ruthst00 opened a new pull request, #16492:
URL: https://github.com/apache/grails-core/pull/16492

   ## Description
   <!-- Describe your change and the problem it solves. Link to the related 
issue(s) if they exist. -->
   
   **Root Cause**: `TEMPLATE_MODEL` is a plain request attribute that persists 
across action boundaries on the same request. When a controller action called 
`render(template:..., model:...)` and then forwarded to another action (or when 
a template included another action via `g:include`), the interceptor on the 
second/included action could read the first action's `TEMPLATE_MODEL` — a leak.
   
   **Changes Made:**
   
   1. **`RequestForwarder.groovy`** — Added `TEMPLATE_MODEL` removal both 
before the forward dispatch and in the `finally` block after it, mirroring the 
existing `MODEL_AND_VIEW` cleanup.
   
   2. **`UrlMappingUtils.java`** — In `includeForUrlMappingInfoHelper`, added 
save/remove/restore of `TEMPLATE_MODEL` around the include dispatch, mirroring 
the existing `MODEL_AND_VIEW` save/restore pattern.
   
   3. **`RequestForwarderSpec.groovy`** — Added a new unit test verifying that 
`TEMPLATE_MODEL` is cleared before the forward (not visible to the forwarded 
action) and removed after the forward completes.
   
   4. **`UrlMappingUtilsSpec.groovy`** — Added two new unit tests: one 
verifying `TEMPLATE_MODEL` is null during the include and restored to the outer 
value after; another verifying that a `TEMPLATE_MODEL` set by the included 
action is removed after the include returns.
   
   5. **`RenderTemplateController.groovy`** (both `views-functional-tests` and 
`hibernate7/views-functional-tests`) — Added `forwardAfterTemplate`, 
`forwardTarget`, `includeAfterTemplate`, and `includeTarget` actions to 
exercise the leak scenarios end-to-end.
   
   6. **`ModelInterceptor.groovy`** (both test apps) — Added `modelByAction` 
map to track the model seen per action name, enabling the include test to 
assert on the included action's model independently.
   
   7. **`ModelInterceptorIntSpec.groovy`** (both test apps) — Added two new 
integration test cases: one asserting `latestModel == null` after a forward 
(the forwarded action sees no leaked model), and one asserting 
`modelByAction['includeTarget'] == null` (the included action sees no leaked 
model).
   
   Fixes issue in [#16453](https://github.com/apache/grails-core/pull/16453) 
found after merge to 8.0.x
   
   Generated with [Claude Sonnet 4.6](https://www.anthropic.com/claude/sonnet) 
via [Cline API Provider](https://cline.bot/)
   
   ## Contributor Checklist
   
   Please review the following checklist before submitting your pull request. 
Pull requests that do not meet these requirements may be closed without review.
   
   ### Issue and Scope
   
   - [X] This PR is linked to an existing issue that has been **acknowledged or 
approved** by the project team. If no approved issue exists, please give 
background on why this change is necessary.  Tickets are preferred for release 
change log history.
   - [X] This PR addresses the **complete scope** of the linked issue. Partial 
implementations or unfinished work should not be submitted for review.
   - [X] This PR contains a **single, focused change**. Unrelated changes 
should be submitted as separate pull requests.
   - [X] This PR targets the **correct branch** for the type of change:
       - **Patch release branches** (e.g., `7.0.x`): Bug fixes only. No new 
features or API changes.
       - **Minor release branches** (e.g., `7.1.x`): New features are welcome, 
but breaking existing APIs must be avoided.
       - **Major release branches** (e.g., `8.0.x`): Reserved for major 
changes. Breaking API changes are permitted.
   
   ### Code Quality
   
   - [X] I have **added or updated tests** that cover the changes introduced in 
this PR. All code contributions are expected to include appropriate test 
coverage.
   - [X] I have verified that all existing tests pass by running `./gradlew 
build --rerun-tasks`.
   - [ ] My code follows the project's **code style** guidelines. I have run 
`./gradlew codeStyle` and resolved any violations. See [Code 
Style](../CONTRIBUTING.md#code-style) for details.
   - [X] This PR does **not** include mass reformatting, style-only changes, or 
large-scale refactoring unless it was **explicitly approved** in the linked 
issue. Unsolicited reformatting will not be accepted.
   - [X] If generative AI tooling was used in preparing this contribution, a 
quality model was used to ensure contributions are **consistent with the 
project's quality standards**.
   
   ### Licensing and Attribution
   
   - [X] All contributed code is provided under the [Apache License 
2.0](https://www.apache.org/licenses/LICENSE-2.0), and new source files include 
the appropriate **Apache license header**.
   - [X] I have the necessary rights to submit this contribution and confirm it 
is my own original work (see [Legal 
Notice](../CONTRIBUTING.md#i-want-to-contribute)).
   - [X] If generative AI tooling was used in preparing this contribution, I 
have followed the [Apache Software Foundation's policy on generative 
tooling](https://www.apache.org/legal/generative-tooling.html) and have 
properly attributed its use.
   
   ### Documentation
   
   - [ ] If this PR introduces user-facing changes, I have included or updated 
the relevant documentation.
   - [ ] If this PR adds a new feature, I have updated the **What's New** 
section of the Grails Guide.
   - [ ] If this PR introduces breaking changes or changes that require user 
action during an upgrade, I have updated the **Upgrade Notes** for the 
corresponding version in the Grails Guide.
   - [X] The PR description clearly explains **what** was changed and **why**.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to