Skip to content

Fix #6264: honor @JsonIgnoreProperties on @JsonAnySetter properties - #6265

Open
aysha-afrah26 wants to merge 1 commit into
FasterXML:3.xfrom
aysha-afrah26:anysetter-ignore-props
Open

aysha-afrah26 wants to merge 1 commit into
FasterXML:3.xfrom
aysha-afrah26:anysetter-ignore-props

Conversation

@aysha-afrah26

Copy link
Copy Markdown
Contributor

@JsonIgnoreProperties and @JsonIncludeProperties on a Map-valued property are honored in both directions today: MapDeserializer.createContextual() picks them up from the property and its read loops skip matching keys, and MapSerializer does the same on the way out. An @JsonAnySetter never goes through a MapDeserializer, because SettableAnyProperty is handed one entry at a time by the bean deserializer, so nothing on that path ever looks at the annotation and every key the caller sent lands in the map. I ran into it while comparing the two directions for one POJO: the any-getter side does honor it (MapSerializer for Map-valued accessors, AnyGetterWriter.resolve() for node-valued ones since #6255), so the same name can be suppressed on write and still accepted on read, which is the awkward half for anyone using the annotation to keep a key out of the map. SettableAnyProperty now builds the same IgnorePropertiesUtil.Checker during resolution and the sinks that hand it a JSON name skip excluded ones with skipChildren(), which keeps the rule in one place instead of at each of the dozen any-setter call sites in BeanDeserializer/BuilderBasedDeserializer/ThrowableDeserializer. Only names actually listed change anything, so @JsonIgnoreProperties(ignoreUnknown = true) on an any-setter stays the no-op it is now, and a type with neither annotation keeps every key. Creator-parameter any-setters are untouched on purpose: neither annotation has PARAMETER in its @Target, so there is nothing to read there.

Targeted at 3.x rather than the maintained lines since it does start dropping input that used to be accepted, though the gap is the same in SettableAnyProperty on 3.2, 3.1 and 2.x, so glad to retarget if you would prefer it further back.

AI tooling (Claude) was used to help prepare this change.

@gitar-bot

gitar-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown
Code Review ✅ Approved

🟡 Medium risk · Any-setter deserialization now skips configured input keys, changing accepted data.

Fixes @JsonIgnoreProperties and @JsonIncludeProperties annotations to be honored on @JsonAnySetter properties during deserialization, matching the behavior already in place for serialization. SettableAnyProperty now builds an IgnorePropertiesUtil.Checker and skips excluded keys, keeping the filtering logic centralized. No issues found.

Review coverage

📋 Rules No rules evaluated

🧪 Functional validation Not enabled · Set up

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Powered by Gitar — free for open source

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

🧪 Code Coverage Report

Metric Coverage Change
Instructions coverage 82.46% 📈 +0.000%
Branches branches 76.33% 📈 +0.010%

Coverage data generated from JaCoCo test results

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant