[OpenNMS/opennms] cf3680: NMS-19970: tolerate unknown properties when readin...

OpenNMS Machine User via opennms-cvs <[email protected]>
Newsgroups gmane.network.opennms.cvs
Message-ID <OpenNMS/opennms/push/refs/heads/merge-foundation/foundation-2023-to-foundation-2024/[email protected]>
  Branch: refs/heads/merge-foundation/foundation-2023-to-foundation-2024
  Home:   https://github.com/OpenNMS/opennms
  Commit: cf36809b500192470a111fec596e5daa34c59613
      https://github.com/OpenNMS/opennms/commit/cf36809b500192470a111fec596e5daa34c59613
  Author: Scott Theleman <[email protected]>
  Date:   2026-07-06 (Mon, 06 Jul 2026)

  Changed paths:
    M features/config/service/impl/src/main/java/org/opennms/features/config/service/util/ConfigConvertUtil.java
    A features/config/service/impl/src/test/java/org/opennms/features/config/service/util/ConfigConvertUtilTest.java

  Log Message:
  -----------
  NMS-19970: tolerate unknown properties when reading CM config JSON (#8620)

Ignore unknown properties so persisted config written by a newer version
(with fields not yet known to the running code) can still be read. Without
this, adding a field to a config class (e.g. Snmpv3User.id) breaks reading
that config on any older version during a downgrade, rollback, or rolling
upgrade.

Adds a regression test that reproduces the failure (ConfigConversionException
caused by Jackson's UnrecognizedPropertyException).


  Commit: 5cb9db511451d26fa102de6f54aa1cdca3e3c0e7
      https://github.com/OpenNMS/opennms/commit/5cb9db511451d26fa102de6f54aa1cdca3e3c0e7
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-13 (Mon, 13 Jul 2026)

  Changed paths:
    M opennms-config/src/main/java/org/opennms/netmgt/filter/JdbcFilterDao.java
    A opennms-config/src/test/java/org/opennms/netmgt/filter/JdbcFilterDaoToInetAddressTest.java

  Log Message:
  -----------
  NMS-20004: tolerate unrepresentable ipaddr values in filter results

A single ipinterface row whose ipaddr value cannot be converted to an
InetAddress aborted the whole filter evaluation with an opaque
UndeclaredThrowableException (null message): the result-row conversion
in JdbcFilterDao used InetAddress.getByName(), which throws for IPv6
zone ids naming an interface that does not resolve on this host, does
a DNS lookup per row for hostname-like values, and silently turns an
empty string into the loopback address. The default rule *.*.*.*
matches every interface, so one bad row could break every package
filter evaluation for pollerd, collectd, threshd, and notifd.

Convert result rows tolerantly instead: accept only IP literals (no
DNS resolution; numeric zone ids convert exactly as before), fall back
to the zone-stripped address for interface-name zones, and log-and-skip
anything that still cannot be represented rather than failing the
evaluation.


  Commit: 74a821c45e091cb5cbf9bbfb2c081d5e8f9265f5
      https://github.com/OpenNMS/opennms/commit/74a821c45e091cb5cbf9bbfb2c081d5e8f9265f5
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-13 (Mon, 13 Jul 2026)

  Changed paths:
    M opennms-config/src/main/java/org/opennms/netmgt/filter/JdbcFilterDao.java
    M opennms-config/src/test/java/org/opennms/netmgt/filter/JdbcFilterDaoToInetAddressTest.java

  Log Message:
  -----------
  NMS-20004: never resolve zone ids locally; reject zone suffixes on IPv4

Interface-name zones now always fall back to the zone-stripped address
instead of first attempting resolution against this host's interfaces,
which made results depend on the evaluating host's interface names.
Zone suffixes on IPv4 literals (never valid) are skipped outright
rather than reaching InetAddress.getByName with an unparseable value.


  Commit: 3a1519249350fc638a4e1e921b4f0c9fe339bbc4
      https://github.com/OpenNMS/opennms/commit/3a1519249350fc638a4e1e921b4f0c9fe339bbc4
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-14 (Tue, 14 Jul 2026)

  Changed paths:
    M opennms-config/src/main/java/org/opennms/netmgt/filter/JdbcFilterDao.java

  Log Message:
  -----------
  NMS-20004: use Guava InetAddresses for literal validation in filter results

Review feedback: replace the hand-rolled IPv4/IPv6 literal regexes with
InetAddresses.isInetAddress, which never resolves hostnames and validates
more precisely. It must run on the zone-stripped address part because
Guava 31.1 rejects scoped addresses; the zone handling is unchanged.


