Skip to content

Move runnable examples to turismo-bootstrap - #49

Merged
ghosthack merged 1 commit into
masterfrom
claude/zealous-shannon-nocart
Sep 24, 2026
Merged

ghosthack merged 1 commit into
masterfrom
claude/zealous-shannon-nocart

Conversation

@ghosthack

Copy link
Copy Markdown
Owner

Fixes code scanning alert java/xss (#4, reported at StringPrinter.java:40).

Why

All four of the alert's flows started in the demo routes under src/test/.../example/, which echoed request data straight into the response: the q parameter in three /search routes, and path params in ExampleAppRoutesList. print() itself is a raw writer by design (the framework can't know the response content type), so the fix belongs in the example code.

Rather than harden demos that ship to nobody, they now live in the separate starter project ghosthack/turismo-bootstrap, with output escaping, an HTTP test, and docs on escaping.

Changes

  • Remove src/test/java/.../example/ and src/test/webapp/ (web.xml and the JSP).
  • ServletTest loaded example.AppRoutes by class name; it now uses its own servlet/TestRoutes.
  • Drop the jetty-ee10-servlet / jetty-ee10-webapp test dependencies and the jetty.version property. Only the examples used them.
  • README: the Quick start now links to turismo-bootstrap.

Verification

  • mvn -B verify: 123 tests, 0 failures.
  • CodeQL 2.27.1 java/xss query run locally: 0 results (1 result with 4 flows before).

🤖 Generated with Claude Code

https://claude.ai/code/session_01K3srgwegxijKeNJuJyGifT


Generated by Claude Code

Fixes code scanning alert java/xss (#4), whose flows all started in the
example routes echoing request parameters into the response. The
examples now live, with output escaping, in the separate
turismo-bootstrap starter project, and the README links to it.

ServletTest loaded example.AppRoutes by name, so it gets its own
TestRoutes class. Jetty was only used by the examples, so its test
dependencies are dropped.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01K3srgwegxijKeNJuJyGifT
@ghosthack
ghosthack merged commit 5ab1300 into master Sep 24, 2026
8 checks passed
@ghosthack
ghosthack deleted the claude/zealous-shannon-nocart branch September 24, 2026 12:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants