matrei opened a new pull request, #16460:
URL: https://github.com/apache/grails-core/pull/16460

   ## Description
   
   Fixes #16459.
   
   When `grails.views.gsp.htmlcodec` is not set, `HTMLCodec` used the HTML4 
encoder from before Grails 2.3. Every application template since 2.3 has set 
`htmlcodec: xml`, so only applications without the setting got it. This PR 
makes the XML-safe `HTMLEncoder` the default and keeps the HTML4 encoder as an 
explicit opt-in.
   
   ### Changes
   
   - `HTMLCodec` uses `HTMLEncoder` by default. `htmlcodec: html4` selects the 
HTML4 encoder. `html` also selects it, because an application that set `html` 
explicitly got the HTML4 encoder before. `xml`, `xhtml` and any other value 
select the default. Matching ignores case, as before.
   - Grails Forge (`GrailsGsp`) and the web profile skeleton no longer write 
`htmlcodec: xml`.
   - The description of `grails.views.gsp.htmlcodec` in the `grails-gsp` 
configuration metadata now describes the new default and `html4`.
   - Guide:
     - The HTMLCodec section in "Encoding and Decoding Objects" lists what the 
codec escapes and shows `html4` as the opt-out. The out-of-date note saying 
apostrophes are not escaped is removed, since both encoders escape `'` as 
`'`.
     - The recommended configuration in "Cross Site Scripting (XSS) Prevention" 
no longer includes `htmlcodec: xml`.
     - New section 81 in the Grails 8 upgrade guide, plus a matching note in 
the `grails-8-upgrade` skill.
   
   The `htmlcodec: xml` lines in `grails-test-examples` and in the plugin 
`application.yml` files are left as they are. They select the same encoder as 
before.
   
   ### Compatibility
   
   Applications that set `htmlcodec: xml` are not affected. Applications 
without the setting now get the XML-safe output: non-ASCII letters are no 
longer written as named entities, and `@`, `\` and `` ` `` are escaped. Tests 
that compare escaped markup exactly may need updating, as the two 
`grails-fields` specs in this PR did (`pattern="\d+"` is now rendered as 
`pattern="\d+"`, which the browser decodes to the same value). Applications 
that serve pages in a non-UTF-8 charset and rely on the entities can set 
`htmlcodec: html4`.
   
   ### Tests
   
   - `HTMLCodecTests`: the default with and without a `GrailsApplication`; the 
settings that select each encoder (`xml`, `XML`, `xhtml`, `XHTML`, `xml-safe`, 
empty and unknown values; `html4`, `HTML4`, `html`, `HTML`); 
`setUseLegacyEncoder`; and that both encoders report the `HTML` codec 
identifier. Each case checks `@`, `\`, `` ` ``, U+2028 and a non-ASCII letter.
   - `CodecsConfigurationSpec`: a data-driven feature that resolves the `HTML` 
encoder through `CodecLookup` in a Spring context for an unset value, `xml`, 
`xhtml` and `html4`. The unset row fails without the change.
   - `GrailsGspSpec` (Forge): the generated configuration no longer contains 
`grails.views.gsp.htmlcodec`.
   - `DefaultInputRenderingSpec` and `DefaultInputRenderingPersistentSpec` 
(`grails-fields`): the expected `pattern` attribute is now the escaped value.
   
   The test suites of the modules that render through the HTML codec pass, 
including `grails-codecs`, `grails-gsp`, the taglib, layout and SiteMesh 3 
modules, `grails-test-suite-uber`/`-web`/`-persistence`, `grails-fields`, 
`grails-scaffolding`, the Spring Security plugins, `grails-mail` and 
`grails-data-graphql`. `GrailsGspSpec` in `grails-forge` also passes.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to