Skip to content

Chore/security ci hardening - #7

Open
davidjbrossard wants to merge 6 commits into
masterfrom
chore/security-ci-hardening
Open

davidjbrossard wants to merge 6 commits into
masterfrom
chore/security-ci-hardening

Conversation

@davidjbrossard

Copy link
Copy Markdown

I used Claude to inspect our Java PEP SDK, upgrade to Java 17, and move to newer versions of dependencies.

davidjbrossard and others added 4 commits September 24, 2026 14:32
…ependencies

Client fixes:
- JaxRsAuthZClient shared one Invocation.Builder across calls, which is not
  thread-safe: under concurrent use requests failed with duplicated
  Content-Type headers or ProcessingExceptions. It now builds a request per
  call from a shared WebTarget. The Invocation.Builder constructor and field
  are kept but deprecated; subclasses can override newRequest() to add
  headers. The client is now AutoCloseable.
- DefaultClientConfiguration (and its builder) no longer print the password
  in toString().
- Both clients now reject a username without a password instead of silently
  sending no credentials (Feign) or an empty password (JAX-RS).
- pdpUrl() is marked @deprecated; the builder error message names the
  correct method.

Dependencies:
- Import the Jackson and Jersey BOMs. Without them Maven's nearest-wins
  resolution gave consumers jackson-databind 2.10.1 (JAX-RS) or 2.12.3
  (Feign) instead of the pinned version.
- Replace springfox-swagger2 with swagger-annotations: only the annotations
  were used, and springfox pulled Spring 4.0.9 and Guava 20 onto every
  consumer's classpath.
- Remove the unused commons-io dependency.
- jackson 2.22.3, jersey 2.48, feign 13.15, slf4j 1.7.36, junit 4.13.2, and
  current Maven plugin versions. All remain Java 8 compatible; compile with
  --release 8 on JDK 9+.
- Resolved runtime classpath goes from 50+ known advisories (OSV) to none.

Tests:
- Add tests for client-core, client-feign and client-jaxrs, run against an
  in-process stub PDP shared through a client-core test-jar, including a
  400-call concurrency test that fails on the previous JAX-RS implementation.

Build metadata: point url/scm to the axiomatics repository, add license and
issue management, inherit module versions from the parent, and skip
deploying the example modules.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- ci.yml: build and test on Java 8, 11, 17, 21 and 25 for pushes to master
  and pull requests.
- codeql.yml: CodeQL (java-kotlin, security-extended) on pushes, pull
  requests and weekly.
- dependabot.yml: weekly grouped Maven and GitHub Actions updates; Jersey 3+
  (jakarta namespace, Java 11) and slf4j 2.x majors are ignored.
- release.yml: pushing a v<major>.<minor>.<patch> tag sets that version,
  publishes the SDK modules (with sources and javadoc) to GitHub Packages
  and creates a GitHub release with generated notes.
- Maven wrapper 3.3.4 pinned to Maven 3.9.16 with a checksum.
- README: thread-safety, build and release instructions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Compile with --release 17 (a single java.version.minimum property) and
  fail the build early on older JDKs with the enforcer plugin.
- CI matrix: 17, 21 and 25.
- README and comments updated; StubPdp uses InputStream.readAllBytes().

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Jersey 2.48 -> 3.1.12 (Jakarta REST 3.1 / Jakarta EE 10). JaxRsAuthZClient
  now uses the jakarta.ws.rs namespace: a breaking change for code that
  passes a WebTarget or Invocation.Builder to it.
- slf4j-api 1.7.36 -> 2.0.20. Applications need an slf4j 2.x provider
  (e.g. logback 1.3+ or slf4j-simple 2.x) to see the SDK's log output.
- Dependabot no longer ignores Jersey and slf4j major updates.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A null Invocation.Builder passed into the deprecated JaxRsAuthZClient(Invocation.Builder) constructor can still trigger a runtime NPE, and should be guarded with an explicit null check.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

This PR hardens the build/release/CI setup for the Java JSON PEP SDK while modernizing the codebase to Java 17+ and newer dependency versions (Jakarta/Jersey 3, updated Jackson/Feign/SLF4J), alongside improving client thread-safety guidance and adding regression tests.

