View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  package org.apache.commons.beanutils2.bugs;
18  
19  import static org.junit.jupiter.api.Assertions.assertThrows;
20  
21  import org.apache.commons.beanutils2.AlphaBean;
22  import org.apache.commons.beanutils2.BeanUtilsBean;
23  import org.apache.commons.beanutils2.SuppressPropertiesBeanIntrospector;
24  import org.junit.jupiter.api.Test;
25  
26  /**
27   * Class loader vulnerability in DefaultResolver
28   *
29   * @see <a href="https://issues.apache.org/jira/browse/BEANUTILS-463">https://issues.apache.org/jira/browse/BEANUTILS-463</a>
30   */
31  public class Jira463Test {
32      /**
33       * Tests that with a specialized {@code BeanIntrospector} implementation the class property can be suppressed.
34       */
35      @Test
36      public void testSuppressClassProperty() throws Exception {
37          final BeanUtilsBean bub = new BeanUtilsBean();
38          bub.getPropertyUtils().addBeanIntrospector(SuppressPropertiesBeanIntrospector.SUPPRESS_CLASS);
39          final AlphaBean bean = new AlphaBean();
40          assertThrows(NoSuchMethodException.class, () -> bub.getProperty(bean, "class"));
41      }
42  }