[Java][WebClient]remove the dead code from java ApiClient.mustache - #6556

Merged
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1
Jul 2, 2020
Merged

[Java][WebClient]remove the dead code from java ApiClient.mustache#6556
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1

Conversation

@grzegorz-moto

@grzegorz-motogrzegorz-moto commented Jun 5, 2020

Copy link
Copy Markdown
Contributor

Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.

@bbdouglas (2017/07) @sreeshas (2017/08) @jfiala (2017/08) @lukoyanov (2017/09) @cbornet (2017/09) @jeff9finger (2018/01) @karismann (2019/03) @Zomzog (2019/04) @lwlee2608 (2019/10) @bkabrda (2020/01)

PR checklist

  • Read the contribution guidelines.
  • If contributing template-only or documentation-only changes which will change sample output, build the project before.
  • Run the shell script(s) under ./bin/ (or Windows batch scripts under.\bin\windows) to update Petstore samples related to your fix. This is important, as CI jobs will verify all generator outputs of your HEAD commit, and these must match the expectations made by your contribution. You only need to run ./bin/{LANG}-petstore.sh, ./bin/openapi3/{LANG}-petstore.sh if updating the code or mustache templates for a language ({LANG}) (e.g. php, ruby, python, etc).
  • File the PR against the correct branch: master, 4.3.x, 5.0.x. Default: master.
  • Copy the technical committee to review the pull request if your PR is targeting a particular programming language.

grzegorz-motoand others added 2 commits June 5, 2020 12:15
Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.
@grzegorz-motogrzegorz-moto changed the title remove the dead code from java WebClient ApiClient.mustache[Java][WebClient]remove the dead code from java ApiClient.mustacheJun 5, 2020
@wing328

Copy link
Copy Markdown
Member

cc @daonomic who contributed the WebClient support.

@wing328

Copy link
Copy Markdown
Member

Looks like ApiClientHttpRequestInterceptor is not used anywhere in the code.

If there's no further feedback/question on this PR, I'll merge it on coming Wed.

@grzegorz-moto can you please resolve the merge conflicts when you've time?

@wing328
wing328 merged commit 23f57a7 into OpenAPITools:masterJul 2, 2020
jimschubert added a commit that referenced this pull request Jul 3, 2020
* master: (142 commits)
update python samples
clarify direction of py client side validation flag (#6850)
fix erronous cmd arg example for docker in readme (#6846)
[BUG] [JAVA] Fix multiple files upload (#4803) (#6808)
[kotlin][client] fix retrofit dependencies (#6836)
[PowerShell] add more fields to be customized (#6835)
[Java][WebClient]remove the dead code from java ApiClient.mustache (#6556)
[PHP] Better handling of invalid data (array) (#6760)
Make ApiClient in retrofit2 be able to use own OkHttpClient (#6699)
mark python2 support in flask as deprecated (#6653)
update samples
[Java][jersey2] Add a getter for the User-Agent header value (#6831)
Provides a default nil value for optional init parameters (#6827)
[Java] Deprecate feignVersion option (#6824)
[R] Enum R6Class Support, closes#3367 (#5728)
[Rust][Client] Unify sync/async client structure (#6753)
[php-ze-ph] Set required PHP version to ^7.2 (#6763)
[Java][client][native][Gradle] Add missing jackson-databind-nullable (#6802)
Improve sttpOpenApiClient generator (#6684)
Update docker-tag-latest-release.yml
...
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@grzegorz-moto@wing328
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[Java][WebClient]remove the dead code from java ApiClient.mustache - #6556

Merged
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1
Jul 2, 2020
Merged

[Java][WebClient]remove the dead code from java ApiClient.mustache#6556
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1

Conversation

@grzegorz-moto

@grzegorz-motogrzegorz-moto commented Jun 5, 2020

Copy link
Copy Markdown
Contributor

Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.

