Repository navigation
Four tests failing with "UnsupportedOperation This method has been removed for security." #893
Description
Activity
#721 is related.
This happens when you use something later than Java 8 to run the tests. For instance, if you run the tests with OpenJDK 8, they all pass. If you were to use OpenJDK 11, you get the failures that you mentioned. I looked at this back when #721 was first reported and concluded that it's failing because in (at least) Java 11 and later, Java's
Properties.storemethod has apparently been removed:... [ERROR] Tests run: 3, Failures: 0, Errors: 3, Skipped: 0, Time elapsed: 0.005 s <<< FAILURE! -- in org.owasp.esapi.reference.crypto.EncryptedPropertiesUtilsTest [ERROR] org.owasp.esapi.reference.crypto.EncryptedPropertiesUtilsTest.testLoadPlaintextAndEncrypt -- Time elapsed: 0.002 s <<< ERROR! java.lang.UnsupportedOperationException: This method has been removed for security. at org.owasp.esapi.reference.crypto.ReferenceEncryptedProperties.entrySet(ReferenceEncryptedProperties.java:244) at java.base/java.util.Properties.store0(Properties.java:938) at java.base/java.util.Properties.store(Properties.java:924) at org.owasp.esapi.reference.crypto.EncryptedPropertiesUtils.storeProperties(EncryptedPropertiesUtils.java:189) at org.owasp.esapi.reference.crypto.EncryptedPropertiesUtilsTest.testLoadPlaintextAndEncrypt(EncryptedPropertiesUtilsTest.java:131) at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.base/java.lang.reflect.Method.invoke(Method.java:566) ...
Which seems odd since Oracle's Javadoc for Properties.store(OutputStream,String) still shows it and it isn't even deprecated there.
Until then, we run our unit tests using Java 8 (where there is no problem) since that is the minimally supported JDK that ESAPI has said we would support. (At some point soon, in the not too distant future--although no date has been set--we will move the minimal JDK to whatever is the oldest LTS JDK version.).
The root cause though may go deeper than that. On the surface at least, it appears it may be related to what is described in this 'Fixing "UnsupportedOperationException": A Comprehensive Guide with Examples' article. I also noticed that there is a note in
java.util.Dictionary, which is a superclass ofjava.util.Hashtable, from whichjava.util.Propertiesis derived, has this note:
"NOTE: This class is obsolete. New implementations should implement the Map interface, rather than extending this class."Regardless, I suppose that it bears further investigation and that we should either rewrite some of those methods or deprecate them. However, I still think between that notice in
java.utils.Dictionaryand this behavior, they would either deprecate theProperties.storemethods or rewrite it to fix this.
I have been looking at 2.4.0.0 that we us in our old product and I have tried running tests. Four tests are failing:
The exception for one of the tests is always about
entrySet:The
entrySetis overridden inorg.owasp.esapi.reference.crypto.ReferenceEncryptedPropertiesbut theProperties.store()is using it.Should the tests be removed if they are expected to fail?