close

Filter

loading table of contents...

Release Notes / Version 11.2310

Table Of Contents

CoreMedia Content Application Engine

Replaced invocations of deprecated and breaking Spring Security code

With the update to Spring Security 5.8, there're a number of deprecations whose invocations have been replaced:

  • Instead of extending the deprecated org.springframework.security.web.context.SaveContextOnUpdateOrErrorResponseWrapper, the com.coremedia.livecontext.hybrid.CookieLevelerFilter.HttpServletResponseCookieAware class now extends its super class org.springframework.security.web.util.OnCommittedResponseWrapper. The overrides of the abstract methods have been applied to reflect the same implementation.

  • Usages of the deprecated org.springframework.security.config.annotation.web.configurers.CsrfConfigurer#ignoringAntMatchers security builder
    methods have been replaced with org.springframework.security.config.annotation.web.configurers.CsrfConfigurer#ignoringRequestMatchers and org.springframework.security.web.util.matcher.AntPathRequestMatcher#antMatcher(String).

  • Usages of the deprecated org.springframework.security.config.annotation.web.builders.HttpSecurity#authorizeRequests security builder
    methods have been replaced with org.springframework.security.config.annotation.web.builders.HttpSecurity#authorizeHttpRequests (including chained access method calls).

  • Usages of the deprecated org.springframework.security.config.annotation.web.builders.HttpSecurity#requestMatcher security builder
    methods have been replaced with org.springframework.security.config.annotation.web.builders.HttpSecurity#securityMatcher.

  • Usages of the deprecated org.springframework.security.config.annotation.web.AbstractRequestMatcherRegistry#antMatchers security builder
    methods have been replaced with org.springframework.security.config.annotation.web.AbstractRequestMatcherRegistry#requestMatchers and org.springframework.security.web.util.matcher.AntPathRequestMatcher#antMatcher(String).

Follow Section, “Replaced invocations of deprecated and breaking Spring Security code” for upgrade information.

(CMS-22524)

Replaced deprecated WebSecurityConfigurerAdapter

For the default CAE:

Follow Section, “Replaced deprecated WebSecurityConfigurerAdapter” for upgrade information.

(CMS-22461)

P2TagFilter Deprecated and Replaced by ReservedClassToElementFilter

Class P2TagFilter had a bug with additional attributes (except class). With this change, processing of CoreMedia Rich Text to generate XHTML is no longer performed by P2TagFilter but ReservedClassToElementFilter. Blueprint's default rich text filter configuration has been adjusted accordingly. Class P2TagFilter is now deprecated.

Follow Section, “P2TagFilter Deprecated and Replaced by ReservedClassToElementFilter” for upgrade information.

(CMS-22251)

Removed UnknownMimetypeCharacterEncodingFilter

Removed class com.coremedia.blueprint.cae.filter.UnknownMimetypeCharacterEncodingFilter as it is not used with embedded tomcat.

(CMS-14235)

Updated Tomcat version to 9.0.71 and changed property names

Tomcat has been updated to version 9.0.71 (see Changelog Tomcat 9.0.71) to prevent known vulnerabilities.

Follow Section, “Updated Tomcat version to 9.0.71 and changed property names” for upgrade information.

(CMS-22521)

Guess mime-type from extension for local development resources in the CAE

For the local code resources it is assumed that guessing the mime-type based on the file extension is more robust than guessing based on file content.

Follow Section, “Guess mime-type from extension for local development resources in the CAE” for upgrade information.

(CMS-22433)

Search Results

Table Of Contents
warning

Your Internet Explorer is no longer supported.

Please use Mozilla Firefox, Google Chrome, or Microsoft Edge.