@bbdouglas (2017/07) @sreeshas (2017/08) @jfiala (2017/08) @lukoyanov (2017/09) @cbornet (2017/09) @jeff9finger (2018/01) @karismann (2019/03) @Zomzog (2019/04) @lwlee2608 (2019/10) @bkabrda (2020/01)

PR checklist

  • Read the contribution guidelines.
  • If contributing template-only or documentation-only changes which will change sample output, build the project before.
  • Run the shell script(s) under ./bin/ (or Windows batch scripts under.\bin\windows) to update Petstore samples related to your fix. This is important, as CI jobs will verify all generator outputs of your HEAD commit, and these must match the expectations made by your contribution. You only need to run ./bin/{LANG}-petstore.sh, ./bin/openapi3/{LANG}-petstore.sh if updating the code or mustache templates for a language ({LANG}) (e.g. php, ruby, python, etc).
  • File the PR against the correct branch: master, 4.3.x, 5.0.x. Default: master.
  • Copy the technical committee to review the pull request if your PR is targeting a particular programming language.

grzegorz-motoand others added 2 commits June 5, 2020 12:15
Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.
@grzegorz-motogrzegorz-moto changed the title remove the dead code from java WebClient ApiClient.mustache[Java][WebClient]remove the dead code from java ApiClient.mustacheJun 5, 2020
@wing328

Copy link
Copy Markdown
Member

cc @daonomic who contributed the WebClient support.

@wing328

Copy link
Copy Markdown
Member

Looks like ApiClientHttpRequestInterceptor is not used anywhere in the code.

If there's no further feedback/question on this PR, I'll merge it on coming Wed.

@grzegorz-moto can you please resolve the merge conflicts when you've time?

@wing328
wing328 merged commit 23f57a7 into OpenAPITools:masterJul 2, 2020
jimschubert added a commit that referenced this pull request Jul 3, 2020
* master: (142 commits)
update python samples
clarify direction of py client side validation flag (#6850)
fix erronous cmd arg example for docker in readme (#6846)
[BUG] [JAVA] Fix multiple files upload (#4803) (#6808)
[kotlin][client] fix retrofit dependencies (#6836)
[PowerShell] add more fields to be customized (#6835)
[Java][WebClient]remove the dead code from java ApiClient.mustache (#6556)
[PHP] Better handling of invalid data (array) (#6760)
Make ApiClient in retrofit2 be able to use own OkHttpClient (#6699)
mark python2 support in flask as deprecated (#6653)
update samples
[Java][jersey2] Add a getter for the User-Agent header value (#6831)
Provides a default nil value for optional init parameters (#6827)
[Java] Deprecate feignVersion option (#6824)
[R] Enum R6Class Support, closes#3367 (#5728)
[Rust][Client] Unify sync/async client structure (#6753)
[php-ze-ph] Set required PHP version to ^7.2 (#6763)
[Java][client][native][Gradle] Add missing jackson-databind-nullable (#6802)
Improve sttpOpenApiClient generator (#6684)
Update docker-tag-latest-release.yml
...
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@grzegorz-moto@wing328
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Java][WebClient]remove the dead code from java ApiClient.mustache - #6556

Merged
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1
Jul 2, 2020
Merged

[Java][WebClient]remove the dead code from java ApiClient.mustache#6556
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1

Conversation

@grzegorz-moto

@grzegorz-motogrzegorz-moto commented Jun 5, 2020

Copy link
Copy Markdown
Contributor

Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.

@bbdouglas (2017/07) @sreeshas (2017/08) @jfiala (2017/08) @lukoyanov (2017/09) @cbornet (2017/09) @jeff9finger (2018/01) @karismann (2019/03) @Zomzog (2019/04) @lwlee2608 (2019/10) @bkabrda (2020/01)

PR checklist

  • Read the contribution guidelines.
  • If contributing template-only or documentation-only changes which will change sample output, build the project before.
  • Run the shell script(s) under ./bin/ (or Windows batch scripts under.\bin\windows) to update Petstore samples related to your fix. This is important, as CI jobs will verify all generator outputs of your HEAD commit, and these must match the expectations made by your contribution. You only need to run ./bin/{LANG}-petstore.sh, ./bin/openapi3/{LANG}-petstore.sh if updating the code or mustache templates for a language ({LANG}) (e.g. php, ruby, python, etc).
  • File the PR against the correct branch: master, 4.3.x, 5.0.x. Default: master.
  • Copy the technical committee to review the pull request if your PR is targeting a particular programming language.

