If this project saved you some time or made your day a little easier, a star would mean a lot — it helps others find it too.
Java scheduling library based on Quartz with ph-scope support (see ph-commons)
Add the following to your pom.xml to use this artifact, replacing x.y.z with the effective version number:
<dependency>
<groupId>com.helger.schedule</groupId>
<artifactId>ph-schedule</artifactId>
<version>x.y.z</version>
</dependency>This library is an in-process scheduler. Three points are worth knowing when integrating it into a host application:
SchedulerRepositoryis process-wide.com.helger.quartz.impl.SchedulerRepositoryis a static singleton keyed by scheduler name, andlookup(String)/lookupAll()are public with no access check. In a deployment whereph-mini-quartzlives in a shared classloader serving multiple applications (e.g. dropped into$CATALINA_HOME/libof a Tomcat hosting several WARs), application A can retrieve and manipulate application B's scheduler. Either shipph-mini-quartzinside each application's own classloader (e.g.WEB-INF/lib), or do not mix mutually untrusting applications in the same JVM.PropertySettingJobFactoryand untrustedJobDataMapcontents. By default this factory invokes any public setter on the Job class whose name matches a key in the mergedJobDataMap. If theJobDataMapis populated from external input, an attacker can invoke arbitrary setters — including any with side effects. Since v6.1.1 you can restrict the factory to a fixed set of keys viasetAllowedProperties(Collection<String>)oraddAllowedProperty(String); non-listed keys are then skipped (or warned/thrown about, depending on the existing flags). The default factory used byStdSchedulerFactoryisSimpleJobFactory, which does not call any setters —PropertySettingJobFactoryis opt-in.org.quartz.propertiesis a trust-sensitive system property.StdSchedulerFactoryreads it as a filesystem path with no canonicalization, then loads it viaFileInputStream. The property values inside that file (org.quartz.threadPool.class,org.quartz.jobStore.class,org.quartz.plugin.*, listener classes, etc.) become arguments toClass.forName(...).newInstance(). This is by design for plugin-driven scheduling, but it means an attacker who can set this system property at JVM startup can load arbitrary classes from the classpath. Treat it like a-Dflag passed by an operator; never derive it from data your application receives at runtime.
v6.1.1 - 2026-05-18
- Removed OSGI bundling
QuartzSchedulerThreadnow catchesThrowable(instead of onlyRuntimeException) in its main loop, so the scheduler thread no longer dies silently onErrors likeOutOfMemoryErrororNoClassDefFoundErrorQuartzSchedulerThreadnow installs anUncaughtExceptionHandlerso any remaining thread death is loggedQuartzSchedulerThread.setIdleWaitTimenow guards against a zero/negativenextIntboundSimpleThreadPool.WorkerThreadnow catchesThrowablewhile running a job, so a worker thrown out by anErroris no longer leaked out of the poolQuartzSchedulerThreadno longer re-asserts the interrupt flag inside its three innerwait()catches; the previous pattern caused a 100% CPU busy spin if the scheduler thread was externally interrupted, because each subsequentwait()re-threwInterruptedExceptionimmediatelyQuartzSchedulerThread's outerThrowablecatch now preserves the interrupt flag if it ever sees anInterruptedException(defensive — all knownwait()sites catch it locally)PropertySettingJobFactorynow supports an opt-in allow-list of property names viasetAllowedProperties(Collection)/addAllowedProperty(String). When set, only listed keys in the mergedJobDataMapare eligible for setter invocation; non-listed keys are skipped (or warned/thrown about, depending on the existing flags). Default behavior is unchanged.
v6.1.0 - 2025-11-16
- Updated to ph-commons 12.1.0
- Using JSpecify annotations
v6.0.1 - 2025-10-28
- Added misfireInstruction support to
JDK8TriggerBuilder
v6.0.0 - 2025-08-25
- Requires Java 17 as the minimum version
- Updated to ph-commons 12.0.0
v5.0.1 - 2024-03-27
- Updated to ph-commons 11.1.5
- Added Java 21 compatibility
v5.0.0 - 2023-01-12
- Using Java 11 as the baseline
- Updated to ph-commons 11
v4.2.0 - 2021-03-21
- Updated to ph-commons 10
- Changed Maven group ID from
com.helgertocom.helger.schedule
v4.1.1 - 2020-09-17
- Updated dependencies
v4.1.0 - 2020-03-29
- Improved debug logging
- Improved code quality slightly
- Updated to ph-commons 9.4.0
v4.0.1 - 2018-11-12
- Fixed OSGI ServiceProvider configuration
- Removed
com.helger.quartz.xmlpackage
v4.0.0 - 2017-12-06
- Updated to ph-commons 9.0.0
v3.6.1 - 2017-03-29
- Started updating MiniQuartz API for Java 8
v3.6.0 - 2016-12-12
- Moved AbstractScopeAwareJob to ph-web (reverted dependencies)
v3.5.0 - 2016-07-22
- Using a forked version of Quartz with less dependencies - "Mini quartz"
My personal Coding Styleguide | It is appreciated if you star the GitHub project if you like it.