Merge branch '6.4.x'

This commit is contained in:
Josh Cummings 2025-02-18 15:11:08 -07:00
commit 51ce91f07b
No known key found for this signature in database
GPG Key ID: 869B37A20E876129

View File

@ -34,6 +34,7 @@ import java.nio.file.Path;
import java.nio.file.Paths; import java.nio.file.Paths;
import java.time.Instant; import java.time.Instant;
import java.util.ArrayList; import java.util.ArrayList;
import java.util.Arrays;
import java.util.Collection; import java.util.Collection;
import java.util.Date; import java.util.Date;
import java.util.HashMap; import java.util.HashMap;
@ -42,7 +43,6 @@ import java.util.List;
import java.util.Locale; import java.util.Locale;
import java.util.Map; import java.util.Map;
import java.util.Set; import java.util.Set;
import java.util.stream.Collectors;
import java.util.stream.Stream; import java.util.stream.Stream;
import jakarta.servlet.http.Cookie; import jakarta.servlet.http.Cookie;
@ -762,7 +762,7 @@ class SpringSecurityCoreVersionSerializableTests {
} }
@Test @Test
void listClassesMissingSerialVersion() throws Exception { void allSerializableClassesShouldHaveSerialVersionOrSuppressWarnings() throws Exception {
ClassPathScanningCandidateComponentProvider provider = new ClassPathScanningCandidateComponentProvider(false); ClassPathScanningCandidateComponentProvider provider = new ClassPathScanningCandidateComponentProvider(false);
provider.addIncludeFilter(new AssignableTypeFilter(Serializable.class)); provider.addIncludeFilter(new AssignableTypeFilter(Serializable.class));
List<Class<?>> classes = new ArrayList<>(); List<Class<?>> classes = new ArrayList<>();
@ -770,10 +770,6 @@ class SpringSecurityCoreVersionSerializableTests {
Set<BeanDefinition> components = provider.findCandidateComponents("org/springframework/security"); Set<BeanDefinition> components = provider.findCandidateComponents("org/springframework/security");
for (BeanDefinition component : components) { for (BeanDefinition component : components) {
Class<?> clazz = Class.forName(component.getBeanClassName()); Class<?> clazz = Class.forName(component.getBeanClassName());
boolean isAbstract = Modifier.isAbstract(clazz.getModifiers());
if (isAbstract) {
continue;
}
if (clazz.isEnum()) { if (clazz.isEnum()) {
continue; continue;
} }
@ -783,15 +779,16 @@ class SpringSecurityCoreVersionSerializableTests {
boolean hasSerialVersion = Stream.of(clazz.getDeclaredFields()) boolean hasSerialVersion = Stream.of(clazz.getDeclaredFields())
.map(Field::getName) .map(Field::getName)
.anyMatch((n) -> n.equals("serialVersionUID")); .anyMatch((n) -> n.equals("serialVersionUID"));
if (!hasSerialVersion) { SuppressWarnings suppressWarnings = clazz.getAnnotation(SuppressWarnings.class);
boolean hasSerialIgnore = suppressWarnings == null
|| Arrays.asList(suppressWarnings.value()).contains("Serial");
if (!hasSerialVersion && !hasSerialIgnore) {
classes.add(clazz); classes.add(clazz);
} }
} }
if (!classes.isEmpty()) { assertThat(classes)
System.out .describedAs("Found Serializable classes that are either missing a serialVersionUID or a @SuppressWarnings")
.println("Found " + classes.size() + " Serializable classes that don't declare a seriallVersionUID"); .isEmpty();
System.out.println(classes.stream().map(Class::getName).collect(Collectors.joining("\r\n")));
}
} }
static Stream<Class<?>> getClassesToSerialize() throws Exception { static Stream<Class<?>> getClassesToSerialize() throws Exception {