grzegorz-motoand others added 2 commits June 5, 2020 12:15
Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.
@grzegorz-motogrzegorz-moto changed the title remove the dead code from java WebClient ApiClient.mustache[Java][WebClient]remove the dead code from java ApiClient.mustacheJun 5, 2020
@wing328

Copy link
Copy Markdown
Member

cc @daonomic who contributed the WebClient support.

@wing328

Copy link
Copy Markdown
Member

Looks like ApiClientHttpRequestInterceptor is not used anywhere in the code.

If there's no further feedback/question on this PR, I'll merge it on coming Wed.

@grzegorz-moto can you please resolve the merge conflicts when you've time?

@wing328
wing328 merged commit 23f57a7 into OpenAPITools:masterJul 2, 2020
jimschubert added a commit that referenced this pull request Jul 3, 2020
* master: (142 commits)
update python samples
clarify direction of py client side validation flag (#6850)
fix erronous cmd arg example for docker in readme (#6846)
[BUG] [JAVA] Fix multiple files upload (#4803) (#6808)
[kotlin][client] fix retrofit dependencies (#6836)
[PowerShell] add more fields to be customized (#6835)
[Java][WebClient]remove the dead code from java ApiClient.mustache (#6556)
[PHP] Better handling of invalid data (array) (#6760)
Make ApiClient in retrofit2 be able to use own OkHttpClient (#6699)
mark python2 support in flask as deprecated (#6653)
update samples
[Java][jersey2] Add a getter for the User-Agent header value (#6831)
Provides a default nil value for optional init parameters (#6827)
[Java] Deprecate feignVersion option (#6824)
[R] Enum R6Class Support, closes#3367 (#5728)
[Rust][Client] Unify sync/async client structure (#6753)
[php-ze-ph] Set required PHP version to ^7.2 (#6763)
[Java][client][native][Gradle] Add missing jackson-databind-nullable (#6802)
Improve sttpOpenApiClient generator (#6684)
Update docker-tag-latest-release.yml
...
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@grzegorz-moto@wing328
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Java][WebClient]remove the dead code from java ApiClient.mustache - #6556

Merged
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1
Jul 2, 2020
Merged

[Java][WebClient]remove the dead code from java ApiClient.mustache#6556
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1

Conversation

@grzegorz-moto

@grzegorz-motogrzegorz-moto commented Jun 5, 2020

Copy link
Copy Markdown
Contributor

Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.

@bbdouglas (2017/07) @sreeshas (2017/08) @jfiala (2017/08) @lukoyanov (2017/09) @cbornet (2017/09) @jeff9finger (2018/01) @karismann (2019/03) @Zomzog (2019/04) @lwlee2608 (2019/10) @bkabrda (2020/01)

PR checklist

  • Read the contribution guidelines.
  • If contributing template-only or documentation-only changes which will change sample output, build the project before.
  • Run the shell script(s) under ./bin/ (or Windows batch scripts under.\bin\windows) to update Petstore samples related to your fix. This is important, as CI jobs will verify all generator outputs of your HEAD commit, and these must match the expectations made by your contribution. You only need to run ./bin/{LANG}-petstore.sh, ./bin/openapi3/{LANG}-petstore.sh if updating the code or mustache templates for a language ({LANG}) (e.g. php, ruby, python, etc).
  • File the PR against the correct branch: master, 4.3.x, 5.0.x. Default: master.
  • Copy the technical committee to review the pull request if your PR is targeting a particular programming language.

grzegorz-motoand others added 2 commits June 5, 2020 12:15
Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.
@grzegorz-motogrzegorz-moto changed the title remove the dead code from java WebClient ApiClient.mustache[Java][WebClient]remove the dead code from java ApiClient.mustacheJun 5, 2020
@wing328

Copy link
Copy Markdown
Member

cc @daonomic who contributed the WebClient support.

