Conversation
The pojo wrappers handed the wrapped objects out through their public getPojo() methods, which are part of the surface weblog templates can reach. The rendering code that does need the wrapped objects (the pagers and the authorization checks) now goes through a dedicated Java-only accessor, Wrappers, and the wrappers' own accessors are package-private, so the SecureUberspector that renders weblog templates no longer reaches them. Add WrapperPojoConfinementTest to pin both sides: templates cannot resolve the wrapped objects, and the Java access still returns them.
snoopdave
commented
Oct 3, 2026
snoopdave
left a comment
Contributor
Author
There was a problem hiding this comment.
PR-Review: 1 inline comment posted.
Contributor
Author
|
🐞Claude Issue: PR-Review: General Issues The following issues were found but cannot be attached to a specific line in the diff:
|
Contributor
Author
|
🤖Claude:
|
Initialise the test engine from WEB-INF/velocity.properties, dropping only the settings that need a running webapp, so the introspection settings under test are the real ones. Add a 6.1.7 CHANGES.md entry for theme authors.
Contributor
Author
|
With those fixes, this PR is ready for merge, IMO. |
Contributor
Author
|
Manually tested on the 6.1.7 integration build (Tomcat 9, JDK 11, MySQL 8) with a custom-theme template. Pass.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Weblog templates are rendered under the Velocity
SecureUberspector, which governs method access — but until now the pojo wrappers still exposed the wrapped objects themselves through their publicgetPojo()methods, which is broader surface than a template should see.WeblogWrapper.getPojo()andWeblogEntryWrapper.getPojo()are now package-private. Velocity introspection reaches public methods only, so the wrapped objects drop out of the template-visible surface entirely.Wrappersaccessor (pojos.wrapper.Wrappers.unwrap(...)), which is never placed in a template context. The two callers —SiteModel's entries pager andUtilitiesModel's authorization checks — are updated to use it.Testing
WrapperPojoConfinementTest(3 tests): the wrapper surface hands out no wrapped object types, a template cannot resolve$weblog.pojo/$entry.pojo(verified against the real engine configured withSecureUberspector), and the Java-side access still returns the same objects.mvn -pl app teston JDK 11: 328 tests, 0 failures, 1 skipped.Targets
roller-6.1.xfor 6.1.7. It will be cherry-picked tomasterafter the 6.1.7 release.