Conversation
Planet is now off unless planet.aggregator.enabled=true is set. While it is off, the Planet admin actions are refused and /planetrss returns 404, rather than only the menu being hidden. Sites that use Planet need to set the property in roller-custom.properties when they upgrade. Add a @RequiresPost annotation and RequiresPostInterceptor to the Roller stack: a marked action method refuses any request that is not a POST. Unmarked methods are unchanged. The Planet save and delete methods are marked; their forms already submit by POST. UISecurityEnforced gains a default isFeatureEnabled(), checked first by UISecurityInterceptor, so an optional feature can switch off all of its actions in one place.
snoopdave
commented
Oct 3, 2026
snoopdave
left a comment
Contributor
Author
There was a problem hiding this comment.
PR-Review: 1 inline comment posted.
Contributor
Author
|
🐞Claude Issue: PR-Review: General Issues The following issues were found but cannot be attached to a specific line in the diff:
|
Contributor
Author
|
🤖Claude:
|
…s off RequiresPostInterceptor now walks the superclass chain, so an override that does not repeat the annotation still requires POST. RefreshRollerPlanetTask and SyncWebsitesTask return early while planet.aggregator.enabled is false. Add a 6.1.7 CHANGES.md section for the Planet changes.
snoopdave
commented
Oct 4, 2026
Replace the @RequiresPost annotation and RequiresPostInterceptor with an isPostRequest() check in PlanetUIAction, called at the start of the five methods that change Planet state, as FrontpageSetup already does. The methods return DENIED for any other request method.
Contributor
Author
|
ready for merge. |
The Planet tasks now do nothing while planet.aggregator.enabled is false, which is the new default, so the test turns it on while it runs them.
Contributor
Author
|
Manually tested on the 6.1.7 integration build (Tomcat 9, JDK 11, MySQL 8). Pass.
One older bug, not caused by this PR: on a new site, the feed's title and description printed the literal |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
planet.aggregator.enabled=false). Few sites use the aggregator. Until now, turning it off only hid the admin menu: the Planet admin actions and the/planetrssfeed still answered. Now, while it is off, the Planet admin actions are refused and/planetrssreturns 404.PlanetUIAction.isPostRequest()is checked at the start of the five methods that save or delete Planet configuration, groups and subscriptions; any other request method getsDENIED. The forms already submit by POST, so the UI is unchanged. This follows the inline checkFrontpageSetupalready uses.UISecurityEnforced.isFeatureEnabled(), a default method checked first byUISecurityInterceptor, lets an optional feature switch off all of its actions in one place.PlanetUIActionties it toplanet.aggregator.enabled.Upgrade note
Sites that use Planet must set
planet.aggregator.enabled=trueinroller-custom.propertieswhen they upgrade, or the Planet pages and feed will be unavailable.Testing
PlanetAvailabilityTest: a GET to each of the five Planet change methods is refused without touching the Weblogger; only a POST counts as a POST request; the Planet setting's default and its effect on actions,/planetrssand the Planet tasks.PlanetAvailabilityTest7/7,ValidateSaltInterceptorTest7/7,UIActionTest3/3. CI runs the full suite on JDK 11, 17, 21 and 25.Targets
roller-6.1.xfor 6.1.7. It will be cherry-picked tomasterafter the 6.1.7 release.