@wing328

Copy link
Copy Markdown
Member

Looks like ApiClientHttpRequestInterceptor is not used anywhere in the code.

If there's no further feedback/question on this PR, I'll merge it on coming Wed.

@grzegorz-moto can you please resolve the merge conflicts when you've time?

@wing328
wing328 merged commit 23f57a7 into OpenAPITools:masterJul 2, 2020
jimschubert added a commit that referenced this pull request Jul 3, 2020
* master: (142 commits)
update python samples
clarify direction of py client side validation flag (#6850)
fix erronous cmd arg example for docker in readme (#6846)
[BUG] [JAVA] Fix multiple files upload (#4803) (#6808)
[kotlin][client] fix retrofit dependencies (#6836)
[PowerShell] add more fields to be customized (#6835)
[Java][WebClient]remove the dead code from java ApiClient.mustache (#6556)
[PHP] Better handling of invalid data (array) (#6760)
Make ApiClient in retrofit2 be able to use own OkHttpClient (#6699)
mark python2 support in flask as deprecated (#6653)
update samples
[Java][jersey2] Add a getter for the User-Agent header value (#6831)
Provides a default nil value for optional init parameters (#6827)
[Java] Deprecate feignVersion option (#6824)
[R] Enum R6Class Support, closes#3367 (#5728)
[Rust][Client] Unify sync/async client structure (#6753)
[php-ze-ph] Set required PHP version to ^7.2 (#6763)
[Java][client][native][Gradle] Add missing jackson-databind-nullable (#6802)
Improve sttpOpenApiClient generator (#6684)
Update docker-tag-latest-release.yml
...
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@grzegorz-moto@wing328
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[Java][WebClient]remove the dead code from java ApiClient.mustache - #6556

Merged
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1
Jul 2, 2020
Merged

[Java][WebClient]remove the dead code from java ApiClient.mustache#6556
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1

Conversation

@grzegorz-moto

@grzegorz-motogrzegorz-moto commented Jun 5, 2020

Copy link
Copy Markdown
Contributor

Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.

@bbdouglas (2017/07) @sreeshas (2017/08) @jfiala (2017/08) @lukoyanov (2017/09) @cbornet (2017/09) @jeff9finger (2018/01) @karismann (2019/03) @Zomzog (2019/04) @lwlee2608 (2019/10) @bkabrda (2020/01)

PR checklist

  • Read the contribution guidelines.
  • If contributing template-only or documentation-only changes which will change sample output, build the project before.
  • Run the shell script(s) under ./bin/ (or Windows batch scripts under.\bin\windows) to update Petstore samples related to your fix. This is important, as CI jobs will verify all generator outputs of your HEAD commit, and these must match the expectations made by your contribution. You only need to run ./bin/{LANG}-petstore.sh, ./bin/openapi3/{LANG}-petstore.sh if updating the code or mustache templates for a language ({LANG}) (e.g. php, ruby, python, etc).
  • File the PR against the correct branch: master, 4.3.x, 5.0.x. Default: master.
  • Copy the technical committee to review the pull request if your PR is targeting a particular programming language.

grzegorz-motoand others added 2 commits June 5, 2020 12:15
Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.
@grzegorz-motogrzegorz-moto changed the title remove the dead code from java WebClient ApiClient.mustache[Java][WebClient]remove the dead code from java ApiClient.mustacheJun 5, 2020
@wing328

Copy link
Copy Markdown
Member

cc @daonomic who contributed the WebClient support.

@wing328

Copy link
Copy Markdown
Member

Looks like ApiClientHttpRequestInterceptor is not used anywhere in the code.

If there's no further feedback/question on this PR, I'll merge it on coming Wed.

@grzegorz-moto can you please resolve the merge conflicts when you've time?