  Commit: 21f35cec1f1f3cc6b3b76bfe95d68926b58dd4d1
      https://github.com/OpenNMS/opennms/commit/21f35cec1f1f3cc6b3b76bfe95d68926b58dd4d1
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-14 (Tue, 14 Jul 2026)

  Changed paths:
    M opennms-config/src/main/java/org/opennms/netmgt/filter/JdbcFilterDao.java
    A opennms-config/src/test/java/org/opennms/netmgt/filter/JdbcFilterDaoToInetAddressTest.java

  Log Message:
  -----------
  Merge pull request #8627 from OpenNMS/NMS-20004-IPv6ZoneIDFix-smoke

NMS-20004: tolerate unrepresentable ipaddr values in filter results


  Commit: dff6d640765adbaa6a14978bbaba7453795ae109
      https://github.com/OpenNMS/opennms/commit/dff6d640765adbaa6a14978bbaba7453795ae109
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-15 (Wed, 15 Jul 2026)

  Changed paths:
    A core/mate/api/src/main/java/org/opennms/core/mate/api/LazyScope.java
    A core/mate/api/src/test/java/org/opennms/core/mate/api/LazyScopeTest.java
    M features/collection/thresholding/impl/src/main/java/org/opennms/netmgt/threshd/ThresholdEntity.java
    M features/collection/thresholding/impl/src/main/java/org/opennms/netmgt/threshd/ThresholdingSetImpl.java
    M features/collection/thresholding/impl/src/main/java/org/opennms/netmgt/threshd/ThresholdingVisitorImpl.java

  Log Message:
  -----------
  NMS-20007: Make thresholding metadata scope creation lazy and shared per collection set

Since NMS-16966, applyThresholds/passedThresholdFilters/evaluateAndCreateEvents
each eagerly built an entity scope (3 read-only DB transactions loading the
node, interface and service entity graphs) per collection resource and per
threshold entity, on every collection cycle - even when no threshold definition
contains a metadata expression. On interface-heavy systems this produces tens
of thousands of database transactions per second (SUPPORT-3261).

Two changes:

1. Introduce LazyScope, a memoizing Scope wrapper, and build thresholding
   scopes lazily. Interpolation only consults a scope when the input contains
   an actual ${} expression, so configurations without metadata expressions
   now perform zero database work in the thresholding path.

2. Share one scope across the whole collection set. The scope only depends on
   session-level state (node id, host address, service name), never on the
   individual resource, so ThresholdingVisitorImpl builds a single lazy scope
   per visit. Configurations that do use metadata expressions go from one
   scope build per resource per threshold entity to at most one per service
   per collection cycle.


  Commit: 93a247e775db32109fdb69979cf5cceaf20e89ff
      https://github.com/OpenNMS/opennms/commit/93a247e775db32109fdb69979cf5cceaf20e89ff
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-15 (Wed, 15 Jul 2026)

  Changed paths:
    M opennms-services/src/main/java/org/opennms/netmgt/collectd/CollectableService.java

  Log Message:
  -----------
  NMS-20008: Honor thresholding-enabled parameter in collectd

The thresholding-enabled service parameter was only honored by the poller
(LatencyStoringServiceMonitorAdaptor); collectd created a thresholding
session and ran threshold processing on every collection regardless of the
parameter, so setting thresholding-enabled=false in
collectd-configuration.xml silently did nothing (SUPPORT-3261).

CollectableService now skips thresholding session creation when the
parameter is explicitly set to false. Default remains enabled, preserving
existing behavior for configurations that do not set the parameter.


  Commit: e978b72035943c63d1d18fdc25b6e2a6909a3ef0
      https://github.com/OpenNMS/opennms/commit/e978b72035943c63d1d18fdc25b6e2a6909a3ef0
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-15 (Wed, 15 Jul 2026)

  Changed paths:
    M features/poller/client-rpc/src/main/java/org/opennms/netmgt/poller/client/rpc/PollerRequestBuilderImpl.java

  Log Message:
  -----------
  NMS-20009: Build poller metadata scope once per request instead of twice

execute() built the node/interface/service scope twice per poll - once for
the configured attributes and once for the monitor's runtime attributes -
at three read-only database transactions per build (SUPPORT-3261).
Memoize it on the request builder.


