Repository navigation
PD-14452 Refactored notification item mapping and post-processing logic into NotificationMapperV2 and NotificationMapperV3, aligning with the existing mapper architectural pattern. - #7756
Conversation
…ic into NotificationMapperV2 and NotificationMapperV3, aligning with the existing mapper architectural pattern. Consolidated item mappings (Item <-> NotificationItemEntity), external identifier mappings, and JSON additionalInfo conversions into NotificationMapperV2 and NotificationMapperV3. Added @AfterMapping post-processing hooks in NotificationMapperV2 and NotificationMapperV3 to guarantee non-null Items containers and null-safe external identifier instances. Updated JpaJaxbNotificationAdapterImpl (v2 and v3) to delegate item mapping and notification post-processing to NotificationMapperV2 and NotificationMapperV3 via Spring component injection. Added comprehensive unit tests in NotificationMapperV2Test and NotificationMapperV3Test verifying bidirectional item mapping and Items initialization.
|
Semgrep found 1 🟠 High severity issue identified in your code: Risk: Affected versions of org.apache.httpcomponents.core5:httpcore5-h2 are vulnerable to Uncontrolled Resource Consumption. The HTTP/2 stream multiplexer initializes its HPACK decoder with the protocol initial SETTINGS_MAX_HEADER_LIST_SIZE of Integer.MAX_VALUE instead of the locally configured limit, so the configured maximum header list size is not enforced until the peer acknowledges the local SETTINGS frame. A remote peer can send an oversized compressed header block during that pre-acknowledgement window to force unbounded memory allocation and cause a denial of service. Both HTTP/2 clients and servers are affected, and the default configuration is vulnerable because the limit it specifies is ignored during that same window. Fix: Upgrade this library to at least version 5.4.3 at ORCID-Source/orcid-core/maven_dep_tree.txt:69. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41095, GHSA-v3jc-474w-2wm6, CVE-2026-54428 Semgrep found 1 🟠 High severity issue identified in your code: Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. Apache ActiveMQ fails to fully validate non-parenthesized composite discovery wrappers (e.g. Fix: Upgrade this library to at least version 6.2.6 at ORCID-Source/orcid-core/maven_dep_tree.txt:91. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33576, GHSA-v853-w46p-fv2h, CVE-2026-34197, CVE-2026-45505 Semgrep found 1 🟠 High severity issue identified in your code: Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default access policy that permits exec operations on ActiveMQ MBeans. An authenticated attacker can invoke BrokerService.addNetworkConnector(String) with a crafted discovery URI that abuses the VM transport brokerConfig parameter (via a masterslave:// URL) to load an attacker-controlled Spring XML application context, achieving arbitrary code execution through bean factory methods such as Runtime.exec(). Upgrade to 5.19.7 or 6.2.6. Fix: Upgrade this library to at least version 6.2.6 at ORCID-Source/orcid-core/maven_dep_tree.txt:91. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33577, GHSA-hg6c-8mvr-jqc9, CVE-2026-42588 Semgrep found 1 🟠 High severity issue identified in your code: Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Control of Generation of Code ('Code Injection') / Improper Input Validation. An authenticated attacker can bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via Fix: Upgrade this library to at least version 6.2.5 at ORCID-Source/orcid-core/maven_dep_tree.txt:91. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25410, GHSA-w3w2-mpp5-92gm, CVE-2026-40466 Semgrep found 1 🟠 High severity issue identified in your code: Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. An authenticated attacker can exploit this vulnerability by using the Apache ActiveMQ admin web console to construct a malicious broker name that bypasses name validation to include an xbean binding. The attacker can then use the DestinationView mbean to send a message that triggers a VM transport creation referencing the malicious broker name, causing Spring ResourceXmlApplicationContext to load a remote Spring XML application context. Because Spring instantiates all singleton beans before BrokerService validates the configuration, this leads to arbitrary code execution on the broker JVM through bean factory methods such as Runtime.exec(). Fix: Upgrade this library to at least version 6.2.5 at ORCID-Source/orcid-core/maven_dep_tree.txt:91. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25412, GHSA-mr6m-xj7v-3cv3, CVE-2026-41044 |
…tification items by ignoring id when mapping Item to NotificationItemEntity
…ID-Source into camelia-orcid/PD-14452
Consolidated item mappings (Item <-> NotificationItemEntity), external identifier mappings, and JSON additionalInfo conversions into NotificationMapperV2 and NotificationMapperV3.
Added @AfterMapping post-processing hooks in NotificationMapperV2 and NotificationMapperV3 to guarantee non-null Items containers and null-safe external identifier instances.
Updated JpaJaxbNotificationAdapterImpl (v2 and v3) to delegate item mapping and notification post-processing to NotificationMapperV2 and NotificationMapperV3 via Spring component injection.
Added unit tests in NotificationMapperV2Test and NotificationMapperV3Test verifying bidirectional item mapping and Items initialization.