Repository navigation
ReleaseNotes61
-
Authorization and Cookie headers are no longer sent along when a redirect goes to a different host, so a token or session can't leak to the redirect target. This is on by default. If you rely on the old behavior you can turn it off:
RestAssured.config = RestAssured.config().redirect(redirectConfig().stripSensitiveHeadersOnCrossHostRedirect(false));
Thanks to the University of Sydney security research team (Liyi Zhou, Ziyue Wang, Strick, Maurice, and Chenchen Yu) for the report.
-
Support for the HTTP QUERY method, which works like GET but carries the query in the request body. It's available in the standard API as well as in the Spring MockMvc and WebTestClient modules:
given(). contentType(ContentType.JSON). body(Map.of("status", "active", "limit", 10)). when(). query("/accounts/search"). then(). statusCode(200);
See usage for more info.
-
The json-schema-validator module now supports JSON Schema draft-06, draft-07, 2019-09 and 2020-12. The draft is picked from the
$schemakeyword in your schema, so you usually don't have to change anything. If your schemas don't declare$schemayou can choose the version yourself:get("/accounts/1").then().body(matchesJsonSchemaInClasspath("account-schema.json").using(JsonSchemaVersion.DRAFT_2020_12));
See usage for more info.
-
java.timevalues such asLocalDateandInstantcan be used as path, query and form parameters, headers and cookies, and are sent in ISO-8601 format. Value objects that serialize to a plain JSON string, such as a record with a@JsonValueaccessor, are sent without the surrounding quotes:given(). pathParam("date", LocalDate.of(2024, 4, 10)). queryParam("userId", new UserId(uuid)). when(). get("/reports/{date}");
See usage for more info.
-
A reusable response specification can now check a header against a value taken from the response:
ResponseSpecification created = new ResponseSpecBuilder(). expectStatusCode(201). expectHeader("Location", response -> endsWith("/users/" + response.path("id"))). build();
-
SSL settings, such as relaxed HTTPS validation, key and trust stores and certificate authentication, now also apply when an
httprequest is redirected tohttps. Previously the redirected request failed with "PKIX path building failed". -
JSON responses without an explicit charset are decoded as UTF-8 also for
+jsoncontent types (such asapplication/problem+json) and forapplication/jsonwith extra parameters (such asapplication/json; version=1). Previously non-ASCII characters could be garbled.
- Authorization and Cookie headers are stripped on cross-host redirects by default (see above).
- Schemas that already declared draft-06 or later in
$schemaused to be validated with draft-04 rules, which silently ignored newer keywords such asconstandif/then/else. They are now validated according to their declared draft, so a test that passed before can start failing if the response doesn't actually match the schema. A configuredJsonSchemaFactoryandcheckedValidationonly apply to draft-03 and draft-04 schemas. -
java.timeparameter, header and cookie values are sent usingtoString()instead of going through the object mapper. - In the Spring MockMvc module, an unnamed path parameter that isn't a simple value (number, string, boolean, enum, UUID,
java.timevalue and so on) is now serialized by the object mapper, like named path parameters, instead of using itstoString(). - In the Spring WebTestClient module, query parameters are now strictly encoded, so reserved characters such as
!or,in a value are sent percent-encoded. -
MultiPartSpecBuilder.charset(Charset)now throws anIllegalArgumentExceptionforbyte[]andInputStreamcontent, likecharset(String)already did, instead of silently ignoring the charset. -
Cookie.toString()always formats the Expires attribute in English (EEE, dd MMM yyyy HH:mm:ss zzz) instead of using the default locale.
- Fixed several JsonPath regressions from the Groovy 5 migration, such as
propertiesspread over a list of objects returning null (thanks to HDPark95 and kdelay). - Fixed JsonPath returning
-Infinityfor very large negative numbers (thanks to kdelay). - Fixed XmlPath and JsonPath for hyphenated names combined with negative indexes and ranges, e.g.
root.some-list[-1]androot.some-list[0..-1].sub-el(thanks to kdelay). - Fixed a
MalformedURLExceptionwhen a query string contains another URL, e.g.get("https://example.com?redirect=https://example.com/callback")(thanks to renechoi). - Fixed failures when the default locale is Turkish (thanks to rdmrtn).
- Request-specific SSL settings no longer leak into later requests when the HTTP client instance is reused.
- The charset given to
MultiPartSpecBuilder.charset(..)is now sent in the Content-Type ofFileparts, and other mime-type parameters are kept. - Spring WebTestClient: non-string unnamed path parameters work, path parameters are no longer encoded twice (thanks to hantsy), and query parameters containing
+,&,=or{...}reach the server unchanged. - Spring MockMvc and WebTestClient: unnamed path parameters are serialized like named ones, also in multipart requests.
- Thanks to seethinajayadileep for several PRs in this release.
See change log for more details.