[PR] Replace ROME Propono AtomPub server with self-contained S tAX implementation [roller]

snoopdave (via GitHub) <[email protected]>
Newsgroups gmane.comp.java.roller.devel
Message-ID <[email protected]>
snoopdave opened a new pull request, #161:
URL: https://github.com/apache/roller/pull/161

   ## What
   
   Reimplements the **Atom Publishing Protocol (RFC 5023) server** using only **JDK StAX** (`javax.xml.stream`) and plain DTOs — **no ROME, no Propono**.
   
   ## Why
   
   The AtomPub server was built on ROME's `rome-propono`, which is only available up to ROME **1.19.0** (the last release that ships Propono). That pin held the *entire* ROME stack at 1.19.0 for the whole app, even though feed rendering doesn't use Propono. Dropping `rome-propono` frees ROME-for-feeds to be upgraded independently in a later, deliberate step.
   
   All Propono usage was confined to `webservices/atomprotocol/`; feeds and the Planet aggregator are untouched.
   
   ## Changes
   
   - **`RollerAtomServlet`** (new) replaces Propono's `AtomServlet` — method dispatch, `201 Created` + `Location`/`Content-Location`, and media streaming ported over. Wired in `web.xml`; `propono.properties` and `RollerAtomHandlerFactory` removed.
   - **New wire model** (`AtomEntry`, `AtomFeed`, `AtomContent`, `AtomLink`, `AtomPerson`, `AtomCategory`, plus the service-doc DTOs and `AtomMediaResource`) with StAX **`AtomWriter`** / **`AtomReader`**. `AtomReader` disables DTDs and external entities (**XXE-safe**).
   - **`RollerAtomHandler` / `RollerAtomService` / `EntryCollection` / `MediaCollection`** keep their Roller domain-mapping logic; only the ROME types they touched changed. Fixes a **latent BASIC-auth bug** that compared against the null instance field instead of the looked-up user's password.
   - **Auth:** keep **BASIC + OAuth**, drop **WSSE** (removes `WSSEUtilities` and the `wsse` choice from the admin config labels, en/ja/zh_CN).
   
   ## Design decisions
   
   - **XML:** JDK StAX only — no JDOM/JAXB. `javax.xml.stream` is not part of the javax→jakarta migration, so it's safe.
   - **Scope:** server only (the AtomPub server receives requests; there is no outbound HTTP in this path).
   
   ## Testing
   
   - **Unit tests** for the reader, writer, DTOs, and request wrapper.
   - **Integration test** (`RollerAtomProtocolTest`) driving the full create / retrieve / update / delete lifecycle plus service-doc and media upload against in-memory Derby.
   - **Schema-validation tests** (`AtomSchemaValidationTest`) that validate `AtomWriter` output against the RFC 4287 (Atom) and RFC 5023 (AtomPub) RELAX NG schemas using Jing.
   
   All 34 new tests pass (`mvn -pl app test -Dtest='...atomprotocol.*'`).
   
   > **Note:** the HTTP transport and BASIC auth *over the wire* need the Spring web context and aren't exercised by the JUnit reactor. Recommend confirming wire-format interop with an over-the-wire exerciser (e.g. APE) against a deployed instance, since the previous format was ROME-generated.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.