{
  "_class" : "org.jenkinsci.plugins.workflow.job.WorkflowRun",
  "actions" : [
    {
      "_class" : "hudson.model.CauseAction",
      "causes" : [
        {
          "_class" : "hudson.triggers.TimerTrigger$TimerTriggerCause",
          "shortDescription" : "Lancé par une alarme périodique"
        }
      ]
    },
    {
      "_class" : "hudson.model.ParametersAction",
      "parameters" : [
        {
          "_class" : "hudson.model.BooleanParameterValue",
          "name" : "SKIP_TEST",
          "value" : False
        },
        {
          "_class" : "hudson.model.BooleanParameterValue",
          "name" : "SKIP_QUALITY",
          "value" : False
        }
      ]
    },
    {
      "_class" : "org.jenkinsci.plugins.workflow.libs.LibrariesAction"
    },
    {
      
    },
    {
      "_class" : "org.jenkinsci.plugins.workflow.cps.EnvActionImpl"
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/master" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 1164,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
            "branch" : [
              {
                "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
                "name" : "refs/remotes/origin/master"
              }
            ]
          },
          "revision" : {
            "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
            "branch" : [
              {
                "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
                "name" : "refs/remotes/origin/master"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
        "branch" : [
          {
            "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
            "name" : "refs/remotes/origin/master"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Jenkins-Pipelines.git"
      ],
      "scmName" : ""
    },
    {
      
    },
    {
      
    },
    {
      
    },
    {
      
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/sonarqube" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 261,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "96a3a41e61a0a59a294dd74fce10884c559e77f4",
            "branch" : [
              {
                "SHA1" : "96a3a41e61a0a59a294dd74fce10884c559e77f4",
                "name" : "refs/remotes/origin/sonarqube"
              }
            ]
          },
          "revision" : {
            "SHA1" : "96a3a41e61a0a59a294dd74fce10884c559e77f4",
            "branch" : [
              {
                "SHA1" : "96a3a41e61a0a59a294dd74fce10884c559e77f4",
                "name" : "refs/remotes/origin/sonarqube"
              }
            ]
          }
        },
        "refs/remotes/origin/master" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 1164,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "3f5875d5832af01276050f9ad75a08f7ddb4dd30",
            "branch" : [
              {
                "SHA1" : "3f5875d5832af01276050f9ad75a08f7ddb4dd30",
                "name" : "refs/remotes/origin/master"
              }
            ]
          },
          "revision" : {
            "SHA1" : "3f5875d5832af01276050f9ad75a08f7ddb4dd30",
            "branch" : [
              {
                "SHA1" : "3f5875d5832af01276050f9ad75a08f7ddb4dd30",
                "name" : "refs/remotes/origin/master"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "3f5875d5832af01276050f9ad75a08f7ddb4dd30",
        "branch" : [
          {
            "SHA1" : "3f5875d5832af01276050f9ad75a08f7ddb4dd30",
            "name" : "refs/remotes/origin/master"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Core"
      ],
      "scmName" : ""
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/master" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 1164,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "eca5145d6d01f77adce83ef714742073585675ca",
            "branch" : [
              {
                "SHA1" : "eca5145d6d01f77adce83ef714742073585675ca",
                "name" : "refs/remotes/origin/master"
              }
            ]
          },
          "revision" : {
            "SHA1" : "eca5145d6d01f77adce83ef714742073585675ca",
            "branch" : [
              {
                "SHA1" : "eca5145d6d01f77adce83ef714742073585675ca",
                "name" : "refs/remotes/origin/master"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "eca5145d6d01f77adce83ef714742073585675ca",
        "branch" : [
          {
            "SHA1" : "eca5145d6d01f77adce83ef714742073585675ca",
            "name" : "refs/remotes/origin/master"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Components"
      ],
      "scmName" : ""
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/master" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 1164,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "3371d6a08cdacadc5573189be43a2d6beaff5437",
            "branch" : [
              {
                "SHA1" : "3371d6a08cdacadc5573189be43a2d6beaff5437",
                "name" : "refs/remotes/origin/master"
              }
            ]
          },
          "revision" : {
            "SHA1" : "3371d6a08cdacadc5573189be43a2d6beaff5437",
            "branch" : [
              {
                "SHA1" : "3371d6a08cdacadc5573189be43a2d6beaff5437",
                "name" : "refs/remotes/origin/master"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "3371d6a08cdacadc5573189be43a2d6beaff5437",
        "branch" : [
          {
            "SHA1" : "3371d6a08cdacadc5573189be43a2d6beaff5437",
            "name" : "refs/remotes/origin/master"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Looks"
      ],
      "scmName" : ""
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/master" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 1164,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "ba454f4f93b74cf8e576d2a33606dc23d5431702",
            "branch" : [
              {
                "SHA1" : "ba454f4f93b74cf8e576d2a33606dc23d5431702",
                "name" : "refs/remotes/origin/master"
              }
            ]
          },
          "revision" : {
            "SHA1" : "ba454f4f93b74cf8e576d2a33606dc23d5431702",
            "branch" : [
              {
                "SHA1" : "ba454f4f93b74cf8e576d2a33606dc23d5431702",
                "name" : "refs/remotes/origin/master"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "ba454f4f93b74cf8e576d2a33606dc23d5431702",
        "branch" : [
          {
            "SHA1" : "ba454f4f93b74cf8e576d2a33606dc23d5431702",
            "name" : "refs/remotes/origin/master"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Setup"
      ],
      "scmName" : ""
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/master" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 1164,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "0c4cdcb02f8e0a964f759187b9cfdfa8870d806b",
            "branch" : [
              {
                "SHA1" : "0c4cdcb02f8e0a964f759187b9cfdfa8870d806b",
                "name" : "refs/remotes/origin/master"
              }
            ]
          },
          "revision" : {
            "SHA1" : "0c4cdcb02f8e0a964f759187b9cfdfa8870d806b",
            "branch" : [
              {
                "SHA1" : "0c4cdcb02f8e0a964f759187b9cfdfa8870d806b",
                "name" : "refs/remotes/origin/master"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "0c4cdcb02f8e0a964f759187b9cfdfa8870d806b",
        "branch" : [
          {
            "SHA1" : "0c4cdcb02f8e0a964f759187b9cfdfa8870d806b",
            "name" : "refs/remotes/origin/master"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Distribution"
      ],
      "scmName" : ""
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/master" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 1164,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "7b2e624fce9db2e795b6e3d50485622b4024aa16",
            "branch" : [
              {
                "SHA1" : "7b2e624fce9db2e795b6e3d50485622b4024aa16",
                "name" : "refs/remotes/origin/master"
              }
            ]
          },
          "revision" : {
            "SHA1" : "7b2e624fce9db2e795b6e3d50485622b4024aa16",
            "branch" : [
              {
                "SHA1" : "7b2e624fce9db2e795b6e3d50485622b4024aa16",
                "name" : "refs/remotes/origin/master"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "7b2e624fce9db2e795b6e3d50485622b4024aa16",
        "branch" : [
          {
            "SHA1" : "7b2e624fce9db2e795b6e3d50485622b4024aa16",
            "name" : "refs/remotes/origin/master"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Assembly"
      ],
      "scmName" : ""
    },
    {
      