@wing328
wing328 merged commit 23f57a7 into OpenAPITools:masterJul 2, 2020
jimschubert added a commit that referenced this pull request Jul 3, 2020
* master: (142 commits)
update python samples
clarify direction of py client side validation flag (#6850)
fix erronous cmd arg example for docker in readme (#6846)
[BUG] [JAVA] Fix multiple files upload (#4803) (#6808)
[kotlin][client] fix retrofit dependencies (#6836)
[PowerShell] add more fields to be customized (#6835)
[Java][WebClient]remove the dead code from java ApiClient.mustache (#6556)
[PHP] Better handling of invalid data (array) (#6760)
Make ApiClient in retrofit2 be able to use own OkHttpClient (#6699)
mark python2 support in flask as deprecated (#6653)
update samples
[Java][jersey2] Add a getter for the User-Agent header value (#6831)
Provides a default nil value for optional init parameters (#6827)
[Java] Deprecate feignVersion option (#6824)
[R] Enum R6Class Support, closes#3367 (#5728)
[Rust][Client] Unify sync/async client structure (#6753)
[php-ze-ph] Set required PHP version to ^7.2 (#6763)
[Java][client][native][Gradle] Add missing jackson-databind-nullable (#6802)
Improve sttpOpenApiClient generator (#6684)
Update docker-tag-latest-release.yml
...
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@grzegorz-moto@wing328
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Java][WebClient]remove the dead code from java ApiClient.mustache - #6556

Merged
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1
Jul 2, 2020
Merged

[Java][WebClient]remove the dead code from java ApiClient.mustache#6556
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1

Conversation

@grzegorz-moto

@grzegorz-motogrzegorz-moto commented Jun 5, 2020

Copy link
Copy Markdown
Contributor

Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.

@bbdouglas (2017/07) @sreeshas (2017/08) @jfiala (2017/08) @lukoyanov (2017/09) @cbornet (2017/09) @jeff9finger (2018/01) @karismann (2019/03) @Zomzog (2019/04) @lwlee2608 (2019/10) @bkabrda (2020/01)

PR checklist

  • Read the contribution guidelines.
  • If contributing template-only or documentation-only changes which will change sample output, build the project before.
  • Run the shell script(s) under ./bin/ (or Windows batch scripts under.\bin\windows) to update Petstore samples related to your fix. This is important, as CI jobs will verify all generator outputs of your HEAD commit, and these must match the expectations made by your contribution. You only need to run ./bin/{LANG}-petstore.sh, ./bin/openapi3/{LANG}-petstore.sh if updating the code or mustache templates for a language ({LANG}) (e.g. php, ruby, python, etc).
  • File the PR against the correct branch: master, 4.3.x, 5.0.x. Default: master.
  • Copy the technical committee to review the pull request if your PR is targeting a particular programming language.

grzegorz-motoand others added 2 commits June 5, 2020 12:15
Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.
@grzegorz-motogrzegorz-moto changed the title remove the dead code from java WebClient ApiClient.mustache[Java][WebClient]remove the dead code from java ApiClient.mustacheJun 5, 2020
@wing328

Copy link
Copy Markdown
Member

cc @daonomic who contributed the WebClient support.

@wing328

Copy link
Copy Markdown
Member

Looks like ApiClientHttpRequestInterceptor is not used anywhere in the code.

If there's no further feedback/question on this PR, I'll merge it on coming Wed.

@grzegorz-moto can you please resolve the merge conflicts when you've time?