Changes:

  • Upgrade baseline to Java 17 (enforced via Maven Enforcer) and introduce Maven Wrapper for reproducible builds.
  • Modernize dependencies and Jakarta namespace usage (Jersey 3.x, Jackson BOM import, Feign upgrades), plus tighten credential handling (mask passwords in toString() and validate username/password pairing).
  • Add CI/release automation (CI matrix, CodeQL, Dependabot, release workflow) and add client test utilities + new test suites.
File Description
README.md Adds thread-safety/closing guidance and build/release instructions.
pom.xml Java 17+ enforcement, BOM-based dependency management, plugin/version modernization, metadata cleanup.
mvnw.cmd Adds Maven Wrapper (Windows).
mvnw Adds Maven Wrapper (POSIX).
.mvn/​wrapper/​maven-wrapper.properties Pins wrapper and Maven distribution + SHA-256 checksum.
models/​pom.xml Removes old deps and aligns versions via parent/BOM; updates description text.
client-core/​pom.xml Publishes test-jar for shared test utilities.
client-core/​src/​main/​java/​io/​xacml/​pep/​json/​client/​DefaultClientConfiguration.java Masks passwords in toString(), improves error messages, deprecates pdpUrl(...).
client-core/​src/​test/​java/​io/​xacml/​pep/​json/​client/​StubPdp.java Adds in-process PDP stub for integration-style client tests.
client-core/​src/​test/​java/​io/​xacml/​pep/​json/​client/​ConcurrentCalls.java Adds concurrency runner for thread-safety tests.
client-core/​src/​test/​java/​io/​xacml/​pep/​json/​client/​DefaultClientConfigurationTest.java Adds tests for password masking and URL behavior.
client-jaxrs/​pom.xml Aligns module versions and pulls in shared test utilities.
client-jaxrs/​src/​main/​java/​io/​xacml/​pep/​json/​client/​jaxrs/​JaxRsAuthZClient.java Switches to Jakarta client types, improves thread-safety by rebuilding requests per call, adds close() for owned client.
client-jaxrs/​src/​test/​java/​io/​xacml/​pep/​json/​client/​jaxrs/​JaxRsAuthZClientTest.java Adds coverage for auth behavior, parsing, error handling, concurrency, and header overrides.
client-jaxrs-example/​pom.xml Skips deploy for examples; aligns module dependency version.
client-jaxrs-example/​src/​main/​java/​io/​xacml/​pep/​json/​client/​jaxrs/​AuthZClientExample.java Uses try-with-resources for JaxRsAuthZClient and documents lifecycle.
client-feign/​pom.xml Aligns module versions and pulls in shared test utilities.
client-feign/​src/​main/​java/​io/​xacml/​pep/​json/​client/​feign/​FeignAuthZClient.java Enforces username/password pairing for basic auth.
client-feign/​src/​main/​java/​io/​xacml/​pep/​json/​client/​feign/​PDPFeignClient.java Minor import cleanup.
client-feign/​src/​test/​java/​io/​xacml/​pep/​json/​client/​feign/​FeignAuthZClientTest.java Adds Feign client behavioral and concurrency tests.
client-feign-example/​pom.xml Skips deploy for examples; aligns module dependency version.
client-feign-example/​src/​main/​java/​io/​xacml/​pep/​json/​client/​feign/​AuthZClientExample.java Fixes incorrect example comment (Feign vs JAX-RS).
.github/​workflows/​ci.yml Adds CI workflow (Java 17/21/25 matrix).
.github/​workflows/​codeql.yml Adds CodeQL scanning workflow.
.github/​workflows/​release.yml Adds tag-driven release publishing + GitHub release creation.
.github/​dependabot.yml Adds Dependabot configuration for Maven + Actions updates.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

davidjbrossard and others added 2 commits September 25, 2026 11:03
Ensure requestInvocationBuilder is non-null in constructor.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
The previous commit's null-check edit removed the constructor's
original closing brace but left an extra one behind, breaking
compilation.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants