Fix #6264: honor @JsonIgnoreProperties on @JsonAnySetter properties - #6265
Open
aysha-afrah26 wants to merge 1 commit into
Open
aysha-afrah26 wants to merge 1 commit into
aysha-afrah26 wants to merge 1 commit into
Conversation
… properties
Code Review ✅ Approved🟡 Medium risk · Any-setter deserialization now skips configured input keys, changing accepted data. Fixes OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Powered by Gitar — free for open source |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
@JsonIgnorePropertiesand@JsonIncludePropertieson aMap-valued property are honored in both directions today:MapDeserializer.createContextual()picks them up from the property and its read loops skip matching keys, andMapSerializerdoes the same on the way out. An@JsonAnySetternever goes through aMapDeserializer, becauseSettableAnyPropertyis handed one entry at a time by the bean deserializer, so nothing on that path ever looks at the annotation and every key the caller sent lands in the map. I ran into it while comparing the two directions for one POJO: the any-getter side does honor it (MapSerializerforMap-valued accessors,AnyGetterWriter.resolve()for node-valued ones since #6255), so the same name can be suppressed on write and still accepted on read, which is the awkward half for anyone using the annotation to keep a key out of the map.SettableAnyPropertynow builds the sameIgnorePropertiesUtil.Checkerduring resolution and the sinks that hand it a JSON name skip excluded ones withskipChildren(), which keeps the rule in one place instead of at each of the dozen any-setter call sites inBeanDeserializer/BuilderBasedDeserializer/ThrowableDeserializer. Only names actually listed change anything, so@JsonIgnoreProperties(ignoreUnknown = true)on an any-setter stays the no-op it is now, and a type with neither annotation keeps every key. Creator-parameter any-setters are untouched on purpose: neither annotation hasPARAMETERin its@Target, so there is nothing to read there.Targeted at
3.xrather than the maintained lines since it does start dropping input that used to be accepted, though the gap is the same inSettableAnyPropertyon 3.2, 3.1 and 2.x, so glad to retarget if you would prefer it further back.AI tooling (Claude) was used to help prepare this change.