    },
    {
      "_class" : "hudson.plugins.sonar.action.SonarAnalysisAction",
      "ceTaskId" : "AaD0l2pebQNaPUmG7crv",
      "credentialsId" : None,
      "installationName" : "Silverpeas SonarCloud",
      "installationUrl" : "https://sonarcloud.io",
      "new" : True,
      "serverUrl" : "https://sonarcloud.io",
      "skipped" : False,
      "sonarqubeDashboardUrl" : "https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&branch=master"
    },
    {
      
    },
    {
      
    },
    {
      "_class" : "hudson.plugins.sonar.action.SonarAnalysisAction",
      "ceTaskId" : "AaD0uxyCkj6CGoBn7yyg",
      "credentialsId" : None,
      "installationName" : "Silverpeas SonarCloud",
      "installationUrl" : "https://sonarcloud.io",
      "new" : True,
      "serverUrl" : "https://sonarcloud.io",
      "skipped" : False,
      "sonarqubeDashboardUrl" : "https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Components&branch=master"
    },
    {
      
    },
    {
      
    },
    {
      
    },
    {
      
    },
    {
      
    },
    {
      
    },
    {
      "_class" : "hudson.plugins.sonar.action.SonarBuildBadgeAction",
      "url" : None
    },
    {
      
    },
    {
      "_class" : "org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction"
    },
    {
      "_class" : "org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction"
    },
    {
      
    },
    {
      "_class" : "org.jenkinsci.plugins.workflow.job.views.FlowGraphAction"
    },
    {
      
    },
    {
      
    }
  ],
  "artifacts" : [
    {
      "displayPath" : "build.yaml",
      "fileName" : "build.yaml",
      "relativePath" : "target/build.yaml"
    }
  ],
  "building" : False,
  "description" : None,
  "displayName" : "6.5-build260930",
  "duration" : 24065087,
  "estimatedDuration" : 10550775,
  "executor" : None,
  "fullDisplayName" : "Silverpeas_Master_AutoDeploy 6.5-build260930",
  "id" : "1164",
  "keepLog" : False,
  "number" : 1164,
  "queueId" : 63961,
  "result" : "SUCCESS",
  "timestamp" : 1790789040596,
  "url" : "https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1164/",
  "changeSets" : [
    {
      "_class" : "hudson.plugins.git.GitChangeSetList",
      "items" : [
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java",
            "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java",
            "core-restapi/src/site/resources/index.html",
            "core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java",
            "core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java",
            "core-restapi/pom.xml",
            "core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java",
            "core-rs/pom.xml",
            "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java",
            "core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java",
            "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java",
            "core-web/pom.xml",
            "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java",
            "pom.xml",
            "core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java",
            "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java"
          ],
          "commitId" : "ec9caee6b1242b8d5893ed5ece0884304d811cb0",
          "timestamp" : 1790597537000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Generate the documentation of the REST API with Swagger instead of Smart-Doc\u000a\u000aSmart-Doc parses the sources with QDox and chokes on constructs Silverpeas\u000arelies on, silently reporting a success while producing an incomplete\u000adocumentation. Swagger scans the compiled classes by reflection and understands\u000athe JAX-RS annotations, so the whole REST API is covered.\u000a\u000aThe new core-restapi module gathers the web resources of all the modules into a\u000asingle OpenAPI 3.1 document, rendered by Redoc and published on its own at\u000adocs/restapi/core. It produces nothing but that documentation and builds only\u000awith the restapi profile, from which the Smart-Doc plugin is dropped.\u000a\u000aAll the 217 operations, spread over 168 paths and 86 schemas, are now\u000adocumented: a summary, a success response with its schema, and the errors the\u000aendpoint can answer. The responses common to several endpoints are declared once\u000afor all:\u000a\u000a  * @Authenticated and @Authorized, besides the security schemes they already\u000a    described, bring the 401 and 403 responses of the protected resources;\u000a  * the 503 is brought by CommonResponsesFilter, applied once the specification\u000a    has been figured out. It cannot come from another meta-annotation of the web\u000a    resources: at class level Swagger returns the responses of the first\u000a    meta-annotation declaring some instead of merging them all, so a second one\u000a    would silently discard the responses of @Authenticated and @Authorized;\u000a  * the recurring 404, 400 and 409 are factored out into the @NotFound,\u000a    @BadRequest and @Conflict annotations of the new annotation.doc package.\u000a    Contrary to the class level one, the method level lookup of Swagger does\u000a    merge, but the description of such an annotation takes precedence over the\u000a    one an endpoint would declare for the same status code, hence an endpoint\u000a    needing another wording must not be annotated.\u000a\u000aDocumenting the endpoints brought several defects to light, which are fixed\u000ahere: the wrong descriptions of the personal space endpoints of SpaceResource, a\u000atest endpoint left over in CipherKeyResource, and the conflicting setters of\u000aAbstractI18NBean for the translations property, which made the scan fail.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:12:17 +0200",
          "id" : "ec9caee6b1242b8d5893ed5ece0884304d811cb0",
          "msg" : "Generate the documentation of the REST API with Swagger instead of Smart-Doc",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java"
            },
            {
              "editType" : "add",
              "file" : "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java"
            },
            {
              "editType" : "add",
              "file" : "core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java"
            },
            {
              "editType" : "edit",
              "file" : "pom.xml"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java"
            },
            {
              "editType" : "add",
              "file" : "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/pom.xml"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java"
            },
            {
              "editType" : "add",
              "file" : "core-restapi/src/site/resources/index.html"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java"
            },
            {
              "editType" : "add",
              "file" : "core-restapi/pom.xml"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java"
            },
            {
              "editType" : "add",
              "file" : "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-rs/pom.xml"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java",
            "core-restapi/pom.xml"
          ],
          "commitId" : "c097c5d943af83fb5ce284ad45b733a9d806b761",
          "timestamp" : 1790597537000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Make the schema resolver of Swagger aware of the JAXB annotations\u000a\u000aThe resolver figures the properties of a web entity out with a plain Jackson\u000aobject mapper, whereas Silverpeas serializes them with the introspector of the\u000aJAXB annotations. The generated schemas were therefore describing properties\u000athat never reach the wire and missing others that do:\u000a\u000a  * an entity whose access is set to XmlAccessType.FIELD was described by its\u000a    getters instead of its fields. SpaceAppearanceEntity came out with two\u000a    properties where six are serialized;\u000a  * a member annotated with @XmlTransient was described all the same.\u000a    PdcAxisValueEntity came out with eleven properties where nine are\u000a    serialized.\u000a\u000aThe JAXBAnnotationsHelper of Swagger is of no help here: it reads @XmlElement,\u000a@XmlElementWrapper and @XmlAttribute only, and only to feed the XML metadata of\u000aa schema, never its visibility. As for the Jackson module bringing that\u000aintrospector, it does declare itself to the ServiceLoader, but Swagger never\u000aasks for the modules available in the classpath.\u000a\u000aThe resolver declared here sets the introspector on a mapper of its own, the\u000avery way the JSON codec of Silverpeas does, so that it applies to the resolution\u000aof the schemas only. Ten business objects were documented that no endpoint ever\u000aanswers -- User, UserDetail, Domain, Quota, SettingBundle, PdcPosition and the\u000alike -- and they are gone now.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:12:17 +0200",
          "id" : "c097c5d943af83fb5ce284ad45b733a9d806b761",
          "msg" : "Make the schema resolver of Swagger aware of the JAXB annotations",
          "paths" : [
            {
              "editType" : "add",
              "file" : "core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java"
            },
            {
              "editType" : "edit",
              "file" : "core-restapi/pom.xml"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-restapi/src/main/openapi/openapi.yaml",
            "core-restapi/pom.xml",
            "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java",
            "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java",
            "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java"
          ],
          "commitId" : "692a545a5347eefc22d5e8f1949b6ce94151f274",
          "timestamp" : 1790597537000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Publish nothing but the documentation of the REST API\u000a\u000aThe generated specification declared no info section, which OpenAPI requires. A\u000arenderer refuses to display such a document, whatever the quality of the rest of\u000ait, and Redoc did. Contrary to the plugin of SmallRye, the one of Swagger has no\u000aparameter to fill that section in, hence the document of its own declared here:\u000athe scan completes it, and Maven fills its version in.\u000a\u000aBesides the documentation of the REST API, the module was publishing the site\u000aMaven builds for it: the reports about the dependencies, the SCM, the javadoc of\u000aa module that has almost no source. Those reports aren't produced any more, and\u000awhat the site brings along -- its decoration and its sitemap, of no use to the\u000arendering page -- is dropped once the site has been built, before it gets\u000apublished. The published tree is now made of the rendering page, the\u000aspecification in both of its formats, and the rendering engine.\u000a\u000aSkipping the site altogether looked simpler but isn't an option: the deploy goal\u000aof the site plugin reads the very same maven.site.skip property as its site\u000agoal, so the documentation would have silently stopped being published.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:12:17 +0200",
          "id" : "692a545a5347eefc22d5e8f1949b6ce94151f274",
          "msg" : "Publish nothing but the documentation of the REST API",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java"
            },
            {
              "editType" : "edit",
              "file" : "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java"
            },
            {
              "editType" : "add",
              "file" : "core-restapi/src/main/openapi/openapi.yaml"
            },
            {
              "editType" : "edit",
              "file" : "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java"
            },
            {
              "editType" : "edit",
              "file" : "core-restapi/pom.xml"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-restapi/pom.xml"
          ],
          "commitId" : "078323a23b15cb23bbbcaa797991a709645d0f7d",
          "timestamp" : 1790597537000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Take from the parent POM what doesn't depend on the project\u000a\u000aThe version of Redoc, swagger-core, the base document carrying the info section,\u000athe output of the generated specification and the binding of the resolve goal of\u000aSwagger, along with the execution stripping the Maven site, are now managed by\u000athe parent POM. The module keeps what is its own: the packages to scan, the\u000aroutes of the SCIM API not to publish, its filter and its schema resolver, the\u000aWAR whose classes are unpacked, and the URL the documentation is published at.\u000a\u000aIt also keeps the setting silencing the reports of the site plugin: that plugin\u000ais declared by the root POM of the project, so managing the setting in the\u000aparent would make every Maven site of Silverpeas lose its reports.\u000a\u000aThis takes effect once the parent POM is released: the project still refers to\u000athe last released one.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:12:17 +0200",
          "id" : "078323a23b15cb23bbbcaa797991a709645d0f7d",
          "msg" : "Take from the parent POM what doesn't depend on the project",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-restapi/pom.xml"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java",
            "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java",
            "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java",
            "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java",
            "core-web/pom.xml",
            "core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java",
            "core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java",
            "core-restapi/pom.xml",
            "core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java",
            "core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java",
            "core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java",
            "core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java",
            "core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java",
            "core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java",
            "core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java",
            "core-rs/pom.xml"
          ],
          "commitId" : "b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a",
          "timestamp" : 1790597537000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Gather in core-rs what generates the documentation of the REST API\u000a\u000aThe filter completing the responses of every endpoint and the resolver reading\u000athe JAXB annotations of the web entities were duplicated, one copy per project\u000adocumenting its REST API, the two being identical but for their package. They\u000aare gathered here, beside the annotations documenting the common errors, in a\u000apackage of their own: org.silverpeas.core.rs.doc.\u000a\u000aTheir name being the same for every project now, the parent POM declares them\u000aonce for all, and nothing is left to keep the copies in step.\u000a\u000aThe counterpart is that core-rs, a module of production, depends on swagger-core\u000ato compile them. The dependency is provided, so nothing of it is shipped, and\u000aneither the filter nor the resolver plays any role at runtime: both are read\u000awhen generating the documentation only.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:12:17 +0200",
          "id" : "b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a",
          "msg" : "Gather in core-rs what generates the documentation of the REST API",
          "paths" : [
            {
              "editType" : "add",
              "file" : "core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java"
            },
            {
              "editType" : "add",
              "file" : "core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java"
            },
            {
              "editType" : "delete",
              "file" : "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/pom.xml"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java"
            },
            {
              "editType" : "delete",
              "file" : "core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java"
            },
            {
              "editType" : "add",
              "file" : "core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java"
            },
            {
              "editType" : "delete",
              "file" : "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-restapi/pom.xml"
            },
            {
              "editType" : "delete",
              "file" : "core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java"
            },
            {
              "editType" : "add",
              "file" : "core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java"
            },
            {
              "editType" : "add",
              "file" : "core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java"
            },
            {
              "editType" : "delete",
              "file" : "core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java"
            },
            {
              "editType" : "edit",
              "file" : "core-rs/pom.xml"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-restapi/pom.xml"
          ],
          "commitId" : "d41b4c150a336e2cb3019a2b3687c5a403cba3d4",
          "timestamp" : 1790597537000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Opt in the stripping of the Maven site\u000a\u000aThe strip-maven-site execution of the parent POM is now skipped by default: it\u000aused to apply to every project inheriting from that POM and wiped out the Maven\u000asite such a project publishes. This module publishes the documentation of the\u000aREST API and nothing else, so it asks for the execution by setting\u000astrip.maven.site.skip to false.\u000a",
          "date" : "2026-09-28 14:12:17 +0200",
          "id" : "d41b4c150a336e2cb3019a2b3687c5a403cba3d4",
          "msg" : "Opt in the stripping of the Maven site",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-restapi/pom.xml"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java",
            "core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java",
            "core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java"
          ],
          "commitId" : "5f5891af886c501d82d72d54f15552e3775e0ce7",
          "timestamp" : 1790599348000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460\u000a\u000a(GitHub issues, reported against 6.4.6)\u000a\u000aThe three reported stored XSS rely on an event callback attribute carried by an\u000aelement the browser fails to load on purpose. Such a declaration was detected by\u000athe \\s+on\\w+\\s*= pattern, which expects a whitespace before the attribute name.\u000aAccording to the HTML tokenizer, an attribute name is also expected right after\u000athe closing quote of the previous attribute value (a\u000amissing-whitespace-between-attributes parse error, whose recovery is mandated by\u000athe specification) and right after a solidus. So the following did declare an\u000aonerror callback the browsers do run, while going through the filter:\u000a\u000a  <img src=\"x\"onerror=alert(1)>\u000a\u000aThe pattern now accepts these separators as well.\u000a\u000aNote this filter is an input guard, not an output encoding: it narrows the\u000areachability of the three flaws but it doesn't fix the rendering code itself.\u000a\u000aMassiveWebSecurityFilterOnReportedXssIT covers the payloads of the three reports\u000aon their actual endpoints and parameters, including when they are submitted as\u000amultipart/form-data streams as the genuine forms do. It also delimits the\u000amultipart exemption, which applies to the webPages component only.\u000a\u000aTestHttpRequest.getContentType() returned null whatever the headers set on the\u000astub, which made the multipart branch untestable.\u000a\u000aCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\u000a(cherry picked from commit 81589f6134e8e337c16a6c390b2d804e78006f8f)\u000a",
          "date" : "2026-09-28 14:42:28 +0200",
          "id" : "5f5891af886c501d82d72d54f15552e3775e0ce7",
          "msg" : "Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java"
            },
            {
              "editType" : "add",
              "file" : "core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-war/src/main/webapp/defaultLoginQuestion.jsp"
          ],
          "commitId" : "018ed026afbb76a9ad52281cd62b8e284b9a914a",
          "timestamp" : 1790599348000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1458\u000a\u000a(GitHub issue, reported against 6.4.6)\u000a\u000aThe login question, which any authenticated user sets from their profile, was\u000aprinted raw by a JSP scriptlet on the password reminder page, an anonymous one.\u000aAny script stored there was then run in the browser of every visitor of that\u000apage, without any login required from them. The answer to that question, itself\u000aa credential, is asked on the very same page.\u000a\u000aThe value is now HTML encoded on output, through a c:out tag. Doing so on the\u000arendering side rather than on the writing one closes both the ways the field is\u000afed: MyProfilRequestRouter, which the report points at, but also\u000aValidationQuestionHandler, which stores the question of the ValidateQuestion\u000afunction with no more filtering. It also neutralizes the values already stored.\u000a\u000aThe login of the hidden field below is encoded as well. It comes from a lookup\u000ain the database and not from the request parameter, so exploiting it would\u000arequire a login holding a quote, but the encoding costs nothing here.\u000a\u000aCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\u000a(cherry picked from commit 457be5fa780ce2656d7104f31515ea7064e2fbf6)\u000a",
          "date" : "2026-09-28 14:42:28 +0200",
          "id" : "018ed026afbb76a9ad52281cd62b8e284b9a914a",
          "msg" : "Fix vulnerability #1458",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-war/src/main/webapp/defaultLoginQuestion.jsp"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java",
            "core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java",
            "core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java",
            "core-configuration/src/main/config/properties/org/silverpeas/util/security.properties",
            "core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java",
            "core-library/src/integration-test/resources/org/silverpeas/util/security.properties",
            "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java",
            "core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java",
            "core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java",
            "core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java",
            "core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java",
            "core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java",
            "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java",
            "core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java"
          ],
          "commitId" : "37283d39cead2166ad9483d373658c2b8e414c95",
          "timestamp" : 1790599348000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1459\u000a\u000a(GitHub issue, reported against 6.4.6)\u000a\u000aThe WYSIWYG content of a form field was written into the response as raw HTML by\u000aWysiwygFCKFieldDisplayer, so any script stored by the writer of a whitePages\u000acard was run in the browser of every user viewing it. The same held for the\u000acontent of a publication, rendered by WysiwygContentRenderer, and for the two\u000aexport paths, none of which was reported.\u000a\u000aSuch a content is sanitized now, by the new SanitizeForRenderingDirective.\u000aUnlike SanitizeDirective, which keeps only a restricted set of safe elements and\u000ais left untouched for the contents extracted out of Silverpeas, this one keeps\u000athe content as it is and drops only what can act on the visitor's browser:\u000a\u000a- the elements able to run code or to take over the document, with their\u000a  content;\u000a- the event callback attributes, whatever the element carrying them;\u000a- the attributes referring a URL with a scripting scheme;\u000a- the iframes and the media whose source isn't allowed.\u000a\u000aThis is deliberate: the WYSIWYG editor is set up to accept any content\u000a(config.allowedContent = true in silverconfig.js), so an allow list applied at\u000arendering time would be narrower than what the users are entitled to write. It\u000awould in particular have dropped the media produced by the video and html5audio\u000aplugins and the rel attribute the userzoom and identitycard ones rely upon.\u000a\u000aThe parsing is delegated to the HTML tokenizer of the OWASP sanitizer, so the\u000acontent is read the way a browser reads it and the dropping can't be dodged by\u000aplaying with the HTML syntax.\u000a\u000aThe rule deciding whether the source of an iframe is allowed moves to the new\u000aEmbeddedSourceValidator class, so that the filtering of the incoming requests\u000aand this sanitization agree on it. It now serves the media as well, through the\u000anew security.external.media.hosts.allowed property. That property is shipped\u000awith the * value, which allows any host and hence preserves the behaviour of the\u000aprevious versions; setting it empty restricts the media to the ones Silverpeas\u000ahosts itself. The inlined images are kept whatever it is, being carried by the\u000acontent itself.\u000a\u000aThe mail path is deliberately left out: its images are referred by cid URLs,\u000awhich such a sanitization drops, and its content isn't rendered in the\u000aSilverpeas origin anyway.\u000a\u000aCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\u000a(cherry picked from commit 2961a40c81708375b2136cfa18f7c5f5e1d97321)\u000a",
          "date" : "2026-09-28 14:42:28 +0200",
          "id" : "37283d39cead2166ad9483d373658c2b8e414c95",
          "msg" : "Fix vulnerability #1459",
          "paths" : [
            {
              "editType" : "add",
              "file" : "core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java"
            },
            {
              "editType" : "add",
              "file" : "core-library/src/integration-test/resources/org/silverpeas/util/security.properties"
            },
            {
              "editType" : "edit",
              "file" : "core-configuration/src/main/config/properties/org/silverpeas/util/security.properties"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java"
            },
            {
              "editType" : "add",
              "file" : "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java"
            },
            {
              "editType" : "edit",
              "file" : "core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java"
            },
            {
              "editType" : "edit",
              "file" : "core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java"
            },
            {
              "editType" : "edit",
              "file" : "core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java"
          ],
          "commitId" : "b2900e3c4738e94ab34622ee8a48197f7921a09f",
          "timestamp" : 1790599348000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1461\u000a\u000a(GitHub issue, reported against 6.4.6)\u000a\u000aLet the callers of HttpUtil complete the HTTP client.\u000a\u000aFixing that vulnerability requires the gallery component to request the image of\u000aa watermark with a connection timeout and without following the redirections,\u000athe latter being able to escape the verification of the address being requested.\u000a\u000ahttpClientBuilder() gives the builder of the HTTP client, already configured\u000awith the proxy of Silverpeas, so that such a caller can complete the\u000aconfiguration without having to duplicate that of the proxy. httpClient() now\u000adelegates to it and is unchanged for its own callers.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a(cherry picked from commit 16cff5ecd5e217798d51ebe7f5a97103f4d901b0)\u000a",
          "date" : "2026-09-28 14:42:28 +0200",
          "id" : "b2900e3c4738e94ab34622ee8a48197f7921a09f",
          "msg" : "Fix vulnerability #1461",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js",
            "core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java",
            "core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java"
          ],
          "commitId" : "23acd94a451f35afaf18324777b344292593341b",
