⚠️ Attention Required
- in Spring Framework 7.0.9,
ForwardedHeaderFilter(Spring MVC) andForwardedHeaderTransformer(WebFlux) each provide a boolean constructor argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property turns on and off use of "X-Forwarded-Prefix". While the default constructor preserves the existing behavior, we recommend to use the new constructor to explicitly specify which forwarded headers to use to make the processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section for details. In 7.1 with #37072 the default constructor is deprecated and marked for removal. #37090
⭐ New Features
- Ignore an empty port value in URI parsing #37117
- Avoid retaining class files in annotation metadata #37112
- Add
@Nullableannotations when treatingMap.remove()as returning@Nullable#37067 - Revisit SSE view fragments handling #37061
- Improve efficiency of list creation in data binding #37036
- Revise operator internals in SpEL #37034
- Refactor redirect handling in UrlHandlerFilter #37030
- Revise stylesheet source handling in XsltView #37029
- Revise view name handling in UrlFilenameViewController #37027
- Handle pre-flight requests in functional endpoint setup without DispatcherHandler #37024
- Improve WebSocket handshake error logging #37023
- Fix missing nullability in JdbcTemplate.batchUpdate #37012
- Timeout property in RetryPolicy does not have a default constant #36983
- Write native configuration files as UTF-8 #36972
- DefaultServerRequest.ServletParametersMap.entrySet() does not retain HttpServletRequest.getParameterMap() order #36966
- Perform nextKey within synchronization for SQLite as well #36959
- Add support for custom ObjectInputFilter on DefaultDeserializer #36958
- Revise resource bundle caching for common locales #36957
- Improve nullability for
getSession(*)inMockHttpServletRequest#36926 - Improve fallback logic in ParameterContentNegotiationStrategy and ParameterContentTypeResolver #36925
- Improve ambiguous match check on preflight request #36903
- Improve Groovy markup template loading #36902
- Improve request path handling on a Reactor Netty server #36893
- Improve JettyWebSocketSession error handling #36891
🐞 Bug Fixes
- EclipseLinkJpaDialect singleton lock in EclipseLinkConnectionHandle.getConnection() serializes all JDBC connection acquisitions under load #37085
- MetadataReader fails to read byte[] array from annotation #37083
- Ensure parsing/tostring symmetry in ContentDisposition #37064
- Character outside of permitted range in Content Disposition #37062
- Release Jackson BufferRecycler to its pool in encoders #37059
- Ensure consistent error escaping #37055
- Refine template name processing #37054
- Reset TwoByteMatcher partial match on mismatching byte #37053
- Refactor async XML parsing limit checks #37031
- Fix part constraint checks in PartEventHttpMessageReader #37028
- Fix buffer leak in RSocket SETUP frame handling #37026
- Ensure correct Jetty core response cookie handling #37025
- Align
domainToAsciiwith current WhatWG spec #37018 - Ensure consistent
ButtonTagvalue attribute processing #37017 - SpEL's
InlineListis cached as a mutable list in compiled mode #37001 - Write native configuration file when only lambda hints are present #36989
- SpEL
Indexerreuses invalid cachedPropertyAccessor#36986 - SpEL reuses invalid cached
ConstructorExecutor#36985 MimeTypeUtilsraisesStringIndexOutOfBoundsExceptionfor some invalid mime types #36971- Ignore DOCTYPE inside a multi-line comment body #36948
- Avoid divide-by-zero in
ExponentialBackOffjitter #36932 - Refactor use or close lock in ConcurrentWebSocketSessionDecorator #36909
- Host header initialization breaking change in StompRelayMessageBrokerHandler #36907
- Remote address checks for SockJS session #36681 breaks xhr-polling #36904
- LifeCyclePrintWriter does not delegate correctly #36885
- IllegalArgumentException when creating named native query via Shared EntityManager with Hibernate 8.0.0-SNAPSHOT / JPA 4.0.0-M4 #36878
📔 Documentation
- Document AOP proxy semantics for Bean Overrides in tests #37121
- Provide guidance for object model design in SpEL #37102
- Fix Javadoc error in ProtobufDecoder #37079
- Improve documentation for SpEL compilation support #37035
- Document security implications of evaluating untrusted SpEL expressions #36997
- Document relationships between expressions, evaluation contexts, and accessors in SpEL #36968
- Update Javadoc for
@ActiveProfilesordering #36950 - Document behavior for 0 delay combined with jitter in backoff policies #36946
- Clarify design goal of UrlFilenameViewController in Javadoc #36906
🔨 Dependency Upgrades
❤️ Contributors
Thank you to all the contributors who worked on this release:
@ZaMan0806, @alexisgra, @alshain, @gianmarcoschifone, @junhyeong9812, @msridhar, @perovic, @quaff, and @samueldlightfoot