  Commit: 0c8a83a6e4dd0dd9c4b33fcddba9185a3d68104c
      https://github.com/OpenNMS/opennms/commit/0c8a83a6e4dd0dd9c4b33fcddba9185a3d68104c
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-15 (Wed, 15 Jul 2026)

  Changed paths:
    M core/mate/api/src/main/java/org/opennms/core/mate/api/LazyScope.java

  Log Message:
  -----------
  NMS-20007: Fail with a clear message if a lazy scope supplier returns null

Addresses Copilot review feedback: split the eager null check on the
supplier from the memoization, and name the failure when a supplier
produces a null scope at materialization time.


  Commit: f7c5ca73434b1768d57ae0d4ed979fb96e81b2f0
      https://github.com/OpenNMS/opennms/commit/f7c5ca73434b1768d57ae0d4ed979fb96e81b2f0
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-15 (Wed, 15 Jul 2026)

  Changed paths:
    M opennms-services/src/main/java/org/opennms/netmgt/collectd/CollectableService.java
    M opennms-services/src/test/java/org/opennms/netmgt/collectd/CollectableServiceTest.java

  Log Message:
  -----------
  NMS-20008: Add tests for thresholding-enabled handling, clarify default comment

Addresses Copilot review feedback: the comment now states that the poller's
default for the same parameter is false while collectd defaults to enabled,
and CollectableServiceTest verifies the thresholding session is not created
when thresholding-enabled=false and is created when the parameter is absent
or true.


  Commit: 0acd5f77d19f69515f23f8eb503ac2cf8c64222c
      https://github.com/OpenNMS/opennms/commit/0acd5f77d19f69515f23f8eb503ac2cf8c64222c
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-15 (Wed, 15 Jul 2026)

  Changed paths:
    M features/poller/client-rpc/src/main/java/org/opennms/netmgt/poller/client/rpc/PollerRequestBuilderImpl.java

  Log Message:
  -----------
  NMS-20009: Invalidate the memoized scope when its inputs change

Addresses Copilot review feedback: withService and withPatternVariables now
reset the cached scope, so a builder mutated after a getScope() call sees
fresh values, matching pre-memoization semantics. execute() still builds the
scope only once since nothing mutates between its two uses.


  Commit: ba59e8aedb4632a333ac8489de6d064b3f8146db
      https://github.com/OpenNMS/opennms/commit/ba59e8aedb4632a333ac8489de6d064b3f8146db
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-15 (Wed, 15 Jul 2026)

  Changed paths:
    M core/ipc/rpc/camel/src/main/java/org/opennms/core/rpc/camel/CamelRpcClientFactory.java
    R core/ipc/rpc/camel/src/test/java/org/opennms/core/rpc/camel/LocalRpcTimeoutTest.java

  Log Message:
  -----------
  NMS-20006: revert NMS-19951 local RPC TTL bound (PR #8604)

Reverts the change from PR #8604 (NMS-19951) that bounded local
(same-location) RPC execution with .orTimeout(TTL / default RPC
timeout). Local execution once again returns module.execute(request)
directly, and the LocalRpcTimeoutTest added by that PR is removed.

This restores the code in core/ipc/rpc/camel/CamelRpcClientFactory.java
byte-for-byte to its pre-PR state.


  Commit: 02936fa106accdb313266660f7b465fc14b91a17
      https://github.com/OpenNMS/opennms/commit/02936fa106accdb313266660f7b465fc14b91a17
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-15 (Wed, 15 Jul 2026)

  Changed paths:
    M opennms-services/src/main/java/org/opennms/netmgt/collectd/CollectableService.java
    M opennms-services/src/test/java/org/opennms/netmgt/collectd/CollectableServiceTest.java

  Log Message:
  -----------
  Merge pull request #8632 from OpenNMS/mm/NMS-20008-smoke

NMS-20008: thresholding-enabled parameter is ignored by collectd


  Commit: d7dd307d0cf8ebf050a4de878410ca71c8dd677c
      https://github.com/OpenNMS/opennms/commit/d7dd307d0cf8ebf050a4de878410ca71c8dd677c
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-16 (Thu, 16 Jul 2026)

  Changed paths:
    M core/ipc/rpc/camel/src/main/java/org/opennms/core/rpc/camel/CamelRpcClientFactory.java
    R core/ipc/rpc/camel/src/test/java/org/opennms/core/rpc/camel/LocalRpcTimeoutTest.java

  Log Message:
  -----------
  Merge pull request #8635 from OpenNMS/mm/NMS-20006-smoke

NMS-20006: revert NMS-19951 local RPC TTL bound (PR #8604)