          "timestamp" : 1790599348000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741\u000a\u000aBoth report a stored XSS through the name of an uploaded file, one from the\u000adocument management and the other from the image upload of the WYSIWYG editor.\u000aThey share their cause: the name is written as an HTML content by the upload\u000awidget, whereas it is carried by the request and escaped on the sending side\u000aonly, which protects from nothing as a request can be forged.\u000a\u000aThe name is now set as a text. Note the formatted size which followed it was\u000aalready not displayed, html() taking a single argument, so the display is left\u000aunchanged.\u000a\u000aA scripting scheme given as the value of an attribute is detected as well by\u000aMassiveWebSecurityFilter. Such a declaration holds no on prefix and was\u000atherefore going through, and the colon introducing it is accepted written as\u000athe character itself or as any of the HTML entities standing for it, as the\u000areported payload uses \"javascript&colon;\". The data scheme is deliberately left\u000aout: the contents do embed their inlined images with it.\u000a\u000a(cherry picked from commit 4f92097f60d0d6e8072815cf5a77093d3f19f9e3)\u000a",
          "date" : "2026-09-28 14:42:28 +0200",
          "id" : "23acd94a451f35afaf18324777b344292593341b",
          "msg" : "Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java",
            "core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql",
            "core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java"
          ],
          "commitId" : "52843258f403c47fb8a0b51a75295f883fb98eda",
          "timestamp" : 1790599348000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Sort only the nodes of the component instance being administrated\u000a\u000aThe sorting of the nodes was granted against the component instance referred by\u000athe URL of the REST service, whereas the nodes to sort were taken from the\u000arequest body, each of them carrying the component instance it belongs to. An\u000aadministrator of any instance could hence ask to sort the nodes of another one.\u000a\u000aThe nodes are now identified within the instance of the URL, the one the\u000aauthorization has been checked against. Taking that instance from the body\u000abrought nothing: the sorting applies by nature to the instance administrated.\u000a\u000aThat wasn't enough though. NodeDAO was updating the order of a node by its\u000aidentifier only, whereas such an identifier isn't unique by itself: the root\u000anode of every component instance is numbered 0, and the ones below it can bear\u000athe same numbers from an instance to another. So the instance of the node is\u000anow part of the criteria. Beyond the authorization, this was a defect on its\u000aown: sorting the nodes of an instance was renumbering the nodes of the other\u000aones bearing the same identifiers, whoever asked for that sorting.\u000a\u000aNodeSortingIT covers the sorting of the nodes of an instance and the isolation\u000aof the other instances from it, in both directions.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a(cherry picked from commit e7028e01e7261c16803ee20f841763ef5b84ab7b)\u000a",
          "date" : "2026-09-28 14:42:28 +0200",
          "id" : "52843258f403c47fb8a0b51a75295f883fb98eda",
          "msg" : "Sort only the nodes of the component instance being administrated",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java"
            },
            {
              "editType" : "add",
              "file" : "core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java"
            },
            {
              "editType" : "add",
              "file" : "core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java",
            "core-war/src/main/webapp/defaultLoginQuestion.jsp"
          ],
          "commitId" : "df92a06600aedb5b24bad01559165e839421c2b5",
          "timestamp" : 1790599348000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Take into account sonarcloud feedback\u000a",
          "date" : "2026-09-28 14:42:28 +0200",
          "id" : "df92a06600aedb5b24bad01559165e839421c2b5",
          "msg" : "Take into account sonarcloud feedback",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java"
            },
            {
              "editType" : "edit",
              "file" : "core-war/src/main/webapp/defaultLoginQuestion.jsp"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-configuration/src/main/config/properties/org/silverpeas/util/security.properties"
          ],
          "commitId" : "db15a2e30508fb101a2addaf4780cc6479eb9270",
          "timestamp" : 1790599436000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@silverpeas.com",
          "comment" : "Now the parameter security.external.media.hosts.allowed is empty.\u000a\u000aThis means all hosts out of Silverpeas will be refused in HTML media\u000atags (video, iframe, img, ...)\u000a",
          "date" : "2026-09-28 14:43:56 +0200",
          "id" : "db15a2e30508fb101a2addaf4780cc6479eb9270",
          "msg" : "Now the parameter security.external.media.hosts.allowed is empty.",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-configuration/src/main/config/properties/org/silverpeas/util/security.properties"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java",
            "core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java",
            "core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java"
          ],
          "commitId" : "3f5875d5832af01276050f9ad75a08f7ddb4dd30",
          "timestamp" : 1790608429000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@silverpeas.com",
          "comment" : "Fix bug-15488\u000a",
          "date" : "2026-09-28 17:13:49 +0200",
          "id" : "3f5875d5832af01276050f9ad75a08f7ddb4dd30",
          "msg" : "Fix bug-15488",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java"
            }
          ]
        }
      ],
      "kind" : "git"
    },
    {
      "_class" : "hudson.plugins.git.GitChangeSetList",
      "items" : [
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java",
            "quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java",
            "quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java",
            "gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java",
            "quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java",
            "community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java",
            "questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java",
            "resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java",
            "gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java",
            "pom.xml",
            "delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java",
            "community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java",
            "components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java",
            "rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java",
            "questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java",
            "components-restapi/src/site/resources/index.html",
            "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java",
            "quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java",
            "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java",
            "quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java",
            "components-restapi/pom.xml"
          ],
          "commitId" : "f2fe8d93d99b4eb77e672c047d22ce154ba94673",
          "timestamp" : 1790597554000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Generate the documentation of the REST API with Swagger instead of Smart-Doc\u000a\u000aThe new components-restapi module gathers the web resources of the fourteen\u000aapplications into a single OpenAPI 3.1 document, rendered by Redoc and published\u000aon its own at docs/restapi/components. It produces nothing but that\u000adocumentation and builds only with the restapi profile, from which the Smart-Doc\u000aplugin is dropped.\u000a\u000aAll the 81 operations, spread over 70 paths and 81 schemas, are now documented.\u000aThe twenty-two operations of the almanach are inherited from the calendar\u000aresources of Core and needed nothing: Swagger reads the annotations of the\u000aoverridden methods. The others got a summary, a success response with its\u000aschema, and the errors they can answer, the recurring ones coming from the\u000a@NotFound and @Conflict annotations of Core. The 503 common to every endpoint is\u000abrought by CommonResponsesFilter, of which this project has its own copy.\u000a\u000aDocumenting the endpoints brought several defects to light, which are fixed\u000ahere:\u000a\u000a  * three of the four folder endpoints of Kmelia were invisible in the\u000a    documentation. Swagger strips the regular expression of a path template, so\u000a    {path: \\d+(/\\d+)*/children} was reduced to {path} and collided with the\u000a    three other ones. The literal suffix now sits outside the template, which\u000a    matches the very same URIs;\u000a  * NewsResource caught back the WebApplicationException it had just thrown and\u000a    turned it into a 503, so neither the 404 of an unknown news nor the refusal\u000a    to delete one ever reached the requester. That refusal answers a 403 now,\u000a    instead of a 401 without any challenge;\u000a  * MediaResolution read the settings of the application from its enum\u000a    constants, making the scan fail with an ExceptionInInitializerError. The\u000a    watermark size is read lazily now;\u000a  * five classes of Quickinfo were missing the licence header.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:12:34 +0200",
