From e7431a3a72e37d18bdaf5909ddf3a459bf2fa7fd Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Tue, 18 Feb 2025 16:52:09 +0000 Subject: [PATCH 1/3] Release 6.4.3 --- gradle.properties | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gradle.properties b/gradle.properties index 7ea67c6b3a..75d8d36713 100644 --- a/gradle.properties +++ b/gradle.properties @@ -14,7 +14,7 @@ # limitations under the License. # springBootVersion=3.3.3 -version=6.4.3-SNAPSHOT +version=6.4.3 samplesBranch=main org.gradle.jvmargs=-Xmx3g -XX:+HeapDumpOnOutOfMemoryError org.gradle.parallel=true From 3456a8eb17b809395b520b5ab4f9e588bc9d8e38 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Tue, 18 Feb 2025 17:24:48 +0000 Subject: [PATCH 2/3] Next development version --- gradle.properties | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gradle.properties b/gradle.properties index 75d8d36713..b672bbceda 100644 --- a/gradle.properties +++ b/gradle.properties @@ -14,7 +14,7 @@ # limitations under the License. # springBootVersion=3.3.3 -version=6.4.3 +version=6.4.4-SNAPSHOT samplesBranch=main org.gradle.jvmargs=-Xmx3g -XX:+HeapDumpOnOutOfMemoryError org.gradle.parallel=true From cc2cfc62b07c4745ea2c0e835c79546c73b917c6 Mon Sep 17 00:00:00 2001 From: Josh Cummings <3627351+jzheaux@users.noreply.github.com> Date: Tue, 18 Feb 2025 15:05:22 -0700 Subject: [PATCH 3/3] Add Test Requiring serialVersionUID Issue gh-16276 --- ...gSecurityCoreVersionSerializableTests.java | 21 ++++++++----------- 1 file changed, 9 insertions(+), 12 deletions(-) diff --git a/config/src/test/java/org/springframework/security/SpringSecurityCoreVersionSerializableTests.java b/config/src/test/java/org/springframework/security/SpringSecurityCoreVersionSerializableTests.java index 2982d2a005..c4b96ab290 100644 --- a/config/src/test/java/org/springframework/security/SpringSecurityCoreVersionSerializableTests.java +++ b/config/src/test/java/org/springframework/security/SpringSecurityCoreVersionSerializableTests.java @@ -32,6 +32,7 @@ import java.nio.file.Path; import java.nio.file.Paths; import java.time.Instant; import java.util.ArrayList; +import java.util.Arrays; import java.util.Collection; import java.util.Date; import java.util.HashMap; @@ -39,7 +40,6 @@ import java.util.List; import java.util.Locale; import java.util.Map; import java.util.Set; -import java.util.stream.Collectors; import java.util.stream.Stream; import jakarta.servlet.http.Cookie; @@ -717,7 +717,7 @@ class SpringSecurityCoreVersionSerializableTests { } @Test - void listClassesMissingSerialVersion() throws Exception { + void allSerializableClassesShouldHaveSerialVersionOrSuppressWarnings() throws Exception { ClassPathScanningCandidateComponentProvider provider = new ClassPathScanningCandidateComponentProvider(false); provider.addIncludeFilter(new AssignableTypeFilter(Serializable.class)); List> classes = new ArrayList<>(); @@ -725,10 +725,6 @@ class SpringSecurityCoreVersionSerializableTests { Set components = provider.findCandidateComponents("org/springframework/security"); for (BeanDefinition component : components) { Class clazz = Class.forName(component.getBeanClassName()); - boolean isAbstract = Modifier.isAbstract(clazz.getModifiers()); - if (isAbstract) { - continue; - } if (clazz.isEnum()) { continue; } @@ -738,15 +734,16 @@ class SpringSecurityCoreVersionSerializableTests { boolean hasSerialVersion = Stream.of(clazz.getDeclaredFields()) .map(Field::getName) .anyMatch((n) -> n.equals("serialVersionUID")); - if (!hasSerialVersion) { + SuppressWarnings suppressWarnings = clazz.getAnnotation(SuppressWarnings.class); + boolean hasSerialIgnore = suppressWarnings == null + || Arrays.asList(suppressWarnings.value()).contains("Serial"); + if (!hasSerialVersion && !hasSerialIgnore) { classes.add(clazz); } } - if (!classes.isEmpty()) { - System.out - .println("Found " + classes.size() + " Serializable classes that don't declare a seriallVersionUID"); - System.out.println(classes.stream().map(Class::getName).collect(Collectors.joining("\r\n"))); - } + assertThat(classes) + .describedAs("Found Serializable classes that are either missing a serialVersionUID or a @SuppressWarnings") + .isEmpty(); } static Stream> getClassesToSerialize() throws Exception {