Skip to content

fix: prevent leaking container validation annotations - #3322

Merged
bnasslahsen merged 1 commit into
springdoc:mainfrom
Mattias-Sehlstedt:leaking-container-validations
Sep 6, 2026
Merged

fix: prevent leaking container validation annotations#3322
bnasslahsen merged 1 commit into
springdoc:mainfrom
Mattias-Sehlstedt:leaking-container-validations

Conversation

@Mattias-Sehlstedt

Copy link
Copy Markdown
Contributor

Adds so that the method parameter annotations are read with methodParameter.getParameter().getAnnotatedType() so that it is considered when handling the schema at the resolver.

The issue before was that the annotation was entirely missing in the resolving stage, which lead to schema being cached with the annotation present (which is an issue since the key calculation does not consider any annotations). This in turn lead to the schema being re-resolved with constraints already present, which then meant that they would all share the constraint that was last applied to the object.

The new behavior matches how the constraint annotation application done in applyBeanValidatorAnnotations finds the annotations that it should apply to the schema.

Fixes: #3318

@bnasslahsen
bnasslahsen merged commit 1020566 into springdoc:main Sep 6, 2026
1 check passed
bnasslahsen added a commit that referenced this pull request Sep 6, 2026
Restore tabs and the java-first import order in the test controllers touched by
PR #3322, keep the 3.0.1 golden file in its existing indentation so the diff is
limited to the new /persons path, and restore the trailing newlines.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
bnasslahsen added a commit that referenced this pull request Sep 6, 2026
…al parameters

Constraints written on the type argument of an Optional parameter were dropped.
The merged form keeps the general handling introduced by PR #3322 - annotations
are read from every parameter's annotated type, not only from Optional ones -
and takes this pull request's guarded accessor, which returns null instead of
throwing when the method parameter has no index.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
bnasslahsen pushed a commit that referenced this pull request Sep 6, 2026
Annotations declared on a container's type argument were invisible when the
schema was first resolved, so the constraint was applied afterwards to a cached
schema shared by every parameter of that type. Reading them from the parameter's
annotated type at resolution time keeps each parameter's constraints its own.

Backport of PR #3322. The app267 test fixtures, introduced with PR #3259 and
never backported, come along so the regression stays covered on this line too.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@Mattias-Sehlstedt
Mattias-Sehlstedt deleted the leaking-container-validations branch September 6, 2026 09:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

@Pattern on @RequestParam List<@Pattern String> leaks to sibling array parameters (incomplete fix from #3259)

3 participants