  Commit: c56be3d4e4910c3d90655a2bf44711b8203b4df9
      https://github.com/OpenNMS/opennms/commit/c56be3d4e4910c3d90655a2bf44711b8203b4df9
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-16 (Thu, 16 Jul 2026)

  Changed paths:
    A core/mate/api/src/main/java/org/opennms/core/mate/api/LazyScope.java
    A core/mate/api/src/test/java/org/opennms/core/mate/api/LazyScopeTest.java
    M features/collection/thresholding/impl/src/main/java/org/opennms/netmgt/threshd/ThresholdEntity.java
    M features/collection/thresholding/impl/src/main/java/org/opennms/netmgt/threshd/ThresholdingSetImpl.java
    M features/collection/thresholding/impl/src/main/java/org/opennms/netmgt/threshd/ThresholdingVisitorImpl.java

  Log Message:
  -----------
  Merge pull request #8631 from OpenNMS/mm/NMS-20007-smoke

NMS-20007: Thresholding builds metadata scopes per resource and per threshold


  Commit: 9ce795e2e8f1f2e4f872cde8c95597aa80e69eae
      https://github.com/OpenNMS/opennms/commit/9ce795e2e8f1f2e4f872cde8c95597aa80e69eae
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-17 (Fri, 17 Jul 2026)

  Changed paths:
    M features/poller/client-rpc/src/main/java/org/opennms/netmgt/poller/client/rpc/PollerRequestBuilderImpl.java

  Log Message:
  -----------
  Merge pull request #8633 from OpenNMS/mm/NMS-20009-smoke

NMS-20009: Poller builds the metadata scope twice per poll


  Commit: 69ccc0290c07251b23abba908af362108a2326d5
      https://github.com/OpenNMS/opennms/commit/69ccc0290c07251b23abba908af362108a2326d5
  Author: Chandra Gorantla <[email protected]>
  Date:   2026-07-21 (Tue, 21 Jul 2026)

  Changed paths:
    M features/collection/client-rpc/src/main/resources/META-INF/opennms/applicationContext-rpc-collector.xml
    M features/collection/client-rpc/src/main/resources/OSGI-INF/blueprint/blueprint.xml
    A features/collection/client-rpc/src/test/java/org/opennms/netmgt/collection/client/rpc/CollectorExecutorLifecycleTest.java
    M features/poller/client-rpc/src/main/resources/META-INF/opennms/applicationContext-rpc-poller.xml
    M features/poller/client-rpc/src/main/resources/OSGI-INF/blueprint/blueprint.xml
    A features/poller/client-rpc/src/test/java/org/opennms/netmgt/poller/client/rpc/PollerExecutorLifecycleTest.java

  Log Message:
  -----------
  NMS-20046: Handle Poller/Collect RPC executor shutdown

Currently daemon shutdown is taking longer as orderly shutdown waits
for all the current jobs to execute properly. We need force shutdown
for RPCs as they have longer timeout


  Commit: 3219789618208820049415e6ba6d8bd8c0b12586
      https://github.com/OpenNMS/opennms/commit/3219789618208820049415e6ba6d8bd8c0b12586
  Author: Chandra Gorantla <[email protected]>
  Date:   2026-07-21 (Tue, 21 Jul 2026)

  Changed paths:
    M features/collection/client-rpc/src/main/resources/META-INF/opennms/applicationContext-rpc-collector.xml
    M features/collection/client-rpc/src/main/resources/OSGI-INF/blueprint/blueprint.xml
    R features/collection/client-rpc/src/test/java/org/opennms/netmgt/collection/client/rpc/CollectorExecutorLifecycleTest.java
    M features/poller/client-rpc/src/main/resources/META-INF/opennms/applicationContext-rpc-poller.xml
    M features/poller/client-rpc/src/main/resources/OSGI-INF/blueprint/blueprint.xml
    R features/poller/client-rpc/src/test/java/org/opennms/netmgt/poller/client/rpc/PollerExecutorLifecycleTest.java

  Log Message:
  -----------
  Revert "NMS-20046: Handle Poller/Collect RPC executor shutdown"

This reverts commit 69ccc0290c07251b23abba908af362108a2326d5.


