Skip to content

BREAKING CHANGE: remove apiml.service.allowEncodedSlashes in favor of enableStrictUrlValidation#4830

Open
richard-salac wants to merge 5 commits into
v3.x.xfrom
reboot/remove_allowEncodedSlashes_in_favor_of_enableStrictUrlValidation
Open

BREAKING CHANGE: remove apiml.service.allowEncodedSlashes in favor of enableStrictUrlValidation#4830
richard-salac wants to merge 5 commits into
v3.x.xfrom
reboot/remove_allowEncodedSlashes_in_favor_of_enableStrictUrlValidation

Conversation

@richard-salac

Copy link
Copy Markdown
Contributor

Description

The apiml.service.allowEncodedSlashes option only ever controlled the encoded slash (%2F) via a Spring Cloud Gateway filter, and its permissive direction was already superseded by apiml.security.enableStrictUrlValidation, which governs the StrictServerWebExchangeFirewall (encoded slash, double slash, backslash, encoded percent, encoded period, semicolon).

Removes the property and its ForbidEncodedSlashesFilterFactory / ForbidSlashException / exception handler / log message (ZWEAG702), along with the config defaults, packaging start scripts, config schemas, dev scripts and integration-test environment mappings.

Adds acceptance tests for gateway-service and the apiml modulith that validate enableStrictUrlValidation across every controlled character, for both routed traffic (relaxed when disabled) and internal endpoints (always strict).

Follow up on #4812
Linked to # (issue)
Part of the # (epic)

Type of change

Please delete options that are not relevant.

  • fix: Bug fix (non-breaking change which fixes an issue)
  • feat: New feature (non-breaking change which adds functionality)
  • docs: Change in a documentation
  • refactor: Refactor the code
  • chore: Chore, repository cleanup, updates the dependencies.
  • BREAKING CHANGE or !: Breaking change (fix or feature that would cause existing functionality to not work as expected)

Checklist:

  • My code follows the style guidelines of this project
  • PR title conforms to commit message guideline ## Commit Message Structure Guideline
  • I have commented my code, particularly in hard-to-understand areas. In JS I did provide JSDoc
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • The java tests in the area I was working on leverage @nested annotations
  • Any dependent changes have been merged and published in downstream modules

For more details about how should the code look like read the Contributing guideline

…ictUrlValidation

The `apiml.service.allowEncodedSlashes` option only ever controlled the
encoded slash (%2F) via a Spring Cloud Gateway filter, and its permissive
direction was already superseded by `apiml.security.enableStrictUrlValidation`,
which governs the StrictServerWebExchangeFirewall (encoded slash, double
slash, backslash, encoded percent, encoded period, semicolon).

Removes the property and its ForbidEncodedSlashesFilterFactory /
ForbidSlashException / exception handler / log message (ZWEAG702), along with
the config defaults, packaging start scripts, config schemas, dev scripts and
integration-test environment mappings.

Adds acceptance tests for gateway-service and the apiml modulith that validate
enableStrictUrlValidation across every controlled character, for both routed
traffic (relaxed when disabled) and internal endpoints (always strict).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Richard Salac <richard.salac@broadcom.com>
Signed-off-by: Richard Salac <richard.salac@broadcom.com>
@sonarqubecloud

Copy link
Copy Markdown

@richard-salac
richard-salac marked this pull request as ready for review July 22, 2026 05:04
* SPDX-License-Identifier: EPL-2.0
*
* Copyright Contributors to the Zowe Project.
*/

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How are these tests different from those in the apiml module?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

From functional point of view, they are the same. I put them there to validate the new firewall is initialized consistently in micro services and modulith.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants