From b03f8905679838c108a3de9a1ca0f649d8877b98 Mon Sep 17 00:00:00 2001 From: Phillip Webb Date: Wed, 30 May 2018 11:14:26 -0700 Subject: [PATCH 1/2] Upgrade to spring-javaformat 0.0.2 --- spring-boot-dependencies/pom.xml | 5 ++--- spring-boot-parent/pom.xml | 7 +------ spring-boot-samples/pom.xml | 2 +- spring-boot-samples/spring-boot-sample-ant/pom.xml | 9 ++++----- spring-boot-starters/spring-boot-starter-parent/pom.xml | 7 +++---- 5 files changed, 11 insertions(+), 19 deletions(-) diff --git a/spring-boot-dependencies/pom.xml b/spring-boot-dependencies/pom.xml index 47a0a94362..e6ac988c64 100644 --- a/spring-boot-dependencies/pom.xml +++ b/spring-boot-dependencies/pom.xml @@ -1,5 +1,4 @@ - - + 4.0.0 org.springframework.boot spring-boot-dependencies @@ -3258,4 +3257,4 @@ integration-test - + \ No newline at end of file diff --git a/spring-boot-parent/pom.xml b/spring-boot-parent/pom.xml index 4df432ffb7..d1402a2947 100644 --- a/spring-boot-parent/pom.xml +++ b/spring-boot-parent/pom.xml @@ -26,7 +26,7 @@ UTF-8 UTF-8 3.1.1 - 0.0.1 + 0.0.2 http://github.com/spring-projects/spring-boot @@ -506,11 +506,6 @@ io.spring.javaformat spring-javaformat-maven-plugin ${spring-javaformat.version} - - - **/HelpMojo.java - - validate diff --git a/spring-boot-samples/pom.xml b/spring-boot-samples/pom.xml index 14263d5858..524abeedd2 100644 --- a/spring-boot-samples/pom.xml +++ b/spring-boot-samples/pom.xml @@ -21,7 +21,7 @@ ${basedir}/.. 1.8 - 0.0.1 + 0.0.2 spring-boot-sample-ant diff --git a/spring-boot-samples/spring-boot-sample-ant/pom.xml b/spring-boot-samples/spring-boot-sample-ant/pom.xml index 8452b89d13..6274590f93 100644 --- a/spring-boot-samples/spring-boot-sample-ant/pom.xml +++ b/spring-boot-samples/spring-boot-sample-ant/pom.xml @@ -1,5 +1,4 @@ - - + 4.0.0 @@ -62,8 +61,8 @@ package - - + + @@ -103,4 +102,4 @@ - + \ No newline at end of file diff --git a/spring-boot-starters/spring-boot-starter-parent/pom.xml b/spring-boot-starters/spring-boot-starter-parent/pom.xml index 1516f021c0..813e6e6dff 100644 --- a/spring-boot-starters/spring-boot-starter-parent/pom.xml +++ b/spring-boot-starters/spring-boot-starter-parent/pom.xml @@ -1,5 +1,4 @@ - - + 4.0.0 org.springframework.boot @@ -206,7 +205,7 @@ META-INF/spring.schemas - + ${start-class} @@ -218,4 +217,4 @@ - + \ No newline at end of file From 4d84933ee46ae6095bd916819c7b38f3706f006e Mon Sep 17 00:00:00 2001 From: Phillip Webb Date: Wed, 30 May 2018 12:02:46 -0700 Subject: [PATCH 2/2] Also call setHttpOnly property on Tomcat context Update `ServerProperties` to also call `setHttpOnly` on the `TomcatContext`. It appears that this is required in addition to using the `ServletContextInitializer` to setup `SessionCookieConfig`. Closes gh-12580 --- .../boot/autoconfigure/web/ServerProperties.java | 11 +++++++++++ .../autoconfigure/web/ServerPropertiesTests.java | 14 ++++++++++++++ 2 files changed, 25 insertions(+) diff --git a/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/web/ServerProperties.java b/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/web/ServerProperties.java index 1ad128448c..fe8dac9a37 100644 --- a/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/web/ServerProperties.java +++ b/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/web/ServerProperties.java @@ -864,6 +864,17 @@ public class ServerProperties .getIncludeStacktrace() == ErrorProperties.IncludeStacktrace.NEVER) { customizeErrorReportValve(factory); } + Cookie cookie = serverProperties.getSession().getCookie(); + if (cookie.getHttpOnly() != null) { + factory.addContextCustomizers(new TomcatContextCustomizer() { + + @Override + public void customize(Context context) { + context.setUseHttpOnly(cookie.getHttpOnly()); + } + + }); + } } private void customizeErrorReportValve( diff --git a/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/web/ServerPropertiesTests.java b/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/web/ServerPropertiesTests.java index c15666133b..571af472e7 100644 --- a/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/web/ServerPropertiesTests.java +++ b/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/web/ServerPropertiesTests.java @@ -32,6 +32,8 @@ import javax.servlet.SessionTrackingMode; import org.apache.catalina.Context; import org.apache.catalina.Valve; +import org.apache.catalina.core.StandardContext; +import org.apache.catalina.startup.Tomcat; import org.apache.catalina.valves.AccessLogValve; import org.apache.catalina.valves.ErrorReportValve; import org.apache.catalina.valves.RemoteIpValve; @@ -734,6 +736,18 @@ public class ServerPropertiesTests { "spring-boot-*.jar"); } + @Test + public void customTomcatHttpOnlyCookie() throws Exception { + this.properties.getSession().getCookie().setHttpOnly(false); + TomcatEmbeddedServletContainerFactory factory = new TomcatEmbeddedServletContainerFactory(); + this.properties.customize(factory); + EmbeddedServletContainer container = factory.getEmbeddedServletContainer(); + Tomcat tomcat = ((TomcatEmbeddedServletContainer) container).getTomcat(); + StandardContext context = (StandardContext) tomcat.getHost().findChildren()[0]; + assertThat(context.getUseHttpOnly()).isFalse(); + container.stop(); + } + @Test public void defaultUseForwardHeadersUndertow() throws Exception { UndertowEmbeddedServletContainerFactory container = spy(