@wing328
wing328 merged commit 23f57a7 into OpenAPITools:masterJul 2, 2020
jimschubert added a commit that referenced this pull request Jul 3, 2020
* master: (142 commits)
update python samples
clarify direction of py client side validation flag (#6850)
fix erronous cmd arg example for docker in readme (#6846)
[BUG] [JAVA] Fix multiple files upload (#4803) (#6808)
[kotlin][client] fix retrofit dependencies (#6836)
[PowerShell] add more fields to be customized (#6835)
[Java][WebClient]remove the dead code from java ApiClient.mustache (#6556)
[PHP] Better handling of invalid data (array) (#6760)
Make ApiClient in retrofit2 be able to use own OkHttpClient (#6699)
mark python2 support in flask as deprecated (#6653)
update samples
[Java][jersey2] Add a getter for the User-Agent header value (#6831)
Provides a default nil value for optional init parameters (#6827)
[Java] Deprecate feignVersion option (#6824)
[R] Enum R6Class Support, closes#3367 (#5728)
[Rust][Client] Unify sync/async client structure (#6753)
[php-ze-ph] Set required PHP version to ^7.2 (#6763)
[Java][client][native][Gradle] Add missing jackson-databind-nullable (#6802)
Improve sttpOpenApiClient generator (#6684)
Update docker-tag-latest-release.yml
...
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@grzegorz-moto@wing328
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Java][WebClient]remove the dead code from java ApiClient.mustache - #6556

Merged
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1
Jul 2, 2020
Merged

[Java][WebClient]remove the dead code from java ApiClient.mustache#6556
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1

Conversation

@grzegorz-moto

@grzegorz-motogrzegorz-moto commented Jun 5, 2020

Copy link
Copy Markdown
Contributor

Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.

@bbdouglas (2017/07) @sreeshas (2017/08) @jfiala (2017/08) @lukoyanov (2017/09) @cbornet (2017/09) @jeff9finger (2018/01) @karismann (2019/03) @Zomzog (2019/04) @lwlee2608 (2019/10) @bkabrda (2020/01)

PR checklist

  • Read the contribution guidelines.
  • If contributing template-only or documentation-only changes which will change sample output, build the project before.
  • Run the shell script(s) under ./bin/ (or Windows batch scripts under.\bin\windows) to update Petstore samples related to your fix. This is important, as CI jobs will verify all generator outputs of your HEAD commit, and these must match the expectations made by your contribution. You only need to run ./bin/{LANG}-petstore.sh, ./bin/openapi3/{LANG}-petstore.sh if updating the code or mustache templates for a language ({LANG}) (e.g. php, ruby, python, etc).
  • File the PR against the correct branch: master, 4.3.x, 5.0.x. Default: master.
  • Copy the technical committee to review the pull request if your PR is targeting a particular programming language.

grzegorz-motoand others added 2 commits June 5, 2020 12:15
Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.
@grzegorz-motogrzegorz-moto changed the title remove the dead code from java WebClient ApiClient.mustache[Java][WebClient]remove the dead code from java ApiClient.mustacheJun 5, 2020
@wing328

Copy link
Copy Markdown
Member

cc @daonomic who contributed the WebClient support.

@wing328

Copy link
Copy Markdown
Member

Looks like ApiClientHttpRequestInterceptor is not used anywhere in the code.

If there's no further feedback/question on this PR, I'll merge it on coming Wed.

@grzegorz-moto can you please resolve the merge conflicts when you've time?

@wing328
wing328 merged commit 23f57a7 into OpenAPITools:masterJul 2, 2020
jimschubert added a commit that referenced this pull request Jul 3, 2020
* master: (142 commits)
update python samples
clarify direction of py client side validation flag (#6850)
fix erronous cmd arg example for docker in readme (#6846)
[BUG] [JAVA] Fix multiple files upload (#4803) (#6808)
[kotlin][client] fix retrofit dependencies (#6836)
[PowerShell] add more fields to be customized (#6835)
[Java][WebClient]remove the dead code from java ApiClient.mustache (#6556)
[PHP] Better handling of invalid data (array) (#6760)
Make ApiClient in retrofit2 be able to use own OkHttpClient (#6699)
mark python2 support in flask as deprecated (#6653)
update samples
[Java][jersey2] Add a getter for the User-Agent header value (#6831)
Provides a default nil value for optional init parameters (#6827)
[Java] Deprecate feignVersion option (#6824)
[R] Enum R6Class Support, closes#3367 (#5728)
[Rust][Client] Unify sync/async client structure (#6753)
[php-ze-ph] Set required PHP version to ^7.2 (#6763)
[Java][client][native][Gradle] Add missing jackson-databind-nullable (#6802)
Improve sttpOpenApiClient generator (#6684)
Update docker-tag-latest-release.yml
...
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@grzegorz-moto@wing328
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[Java][WebClient]remove the dead code from java ApiClient.mustache - #6556

