Skip to content

Keep wrapped pojos out of the template surface - #199

Open
snoopdave wants to merge 3 commits into
roller-6.1.xfrom
wrapper-pojo-template-access
Open

snoopdave wants to merge 3 commits into
roller-6.1.xfrom
wrapper-pojo-template-access

Conversation

@snoopdave

@snoopdave snoopdave commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Weblog templates are rendered under the Velocity SecureUberspector, which governs method access — but until now the pojo wrappers still exposed the wrapped objects themselves through their public getPojo() methods, which is broader surface than a template should see.

  • WeblogWrapper.getPojo() and WeblogEntryWrapper.getPojo() are now package-private. Velocity introspection reaches public methods only, so the wrapped objects drop out of the template-visible surface entirely.
  • Java rendering code that still needs the wrapped objects goes through a new Wrappers accessor (pojos.wrapper.Wrappers.unwrap(...)), which is never placed in a template context. The two callers — SiteModel's entries pager and UtilitiesModel's authorization checks — are updated to use it.

Testing

  • New WrapperPojoConfinementTest (3 tests): the wrapper surface hands out no wrapped object types, a template cannot resolve $weblog.pojo / $entry.pojo (verified against the real engine configured with SecureUberspector), and the Java-side access still returns the same objects.
  • mvn -pl app test on JDK 11: 328 tests, 0 failures, 1 skipped.

Targets roller-6.1.x for 6.1.7. It will be cherry-picked to master after the 6.1.7 release.

The pojo wrappers handed the wrapped objects out through their public
getPojo() methods, which are part of the surface weblog templates can
reach. The rendering code that does need the wrapped objects (the
pagers and the authorization checks) now goes through a dedicated
Java-only accessor, Wrappers, and the wrappers' own accessors are
package-private, so the SecureUberspector that renders weblog
templates no longer reaches them.

Add WrapperPojoConfinementTest to pin both sides: templates cannot
resolve the wrapped objects, and the Java access still returns them.
@snoopdave snoopdave added the 6.1.7 label Oct 3, 2026

@snoopdave snoopdave left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR-Review: 1 inline comment posted.

@snoopdave

Copy link
Copy Markdown
Contributor Author

🐞Claude Issue: PR-Review: General Issues

The following issues were found but cannot be attached to a specific line in the diff:

  • Blocking: CHANGES.md on roller-6.1.x is not updated. Add a 6.1.7 entry. It must tell theme authors that $weblog.pojo and $entry.pojo (and getPojo()) no longer resolve in templates. Custom themes that use them will print the literal reference text instead of failing loudly, so this needs to be in the release notes.
  • Important: No CI runs on this PR, because the roller-6.1.x workflows trigger only for master. I ran WrapperPojoConfinementTest locally on JDK 11: 3 tests, 0 failures. I also confirmed that no bundled .vm or .jsp file references .pojo and that no other wrapper has a public getPojo().

@snoopdave

Copy link
Copy Markdown
Contributor Author

🤖Claude:

  • CHANGES.md: fixed by adding a 6.1.7 entry for theme authors (not yet pushed). It says $weblog.pojo, $entry.pojo and getPojo() no longer resolve, that such references now print as literal text, and which wrapper properties to use instead.
  • CI: not fixed here. Run CI and CodeQL on roller-6.1.x #206 has since added roller-6.1.x to the CI and CodeQL triggers; checks will start after this PR is rebased onto roller-6.1.x.

Initialise the test engine from WEB-INF/velocity.properties, dropping only
the settings that need a running webapp, so the introspection settings
under test are the real ones.

Add a 6.1.7 CHANGES.md entry for theme authors.
@snoopdave

Copy link
Copy Markdown
Contributor Author

With those fixes, this PR is ready for merge, IMO.

@snoopdave

Copy link
Copy Markdown
Contributor Author

Manually tested on the 6.1.7 integration build (Tomcat 9, JDK 11, MySQL 8) with a custom-theme template. Pass.

  • $model.weblog.pojo, $model.weblog.getPojo() and $entry.pojo print as literal text. $entry.title and $model.weblog.handle still work.
  • $utils.isUserAuthorizedToAuthor and isUserAuthorizedToAdmin return true when logged in as the owner and false when logged out.
  • With front-page aggregation on, $site.getWeblogEntriesPager($model.weblog, …) lists entries.
  • Fetched logged out, these render with no errors: the front page, the weblog page, a permalink, a category page, day and month archives, the Atom and RSS feeds, and search.

@snoopdave snoopdave removed the Ready for Review Ready for review label Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant