.
When `grails.views.gsp.htmlcodec` is not set, `HTMLCodec` used the HTML4
encoder from before Grails 2.3. Every application template since 2.3 has set
`htmlcodec: xml`, so only applications without the setting got it. This PR
makes the XML-safe `HTMLEncoder` the default and keeps the HTML4 encoder as an
explicit opt-in.
### Changes
- `HTMLCodec` uses `HTMLEncoder` by default. `htmlcodec: html4` selects the
HTML4 encoder. `html` also selects it, because an application that set `html`
explicitly got the HTML4 encoder before. `xml`, `xhtml` and any other value
select the default. Matching ignores case, as before.
- Grails Forge (`GrailsGsp`) and the web profile skeleton no longer write
`htmlcodec: xml`.
- The description of `grails.views.gsp.htmlcodec` in the `grails-gsp`
configuration metadata now describes the new default and `html4`.
- Guide:
- The HTMLCodec section in "Encoding and Decoding Objects" lists what the
codec escapes and shows `html4` as the opt-out. The out-of-date note saying
apostrophes are not escaped is removed, since both encoders escape `'` as
`'`.
- The recommended configuration in "Cross Site Scripting (XSS) Prevention"
no longer includes `htmlcodec: xml`.
- New section 81 in the Grails 8 upgrade guide, plus a matching note in
the `grails-8-upgrade` skill.
The `htmlcodec: xml` lines in `grails-test-examples` and in the plugin
`application.yml` files are left as they are. They select the same encoder as
before.
### Compatibility
Applications that set `htmlcodec: xml` are not affected. Applications
without the setting now get the XML-safe output: non-ASCII letters are no
longer written as named entities, and `@`, `\` and `` ` `` are escaped. Tests
that compare escaped markup exactly may need updating, as the two
`grails-fields` specs in this PR did (`pattern="\d+"` is now rendered as
`pattern="\d+"`, which the browser decodes to the same value). Applications
that serve pages in a non-UTF-8 charset and rely on the entities can set
`htmlcodec: html4`.
### Tests
- `HTMLCodecTests`: the default with and without a `GrailsApplication`; the
settings that select each encoder (`xml`, `XML`, `xhtml`, `XHTML`, `xml-safe`,
empty and unknown values; `html4`, `HTML4`, `html`, `HTML`);
`setUseLegacyEncoder`; and that both encoders report the `HTML` codec
identifier. Each case checks `@`, `\`, `` ` ``, U+2028 and a non-ASCII letter.
- `CodecsConfigurationSpec`: a data-driven feature that resolves the `HTML`
encoder through `CodecLookup` in a Spring context for an unset value, `xml`,
`xhtml` and `html4`. The unset row fails without the change.
- `GrailsGspSpec` (Forge): the generated configuration no longer contains
`grails.views.gsp.htmlcodec`.
- `DefaultInputRenderingSpec` and `DefaultInputRenderingPersistentSpec`
(`grails-fields`): the expected `pattern` attribute is now the escaped value.
The test suites of the modules that render through the HTML codec pass,
including `grails-codecs`, `grails-gsp`, the taglib, layout and SiteMesh 3
modules, `grails-test-suite-uber`/`-web`/`-persistence`, `grails-fields`,
`grails-scaffolding`, the Spring Security plugins, `grails-mail` and
`grails-data-graphql`. `GrailsGspSpec` in `grails-forge` also passes.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]