Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESBROADCOMVERIFIED

PUBLISHER UPDATE · SPRING-FRAMEWORK-7.1.0-M1

SPRING-FRAMEWORK-7.1.0-M1 release notes and known issues

v7.1.0-M1

Scope: Spring Framework. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

⚠️ Attention Required starting in Spring Framework 7.1, ForwardedHeaderFilter (Spring MVC) and ForwardedHeaderTransformer (WebFlux) each require a boolean argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property enables use of "X-Forwarded-Prefix" if needed. The default constructor with the existing behaviour of checking both types of headers is still available but deprecated and marked for removal. The new constructor makes forwarded header processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section, as well as related changes in Spring Boot spring-projects/spring-boot#51030 . #37072 Default context config is not detected when superclass or enclosing class is not annotated with @ContextConfiguration #31456 ⭐ New Features Add logging operators in DefaultExchangeFunction only when debug is enabled #37095 Consistently enforce non-null instance in AbstractFactoryBean #37091 Reinstate invalid resource location checks #37063 Preserve original bean names as aliases with FullyQualifiedConfigurationBeanNameGenerator #37038 Improve forwarded header parsing #36964 Avoid "NullAway.Init" suppression in favor of explicit field handling #36961 Refine and better specify error handling in MultipartParser #36947 Use double division to calculate applied jitter in ExponentialBackOff #36943 Throw ClassNotFoundException for missing class resource in ThrowawayClassLoader #36938 Replace isAssignableFrom() with isInstance() where feasible #36899 Simplify BUFFER_COUNT in ConcurrentLruCache to a constant #36872 Apply auto-grow collection limit to direct field binding #36862 Reject duplicate MIME type parameters #36841 Add DataSize converters to DefaultConversionService #36830 Only update ObservationThreadLocalAccessor when a test has an active ApplicationContext #36817 Deprecate setDisallowedFields in DataBinder for removal #36816 Optimize ClassNameReader.getClassName via direct ASM API #36814 AbortedException from client logged at ERROR level with WebFlux functional endpoint #36811 Add dedicated exception for HttpStatus.PRECONDITION_FAILED #36807 Reset mocks only when a test has an active ApplicationContext #36782 Improve MimeType parser for RFC compliance #36729 Reject unsafe static resource locations in MVC and WebFlux #36695 Use String#replace instead of String#replaceAll where appropriate #36678 Beans created with BeanRegistrar on GenericApplicationContext do not honor allow-bean-definition-overriding setting #36648 Use defensive Date copies for SimpleMailMessage sentDate #36626 Align StandardMethodMetadata with ASM/ClassFile support for getReturnTypeName() #36619 Use canonical names in error messages in annotation processing #36607 Provide bean conditional registration capabilities in BeanRegistrarDsl #36601 Align with JDK behavior by throwing TypeNotPresentException during annotation processing #36593 Deprecate RestTemplate and related types #36574 Remove deprecated methodIdentification() method in CacheAspectSupport #36560 Reject unbalanced parentheses in profile expressions #36550 Introduce ResolvableType.forParameter() factory method #36545 Remove redundant Assert.notNull() checks in ResolvableType #36544 Introduce support for custom parameter names in ParameterResolutionDelegate #36534 Perform case-insensitive lookup in HttpMethod.valueOf() #36518 Add "application/jsonl" support alongside "application/x-ndjson" for streaming #36485 Replace HandlerMappingIntrospector with PreFlightRequestHandler bean in MVC config #36481 GenericTypeResolver.resolveType should resolve TypeVariable with nested ParameterizedType #36480 Introduce classpath*: support for ResourceLoader#getResource with fully specified resource path #36415 Support for Map body types in FormHttpMessageConverter #36408 Support compilation of SpEL expressions that use Optional with null-safe and Elvis operators #36330 Skip Jaxb auto-detection in Http

Improvements and security content

  • ⚠️ Attention Required starting in Spring Framework 7.1, ForwardedHeaderFilter (Spring MVC) and ForwardedHeaderTransformer (WebFlux) each require a boolean argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property enables use of "X-Forwarded-Prefix" if needed. The default constructor with the existing behaviour of checking both types of headers is still available but deprecated and marked for removal. The new constructor makes forwarded header processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section, as well as related changes in Spring Boot spring-projects/spring-boot#51030 . #37072 Default context config is not detected when superclass or enclosing class is not annotated with @ContextConfiguration #31456 ⭐ New Features Add logging operators in DefaultExchangeFunction only when debug is enabled #37095 Consistently enforce non-null instance in AbstractFactoryBean #37091 Reinstate invalid resource location checks #37063 Preserve original bean names as aliases with FullyQualifiedConfigurationBeanNameGenerator #37038 Improve forwarded header parsing #36964 Avoid "NullAway.Init" suppression in favor of explicit field handling #36961 Refine and better specify error handling in MultipartParser #36947 Use double division to calculate applied jitter in ExponentialBackOff #36943 Throw ClassNotFoundException for missing class resource in ThrowawayClassLoader #36938 Replace isAssignableFrom() with isInstance() where feasible #36899 Simplify BUFFER_COUNT in ConcurrentLruCache to a constant #36872 Apply auto-grow collection limit to direct field binding #36862 Reject duplicate MIME type parameters #36841 Add DataSize converters to DefaultConversionService #36830 Only update ObservationThreadLocalAccessor when a test has an active ApplicationContext #36817 Deprecate setDisallowedFields in DataBinder for removal #36816 Optimize ClassNameReader.getClassName via direct ASM API #36814 AbortedException from client logged at ERROR level with WebFlux functional endpoint #36811 Add dedicated exception for HttpStatus.PRECONDITION_FAILED #36807 Reset mocks only when a test has an active ApplicationContext #36782 Improve MimeType parser for RFC compliance #36729 Reject unsafe static resource locations in MVC and WebFlux #36695 Use String#replace instead of String#replaceAll where appropriate #36678 Beans created with BeanRegistrar on GenericApplicationContext do not honor allow-bean-definition-overriding setting #36648 Use defensive Date copies for SimpleMailMessage sentDate #36626 Align StandardMethodMetadata with ASM/ClassFile support for getReturnTypeName() #36619 Use canonical names in error messages in annotation processing #36607 Provide bean conditional registration capabilities in BeanRegistrarDsl #36601 Align with JDK behavior by throwing TypeNotPresentException during annotation processing #36593 Deprecate RestTemplate and related types #36574 Remove deprecated methodIdentification() method in CacheAspectSupport #36560 Reject unbalanced parentheses in profile expressions #36550 Introduce ResolvableType.forParameter() factory method #36545 Remove redundant Assert.notNull() checks in ResolvableType #36544 Introduce support for custom parameter names in ParameterResolutionDelegate #36534 Perform case-insensitive lookup in HttpMethod.valueOf() #36518 Add "application/jsonl" support alongside "application/x-ndjson" for streaming #36485 Replace HandlerMappingIntrospector with PreFlightRequestHandler bean in MVC config #36481 GenericTypeResolver.resolveType should resolve TypeVariable with nested ParameterizedType #36480 Introduce classpath*: support for ResourceLoader#getResource with fully specified resource path #36415 Support for Map body types in FormHttpMessageConverter #36408 Support compilation of SpEL expressions that use Optional with null-safe and Elvis operators #36330 Skip Jaxb auto-detection in Http

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Spring Framework

Affected versions

  • 7.1.0-M1
  • 7.1

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Official publisher evidence