          "id" : "f2fe8d93d99b4eb77e672c047d22ce154ba94673",
          "msg" : "Generate the documentation of the REST API with Swagger instead of Smart-Doc",
          "paths" : [
            {
              "editType" : "add",
              "file" : "components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java"
            },
            {
              "editType" : "edit",
              "file" : "rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java"
            },
            {
              "editType" : "edit",
              "file" : "gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java"
            },
            {
              "editType" : "edit",
              "file" : "resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java"
            },
            {
              "editType" : "edit",
              "file" : "questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java"
            },
            {
              "editType" : "edit",
              "file" : "community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java"
            },
            {
              "editType" : "edit",
              "file" : "suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java"
            },
            {
              "editType" : "edit",
              "file" : "pom.xml"
            },
            {
              "editType" : "edit",
              "file" : "community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java"
            },
            {
              "editType" : "edit",
              "file" : "quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java"
            },
            {
              "editType" : "edit",
              "file" : "delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java"
            },
            {
              "editType" : "edit",
              "file" : "quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java"
            },
            {
              "editType" : "add",
              "file" : "components-restapi/pom.xml"
            },
            {
              "editType" : "edit",
              "file" : "questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java"
            },
            {
              "editType" : "edit",
              "file" : "quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java"
            },
            {
              "editType" : "add",
              "file" : "components-restapi/src/site/resources/index.html"
            },
            {
              "editType" : "edit",
              "file" : "quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java"
            },
            {
              "editType" : "edit",
              "file" : "gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java"
            },
            {
              "editType" : "edit",
              "file" : "quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java",
            "components-restapi/pom.xml"
          ],
          "commitId" : "59908ef73f929070700744af9c79e30cf0066fff",
          "timestamp" : 1790597554000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Make the schema resolver of Swagger aware of the JAXB annotations\u000a\u000aThe resolver figures the properties of a web entity out with a plain Jackson\u000aobject mapper, whereas Silverpeas serializes them with the introspector of the\u000aJAXB annotations. The generated schemas were therefore describing properties\u000athat never reach the wire, those excluded by @XmlTransient or by an access set\u000ato XmlAccessType.FIELD, and missing the fields that do reach it.\u000a\u000aSame resolver as the one of Core, of which this project has its own copy, for\u000athe very reason its filter completing the responses has one.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:12:34 +0200",
          "id" : "59908ef73f929070700744af9c79e30cf0066fff",
          "msg" : "Make the schema resolver of Swagger aware of the JAXB annotations",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "components-restapi/pom.xml"
            },
            {
              "editType" : "add",
              "file" : "components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "components-restapi/src/main/openapi/openapi.yaml",
            "components-restapi/pom.xml"
          ],
          "commitId" : "ae522b0fb3a88fbb36407023c62f0c096c2a3ab3",
          "timestamp" : 1790597554000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Publish nothing but the documentation of the REST API\u000a\u000aThe generated specification declared no info section, which OpenAPI requires. A\u000arenderer refuses to display such a document, whatever the quality of the rest of\u000ait. Contrary to the plugin of SmallRye, the one of Swagger has no parameter to\u000afill that section in, hence the document of its own declared here: the scan\u000acompletes it, and Maven fills its version in.\u000a\u000aBesides the documentation of the REST API, the module was publishing the site\u000aMaven builds for it: the reports about the dependencies, the SCM, the javadoc of\u000aa module that has almost no source. Those reports aren't produced any more, and\u000awhat the site brings along -- its decoration and its sitemap, of no use to the\u000arendering page -- is dropped once the site has been built, before it gets\u000apublished.\u000a\u000aSame setting as the one of Core, of which this project has its own copy, for the\u000avery reason its filter completing the responses has one.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:12:34 +0200",
          "id" : "ae522b0fb3a88fbb36407023c62f0c096c2a3ab3",
          "msg" : "Publish nothing but the documentation of the REST API",
          "paths" : [
            {
              "editType" : "add",
              "file" : "components-restapi/src/main/openapi/openapi.yaml"
            },
            {
              "editType" : "edit",
              "file" : "components-restapi/pom.xml"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "components-restapi/pom.xml"
          ],
          "commitId" : "01111927bc2afba8b8a88f23247f97c2e70eab18",
          "timestamp" : 1790597554000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Take from the parent POM what doesn't depend on the project\u000a\u000aThe version of Redoc, swagger-core, the base document carrying the info section,\u000athe output of the generated specification and the binding of the resolve goal of\u000aSwagger, along with the execution stripping the Maven site, are now managed by\u000athe parent POM. The module keeps what is its own: the packages to scan, its\u000afilter and its schema resolver, the fourteen WAR whose classes are unpacked, and\u000athe URL the documentation is published at.\u000a\u000aIt also keeps the setting silencing the reports of the site plugin: that plugin\u000ais declared by the root POM of the project, so managing the setting in the\u000aparent would make every Maven site of Silverpeas lose its reports.\u000a\u000aThis takes effect once the parent POM is released: the project still refers to\u000athe last released one.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:12:34 +0200",
          "id" : "01111927bc2afba8b8a88f23247f97c2e70eab18",
          "msg" : "Take from the parent POM what doesn't depend on the project",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "components-restapi/pom.xml"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java",
            "components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java",
            "quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java",
            "gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java",
            "community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java",
            "questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java",
            "resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java",
            "pom.xml",
            "delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java",
            "community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java",
            "components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java",
            "rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java",
            "questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java",
            "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java",
            "components-restapi/pom.xml"
          ],
          "commitId" : "021fe614496d0adf069aaade785f13438a7998ca",
          "timestamp" : 1790597554000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Take from core-rs what generates the documentation of the REST API\u000a\u000aThe filter completing the responses of every endpoint and the resolver reading\u000athe JAXB annotations of the web entities were copied here from Silverpeas Core,\u000awhere they now sit in a package of their own, org.silverpeas.core.rs.doc,\u000aalongside the annotations documenting the common errors. The copies are dropped\u000aand the parent POM declares the classes of core-rs instead.\u000a\u000aThe annotations documenting the common errors follow them: the endpoints of the\u000aapplications refer them at their new place.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:12:34 +0200",
