Skip to content

ReleaseNotes61

Claude edited this page Oct 9, 2026 · 1 revision

Release Notes for REST Assured 6.1.0

Contents

  1. Highlights
  2. Non-backward compatible changes
  3. Other Changes

Highlights

  • Authorization and Cookie headers are no longer sent along when a redirect goes to a different host, so a token or session can't leak to the redirect target. This is on by default. If you rely on the old behavior you can turn it off:

     RestAssured.config = RestAssured.config().redirect(redirectConfig().stripSensitiveHeadersOnCrossHostRedirect(false));

    Thanks to the University of Sydney security research team (Liyi Zhou, Ziyue Wang, Strick, Maurice, and Chenchen Yu) for the report.

  • Support for the HTTP QUERY method, which works like GET but carries the query in the request body. It's available in the standard API as well as in the Spring MockMvc and WebTestClient modules:

     given().
             contentType(ContentType.JSON).
             body(Map.of("status", "active", "limit", 10)).
     when().
             query("/accounts/search").
     then().
             statusCode(200);

    See usage for more info.

  • The json-schema-validator module now supports JSON Schema draft-06, draft-07, 2019-09 and 2020-12. The draft is picked from the $schema keyword in your schema, so you usually don't have to change anything. If your schemas don't declare $schema you can choose the version yourself:

     get("/accounts/1").then().body(matchesJsonSchemaInClasspath("account-schema.json").using(JsonSchemaVersion.DRAFT_2020_12));

    See usage for more info.

  • java.time values such as LocalDate and Instant can be used as path, query and form parameters, headers and cookies, and are sent in ISO-8601 format. Value objects that serialize to a plain JSON string, such as a record with a @JsonValue accessor, are sent without the surrounding quotes:

     given().
             pathParam("date", LocalDate.of(2024, 4, 10)).
             queryParam("userId", new UserId(uuid)).
     when().
             get("/reports/{date}");

    See usage for more info.

  • A reusable response specification can now check a header against a value taken from the response:

     ResponseSpecification created = new ResponseSpecBuilder().
             expectStatusCode(201).
             expectHeader("Location", response -> endsWith("/users/" + response.path("id"))).
             build();
  • SSL settings, such as relaxed HTTPS validation, key and trust stores and certificate authentication, now also apply when an http request is redirected to https. Previously the redirected request failed with "PKIX path building failed".

  • JSON responses without an explicit charset are decoded as UTF-8 also for +json content types (such as application/problem+json) and for application/json with extra parameters (such as application/json; version=1). Previously non-ASCII characters could be garbled.

Non-backward compatible changes

  • Authorization and Cookie headers are stripped on cross-host redirects by default (see above).
  • Schemas that already declared draft-06 or later in $schema used to be validated with draft-04 rules, which silently ignored newer keywords such as const and if/then/else. They are now validated according to their declared draft, so a test that passed before can start failing if the response doesn't actually match the schema. A configured JsonSchemaFactory and checkedValidation only apply to draft-03 and draft-04 schemas.
  • java.time parameter, header and cookie values are sent using toString() instead of going through the object mapper.
  • In the Spring MockMvc module, an unnamed path parameter that isn't a simple value (number, string, boolean, enum, UUID, java.time value and so on) is now serialized by the object mapper, like named path parameters, instead of using its toString().
  • In the Spring WebTestClient module, query parameters are now strictly encoded, so reserved characters such as ! or , in a value are sent percent-encoded.
  • MultiPartSpecBuilder.charset(Charset) now throws an IllegalArgumentException for byte[] and InputStream content, like charset(String) already did, instead of silently ignoring the charset.
  • Cookie.toString() always formats the Expires attribute in English (EEE, dd MMM yyyy HH:mm:ss zzz) instead of using the default locale.

Other changes

  • Fixed several JsonPath regressions from the Groovy 5 migration, such as properties spread over a list of objects returning null (thanks to HDPark95 and kdelay).
  • Fixed JsonPath returning -Infinity for very large negative numbers (thanks to kdelay).
  • Fixed XmlPath and JsonPath for hyphenated names combined with negative indexes and ranges, e.g. root.some-list[-1] and root.some-list[0..-1].sub-el (thanks to kdelay).
  • Fixed a MalformedURLException when a query string contains another URL, e.g. get("https://example.com?redirect=https://example.com/callback") (thanks to renechoi).
  • Fixed failures when the default locale is Turkish (thanks to rdmrtn).
  • Request-specific SSL settings no longer leak into later requests when the HTTP client instance is reused.
  • The charset given to MultiPartSpecBuilder.charset(..) is now sent in the Content-Type of File parts, and other mime-type parameters are kept.
  • Spring WebTestClient: non-string unnamed path parameters work, path parameters are no longer encoded twice (thanks to hantsy), and query parameters containing +, &, = or {...} reach the server unchanged.
  • Spring MockMvc and WebTestClient: unnamed path parameters are serialized like named ones, also in multipart requests.
  • Thanks to seethinajayadileep for several PRs in this release.

See change log for more details.

Clone this wiki locally