Repository navigation
fix(security): bump Jackson to 2.21 LTS line - #161
Conversation
Remediates CVE-2026-59889 (JsonView authorization bypass) in jackson-databind. Targets the 2.21 LTS line rather than the latest 2.22.x release for long-term stability in this client library. jackson-annotations no longer publishes patch-level versions past 2.20, so it now has its own jackson-annotations-version property separate from the shared jackson-version used by jackson-core and jackson-databind.
Picks up the newly published lf-api-client-core 2.2.5, which includes the Jackson 2.21 LTS bump, keeping both packages on a consistent Jackson version.
CI overrides the checked-in pom.xml version via mvn versions:set using VERSION_PREFIX from main.yml, so bumping pom.xml's <version> directly had no effect on the published artifact. Reverted pom.xml to its 1.0.0 placeholder and bumped VERSION_PREFIX to 1.0.4 instead, matching the fix applied in lf-api-client-core-java (PR #89).
Default GITHUB_TOKEN permissions are read-only, so EnricoMi/publish-unit-test-result-action was failing with 403 Resource not accessible by integration when creating check runs (and would also fail posting its PR comment). Same fix already worked out on an earlier abandoned branch, carried over here.
startDeleteEntryCanDeleteFolder only waited for the task to leave IN_PROGRESS, which is also true when a task fails, then asserted getEntry throws 404. A failed delete (e.g. a required audit reason not set) would silently look identical to "not deleted yet" in the old assertion. Now asserts TaskStatus.COMPLETED first and prints the ProblemDetails on failure, matching the pattern already used in ImportUploadedPartsApiTest.
REPOSITORY_ID_1 requires an audit reason for DeleteEntry (ErrorCode 216: "Need to provide correct audit reason for DeleteEntry"), confirmed via the ProblemDetails now printed by startDeleteEntryCanDeleteFolder. Every StartDeleteEntryRequest in the suite was missing one, including BaseTest.deleteEntry(), the shared @afterall cleanup helper used by nearly every test class, which was silently failing and leaving orphaned test folders behind. Added findAuditReasonForDelete()/newDeleteEntryRequest() to BaseTest, mirroring the existing findAuditReasonForExport() pattern in ImportUploadedPartsApiTest, and switched all four delete call sites to use it.
bzajzon-laserfiche
left a comment
There was a problem hiding this comment.
Approving. The Jackson change is sound and the split property is well justified: pinning jackson-annotations separately at 2.21 while jackson-core/jackson-databind track 2.21.6 is the normal arrangement once annotations stops cutting patch releases, and the body explains why.
Two things I'd like reflected in the description rather than changed in the code, since a reader coming to this from the title will not expect them.
The PR does more than bump Jackson. Alongside the CVE fix it also bumps lf-api-client-core 2.2.4 → 2.2.5, bumps VERSION_PREFIX to 1.0.4, adds a permissions block to build-n-test, switches the integration-test repository, and reworks delete-entry test setup. The changelog covers the two dependency bumps; the rest is invisible unless you read the diff.
The test repository switch is the one worth calling out. DEV_CA_PUBLIC_USE_REPOSITORY_ID_2 → _1 changes which repository every integration test runs against, and the BaseTest changes look like the consequence — repository 1 appearing to require an audit reason on delete where 2 did not. If that is the reason, it belongs in the description, because it is the change most likely to confuse someone bisecting a future CI failure. Unrelated to the CVE either way.
Two things I liked. The explicit permissions block is a tightening, not a loosening, since the default would otherwise be broader. And asserting TaskStatus.COMPLETED with printProblemDetails on failure is a real improvement over waiting and inferring success from the entry being gone — the old shape would report a deletion that silently failed as a passing test.
One small note, not blocking: newDeleteEntryRequest() falls back to a request with no audit reason when none is found, which keeps this working on repositories that do not require one. That is the right default, but it does mean a misconfigured fixture surfaces as a delete failure later rather than at setup.
Remediates CVE-2026-59889 (JsonView authorization bypass) in jackson-databind. Targets the 2.21 LTS line rather than the latest 2.22.x release for long-term stability in this client library.
jackson-annotations no longer publishes patch-level versions past 2.20, so it now has its own jackson-annotations-version property separate from the shared jackson-version used by jackson-core and jackson-databind.