  Commit: 8f35e86a6fa16f1a45ba33d151bace5414aebdf5
      https://github.com/OpenNMS/opennms/commit/8f35e86a6fa16f1a45ba33d151bace5414aebdf5
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-21 (Tue, 21 Jul 2026)

  Changed paths:
    M core/ipc/rpc/api/src/main/java/org/opennms/core/rpc/api/RpcExceptionUtils.java
    M core/ipc/rpc/camel/src/main/java/org/opennms/core/rpc/camel/CamelRpcClientFactory.java
    A core/ipc/rpc/camel/src/test/java/org/opennms/core/rpc/camel/LocalRpcTimeoutTest.java
    M docs/modules/reference/pages/configuration/ttl-rpc.adoc

  Log Message:
  -----------
  NMS-20006: bound local RPC execution to a fixed, configurable timeout

Local (same-location) RPC execution in CamelRpcClientFactory is bounded
again so a module future that never completes cannot wedge its caller
(the NMS-19951 goal), but the bound is no longer the request TTL: it is
a fixed timeout, 30 minutes by default, configurable via the
org.opennms.core.ipc.rpc.local.timeout system property (0 disables).
TTL values resolved from snmp-config, service parameters, or the
collection interval no longer affect local execution, so
slow-but-completing local operations cannot be failed by configuration
intended for the Minion path.

RpcExceptionUtils now maps java.util.concurrent.TimeoutException to
onTimedOut, so an expired local execution is reported as a timeout
(e.g. CollectionTimedOut) rather than as an unexpected exception.


  Commit: 5e25bc2b22dbf3425f931a9f631df7cbde0180fe
      https://github.com/OpenNMS/opennms/commit/5e25bc2b22dbf3425f931a9f631df7cbde0180fe
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-21 (Tue, 21 Jul 2026)

  Changed paths:
    M smoke-test/src/main/java/org/opennms/smoketest/selenium/AbstractOpenNMSSeleniumHelper.java

  Log Message:
  -----------
  NMS-20049: harden smoke test login against CSRF/session race

Deleting cookies while the previous test's page is still loaded lets a
background request (e.g. a Vaadin heartbeat) race the login.jsp load
and swap the session cookie after the form is rendered. The form's
CSRF token then no longer matches, j_spring_security_check rejects the
POST and forwards to accessDenied.jsp, which passes login()'s
post-login checks. skipPasswordGate() then blocks for the full
timeout and the test runs unauthenticated, showing up as unrelated
flaky failures (GraphMLTopologyIT, TopologyIT, NodeDetailPageIT).

login() now parks on about:blank after cookie deletion so nothing can
race the form render, retries up to three times if the POST lands on
accessDenied.jsp, and skipPasswordGate() returns immediately when not
on the gate page instead of waiting for a button that never appears.


  Commit: 23d61a501fc3ca7607a34e131406b031800988ba
      https://github.com/OpenNMS/opennms/commit/23d61a501fc3ca7607a34e131406b031800988ba
  Author: Christian Pape <[email protected]>
  Date:   2026-07-22 (Wed, 22 Jul 2026)

  Changed paths:
    M pom.xml

  Log Message:
  -----------
  NMS-19996: Bumped netty version


  Commit: dd6e40cceb81da19172ad358ee98a415ad843530
      https://github.com/OpenNMS/opennms/commit/dd6e40cceb81da19172ad358ee98a415ad843530
  Author: Christian Pape <[email protected]>
  Date:   2026-07-22 (Wed, 22 Jul 2026)

  Changed paths:
    M pom.xml

  Log Message:
  -----------
  NMS-20034: Bumped mina version


  Commit: ffb62839abb62b58293a48203bae68013059f0ea
      https://github.com/OpenNMS/opennms/commit/ffb62839abb62b58293a48203bae68013059f0ea
  Author: Christian Pape <[email protected]>
  Date:   2026-07-22 (Wed, 22 Jul 2026)

  Changed paths:
    M pom.xml

  Log Message:
  -----------
  NMS-19931: Bumped jackson-databind version


  Commit: 572db79e320b4841376b5eb58dc9b921a68aaac2
      https://github.com/OpenNMS/opennms/commit/572db79e320b4841376b5eb58dc9b921a68aaac2
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-22 (Wed, 22 Jul 2026)

  Changed paths:
    M core/ipc/rpc/api/src/main/java/org/opennms/core/rpc/api/RpcExceptionUtils.java
    M core/ipc/rpc/camel/src/main/java/org/opennms/core/rpc/camel/CamelRpcClientFactory.java
    A core/ipc/rpc/camel/src/test/java/org/opennms/core/rpc/camel/LocalRpcTimeoutTest.java
    M docs/modules/reference/pages/configuration/ttl-rpc.adoc