Merged
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1
Jul 2, 2020
Merged

[Java][WebClient]remove the dead code from java ApiClient.mustache#6556
wing328 merged 4 commits into
OpenAPITools:masterfrom
grzegorz-moto:patch-1

Conversation

@grzegorz-moto

@grzegorz-motogrzegorz-moto commented Jun 5, 2020

Copy link
Copy Markdown
Contributor

Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.

@bbdouglas (2017/07) @sreeshas (2017/08) @jfiala (2017/08) @lukoyanov (2017/09) @cbornet (2017/09) @jeff9finger (2018/01) @karismann (2019/03) @Zomzog (2019/04) @lwlee2608 (2019/10) @bkabrda (2020/01)

PR checklist

  • Read the contribution guidelines.
  • If contributing template-only or documentation-only changes which will change sample output, build the project before.
  • Run the shell script(s) under ./bin/ (or Windows batch scripts under.\bin\windows) to update Petstore samples related to your fix. This is important, as CI jobs will verify all generator outputs of your HEAD commit, and these must match the expectations made by your contribution. You only need to run ./bin/{LANG}-petstore.sh, ./bin/openapi3/{LANG}-petstore.sh if updating the code or mustache templates for a language ({LANG}) (e.g. php, ruby, python, etc).
  • File the PR against the correct branch: master, 4.3.x, 5.0.x. Default: master.
  • Copy the technical committee to review the pull request if your PR is targeting a particular programming language.

grzegorz-motoand others added 2 commits June 5, 2020 12:15
Remove the dead code from ApiClient
The code is not used and it contains vulnerability of Log Forgery when it writes unvalidated http header to the log. An attacker could take advantage of this behaviour to forge log entries or inject malicious content into the log.
@grzegorz-motogrzegorz-moto changed the title remove the dead code from java WebClient ApiClient.mustache[Java][WebClient]remove the dead code from java ApiClient.mustacheJun 5, 2020
@wing328

Copy link
Copy Markdown
Member

cc @daonomic who contributed the WebClient support.

@wing328

Copy link
Copy Markdown
Member

Looks like ApiClientHttpRequestInterceptor is not used anywhere in the code.

If there's no further feedback/question on this PR, I'll merge it on coming Wed.

@grzegorz-moto can you please resolve the merge conflicts when you've time?

@wing328
wing328 merged commit 23f57a7 into OpenAPITools:masterJul 2, 2020
jimschubert added a commit that referenced this pull request Jul 3, 2020
* master: (142 commits)
update python samples
clarify direction of py client side validation flag (#6850)
fix erronous cmd arg example for docker in readme (#6846)
[BUG] [JAVA] Fix multiple files upload (#4803) (#6808)
[kotlin][client] fix retrofit dependencies (#6836)
[PowerShell] add more fields to be customized (#6835)
[Java][WebClient]remove the dead code from java ApiClient.mustache (#6556)
[PHP] Better handling of invalid data (array) (#6760)
Make ApiClient in retrofit2 be able to use own OkHttpClient (#6699)
mark python2 support in flask as deprecated (#6653)
update samples
[Java][jersey2] Add a getter for the User-Agent header value (#6831)
Provides a default nil value for optional init parameters (#6827)
[Java] Deprecate feignVersion option (#6824)
[R] Enum R6Class Support, closes#3367 (#5728)
[Rust][Client] Unify sync/async client structure (#6753)
[php-ze-ph] Set required PHP version to ^7.2 (#6763)
[Java][client][native][Gradle] Add missing jackson-databind-nullable (#6802)
Improve sttpOpenApiClient generator (#6684)
Update docker-tag-latest-release.yml
...
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@grzegorz-moto@wing328