Releases: aehrc/fhir-bulk-java
Releases · aehrc/fhir-bulk-java
Release list
v1.1.0
Security
- Fixed a path traversal vulnerability in bulk export downloads (#11): a malicious or malformed export manifest could previously cause files to be written outside the intended output directory (e.g. via absolute paths,
..segments, or a pre-placed symlink at the destination). The manifest is now validated where it enters the system — each resource type must match a safe character class — so a resolved path can never escape the output directory. A symlink at the download destination is now refused rather than followed; a plain file already there is overwritten (needed for retry, see below). - Bumped dependencies flagged by Dependabot (#18):
logback(1.2.11 → 1.5.34),commons-io(2.13.0 → 2.14.0),org.json(20230618 → 20231013), andwiremock-jre8-standalone(test-only, 2.35.0 → 2.35.1).
Features
- Retry downloads that are cut short mid-transfer (#16): previously, one truncated file download would abandon an entire export. Each file now gets multiple attempts (configurable), rewritten from the start each time, and the retry delay is bounded and randomised (jittered) rather than exponential, so concurrent downloads that fail together don't all back off in lockstep. New public
DownloadConfig, settable on the client builder, controlsmaxRetriesand the delay bound; a default is used if not supplied. - Allow a caller to supply their own Hadoop
FileSystemtoHdfsFileStoreFactoryvia a newforFileSystemAPI (#13), for callers that need to control filesystem identity/configuration directly (e.g. under user impersonation). - Output file extension is now inferred from the
outputFormatMIME type (#10) —application/fhir+ndjson/application/x-ndjson→.ndjson,application/vnd.apache.parquet→.parquet, unknown formats default to.ndjson.outputExtensionis now optional and, when set, overrides the inferred value.
Fixes
- Stopped closing a shared Hadoop filesystem (#13):
HdfsFileStoreFactorywas closing aFileSysteminstance obtained from Hadoop's JVM-wide cache, which is shared with the host application. A successful export would leave a closed, unusable instance in the cache, breaking all subsequent access to that scheme until the process was restarted. Closing the store is now a no-op — the filesystem is borrowed, not owned.
Full changelog: v1.0.4...v1.1.0
v1.0.4
What's Changed
- Extract authentication code to separate library by @johngrimes in #8
- Add _until parameter support by @johngrimes in #9
- Fix file extensions to be inferred from output format by @johngrimes in #10
Full Changelog: v1.0.3...v1.0.4
v1.0.3
What's Changed
- Add error logging for non-200 HTTP responses in JsonResponseHandler by @johngrimes in #4
- Update nimbus-jose-jwt to version 9.37.2 by @johngrimes in #6
Full Changelog: v1.0.2...v1.0.3
v1.0.2
What's Changed
- Fix 500 error in async auth token request by @johngrimes in #5
Full Changelog: v1.0.1...v1.0.2
v1.0.1
v1.0.0
Initial release.
Please check README.md for supported features.
v0.1.0-alfa
Test pre-release.
Check README.md for supported features.