  Log Message:
  -----------
  Merge pull request #8641 from OpenNMS/mm/NMS-20006-smoke

NMS-20006: bound local RPC execution with a timeout decoupled from the TTL


  Commit: 32415ae77aadde9fb098d1c5f474431eabba495f
      https://github.com/OpenNMS/opennms/commit/32415ae77aadde9fb098d1c5f474431eabba495f
  Author: Christian Pape <[email protected]>
  Date:   2026-07-22 (Wed, 22 Jul 2026)

  Changed paths:
    M features/vaadin-surveillance-views/src/main/java/org/opennms/features/vaadin/surveillanceviews/ui/SurveillanceViewTable.java
    M opennms-webapp/src/main/java/org/opennms/web/controller/notification/NotificationFilterController.java
    M opennms-webapp/src/main/java/org/opennms/web/nodelabel/NodeLabelChangeServlet.java
    M opennms-webapp/src/main/webapp/WEB-INF/jsp/alarm/list.jsp
    M opennms-webapp/src/main/webapp/WEB-INF/jsp/notification/list.jsp
    M opennms-webapp/src/main/webapp/WEB-INF/jsp/outage/list.jsp
    M opennms-webapp/src/main/webapp/WEB-INF/templates/navbar.ftl
    M opennms-webapp/src/main/webapp/admin/nodelabel.jsp
    M opennms-webapp/src/main/webapp/element/node.jsp

  Log Message:
  -----------
  NMS-17875: Fixed XSS issues

(cherry picked from commit 627a2fbb7f29d978182877482d2801c7fba7e376)


  Commit: b6f6dde420a94c47288cef7596a7fd5f8fe9672e
      https://github.com/OpenNMS/opennms/commit/b6f6dde420a94c47288cef7596a7fd5f8fe9672e
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-22 (Wed, 22 Jul 2026)

  Changed paths:
    M smoke-test/src/main/java/org/opennms/smoketest/selenium/AbstractOpenNMSSeleniumHelper.java

  Log Message:
  -----------
  Merge pull request #8649 from OpenNMS/mm/NMS-20049-smoke

NMS-20049: harden smoke test login against CSRF/session race


  Commit: 1d59bcf917d84dd2c150e06a98cb65141f5626e2
      https://github.com/OpenNMS/opennms/commit/1d59bcf917d84dd2c150e06a98cb65141f5626e2
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-22 (Wed, 22 Jul 2026)

  Changed paths:
    M features/vaadin-surveillance-views/src/main/java/org/opennms/features/vaadin/surveillanceviews/ui/SurveillanceViewTable.java
    M opennms-webapp/src/main/java/org/opennms/web/controller/notification/NotificationFilterController.java
    M opennms-webapp/src/main/java/org/opennms/web/nodelabel/NodeLabelChangeServlet.java
    M opennms-webapp/src/main/webapp/WEB-INF/jsp/alarm/list.jsp
    M opennms-webapp/src/main/webapp/WEB-INF/jsp/notification/list.jsp
    M opennms-webapp/src/main/webapp/WEB-INF/jsp/outage/list.jsp
    M opennms-webapp/src/main/webapp/WEB-INF/templates/navbar.ftl
    M opennms-webapp/src/main/webapp/admin/nodelabel.jsp
    M opennms-webapp/src/main/webapp/element/node.jsp

  Log Message:
  -----------
  Merge pull request #8651 from OpenNMS/mm/NMS-17875-2023-smoke

NMS-17875: (Porting to F2023) Fixed XSS issues


  Commit: d7f5e3c385eabbd148b474a638a5e46e5aca1c6e
      https://github.com/OpenNMS/opennms/commit/d7f5e3c385eabbd148b474a638a5e46e5aca1c6e
  Author: CI/CD System <[email protected]>
  Date:   2026-07-22 (Wed, 22 Jul 2026)

  Changed paths:

  Log Message:
  -----------
  Merge remote-tracking branch 'origin/foundation-2023' into foundation-2024


Compare: https://github.com/OpenNMS/opennms/compare/ec2a3d85e3c1...d7f5e3c385ea

To unsubscribe from these emails, change your notification settings at https://github.com/OpenNMS/opennms/settings/notifications


_______________________________________________
Please read the OpenNMS Mailing List FAQ:
http://www.opennms.org/wiki/index.php?page=MailingListFaq
opennms-cvs mailing list

To *unsubscribe* or change your subscription options, see the bottom of this page:
https://lists.sourceforge.net/lists/listinfo/opennms-cvs
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.