lukaszlenart commented on PR #1774: URL: https://github.com/apache/struts/pull/1774#issuecomment-4955031334
Thanks for the thorough follow-up — `0c93ea2fa` closes the completeness gaps I raised. I re-ran both suites locally against the PR head: - `ParameterAuthorizationContextTest` (core) — green - `ParameterAuthorizingModuleTest` (rest) — 23/23 green The `RedactionAwareDeserializer` + redaction-scope stack is a clean way to handle the construction-failure case: substituting a stand-in for a dropped creator-bound component and then treating a resulting construction failure as "drop the whole object" is consistent with how a rejected non-creator nested property already behaves. Good that `testValidatingRecord_genuineClientErrorStillPropagates` pins down the other side of it — a construction failure with nothing dropped still propagates, so genuine client/data errors aren't masked. Coverage across records, static-factory `@JsonCreator`, `@ConstructorProperties`, top-level records, 3-level nesting, and `List`/`Map` creator params is exactly the matrix I was after. Three small, non-blocking notes: 1. **Array-typed creator param.** `prefixForNested` handles `type.isArray()`, but only `List`/`Map` element paths are exercised in tests — an `Item[]` creator-param case would round out the collection matrix. 2. **`FAIL_ON_NULL_FOR_PRIMITIVES` off (the default).** With it disabled, a dropped primitive creator component silently becomes the type default (`0`/`false`) rather than dropping the object. That's fine — the point is the client value never lands — but worth a one-line comment so it reads as a deliberate choice rather than an oversight. 3. **Co-located failures.** If the same object both had a property dropped *and* hit an unrelated `JsonMappingException`, the current scope is marked, so the unrelated error is folded into "object dropped." Harmless in outcome, just slightly less informative to the caller — fine to leave, worth being aware of. None of these block. Nice work tightening it up. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