          "id" : "021fe614496d0adf069aaade785f13438a7998ca",
          "msg" : "Take from core-rs what generates the documentation of the REST API",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java"
            },
            {
              "editType" : "edit",
              "file" : "resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java"
            },
            {
              "editType" : "edit",
              "file" : "rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java"
            },
            {
              "editType" : "edit",
              "file" : "community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java"
            },
            {
              "editType" : "edit",
              "file" : "community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java"
            },
            {
              "editType" : "edit",
              "file" : "pom.xml"
            },
            {
              "editType" : "edit",
              "file" : "delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java"
            },
            {
              "editType" : "edit",
              "file" : "components-restapi/pom.xml"
            },
            {
              "editType" : "delete",
              "file" : "components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java"
            },
            {
              "editType" : "edit",
              "file" : "questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java"
            },
            {
              "editType" : "edit",
              "file" : "quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java"
            },
            {
              "editType" : "edit",
              "file" : "suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java"
            },
            {
              "editType" : "delete",
              "file" : "components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java"
            },
            {
              "editType" : "edit",
              "file" : "gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "components-restapi/pom.xml"
          ],
          "commitId" : "9d3490bf7cd64723cdac38d15472d03679bb8950",
          "timestamp" : 1790597554000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Opt in the stripping of the Maven site\u000a\u000aThe strip-maven-site execution of the parent POM is now skipped by default: it\u000aused to apply to every project inheriting from that POM and wiped out the Maven\u000asite such a project publishes. This module publishes the documentation of the\u000aREST API and nothing else, so it asks for the execution by setting\u000astrip.maven.site.skip to false.\u000a",
          "date" : "2026-09-28 14:12:34 +0200",
          "id" : "9d3490bf7cd64723cdac38d15472d03679bb8950",
          "msg" : "Opt in the stripping of the Maven site",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "components-restapi/pom.xml"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp",
            "forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp",
            "forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp"
          ],
          "commitId" : "3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2",
          "timestamp" : 1790599402000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1460\u000a\u000a(GitHub issue of Silverpeas-Core, reported against 6.4.6)\u000a\u000aThe title and the body of a forum message were printed raw by JSP scriptlets on\u000athe thread page, so any script posted by a user of the forum was run in the\u000abrowser of every user reading it.\u000a\u000aThe title is now HTML encoded on output, as the other JSPs of the component\u000aalready do through WebEncodeHelper. Two other raw outputs of the title, which\u000athe report doesn't mention, are encoded as well: the one of modifyMessage.jsp,\u000awhere the title lands in the value attribute of an input and is hence\u000aexploitable by escaping that attribute, and the one of editMessageKeywords.jsp.\u000a\u000aThe body is sanitized by the applySanitizeForRenderingDirective directive\u000aintroduced in Silverpeas-Core for the vulnerability #1459, which drops what can\u000aact on the visitor's browser while keeping the content as it is.\u000a\u000aNote the report also states the title pollutes the title element of the page.\u000aIt does appear there, but viewMessage.jsp already prints it through a c:out tag,\u000aso it is encoded and isn't a vector.\u000a\u000aCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\u000a(cherry picked from commit ea479b045468c5015e93e8b6c0924b919f8e4f32)\u000a",
          "date" : "2026-09-28 14:43:22 +0200",
          "id" : "3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2",
          "msg" : "Fix vulnerability #1460",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp"
            },
            {
              "editType" : "edit",
              "file" : "forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp"
            },
            {
              "editType" : "edit",
              "file" : "forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java",
            "gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java"
          ],
          "commitId" : "b0d04438a605a666ee748f7c6ca310fef0ff6a4a",
          "timestamp" : 1790599402000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1461\u000a\u000a(GitHub issue of Silverpeas-Core, reported against 6.4.6)\u000a\u000aThe image of a watermark is an instance parameter any manager of the space\u000aholding the gallery can set, and the server requests it as it is, at each media\u000acreation. It could hence be pointed at a service the server keeps for itself.\u000a\u000aSuch an URL is now verified before being requested: only the HTTP and HTTPS\u000aschemes are handled, and the host must resolve to neither a loopback nor a\u000alink-local address, so that neither the services bound to the server itself nor\u000athe metadata endpoint of a cloud provider can be reached. Every address the host\u000aresolves to is verified, otherwise a host resolving to a forbidden address\u000abeside an allowed one would go through.\u000a\u000aThe addresses of the private networks of an organization remain reachable on\u000apurpose: they are where the internal resources of an intranet legitimately live,\u000aand no address range can tell them from the internal services one would rather\u000aprotect. Only an explicit list of allowed hosts could, which is left to a\u000afurther decision.\u000a\u000aThe request is besides given a timeout and its response is no longer copied\u000awithout any bound, both being able to exhaust the resources of the server, and\u000athe redirections are no longer followed as they would escape the verification\u000aabove.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a(cherry picked from commit 83864c0f72b6c5f62a1afdf2cb420f8b62840f20)\u000a",
          "date" : "2026-09-28 14:43:22 +0200",
          "id" : "b0d04438a605a666ee748f7c6ca310fef0ff6a4a",
          "msg" : "Fix vulnerability #1461",
          "paths" : [
            {
              "editType" : "add",
              "file" : "gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java"
            },
            {
              "editType" : "edit",
              "file" : "gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp",
            "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp",
            "infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java"
          ],
          "commitId" : "03b14dd2f030f634a99944c3272b31500811242f",
          "timestamp" : 1790599402000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1462 and secure the other writings of the newsletter\u000a\u000a(GitHub issue of Silverpeas-Core, reported against 6.4.6)\u000a\u000aPublishing an issue of a newsletter changes its state, stamps its publication\u000adate, notifies the subscribers and mails the external ones. It was requested by\u000aa GET, and the synchronizer token is required on a GET only when its URL holds\u000aone of a few keywords, which ValidateParution holds none of. Any logged user\u000alured into a cross-site visit was hence publishing the issue as themselves.\u000a\u000aThe publication is now submitted by POST, on which the token is required\u000awhatever the URL, through the formRequest facility which stamps it.\u000a\u000aMoreover the endpoint had no role check at all, so any reader of the newsletter\u000awas able to publish an issue and to trigger the mailing, with no luring needed.\u000aOnly its publishers and its managers can do so now.\u000a\u000aThree other writings, which the report doesn't mention, were exposed the same\u000away and are secured likewise:\u000a- resetting the content of an issue with its template, which overwrites the\u000a  content being written;\u000a- mailing an issue to oneself and to the managers, which sends the content of an\u000a  issue not published yet and was hence a way for any reader to get a draft.\u000a\u000aAs EditContent also serves the edition itself, a mere navigation which remains a\u000aGET, the reset is explicitly refused when it isn't requested by POST: submitting\u000ait by POST would otherwise protect nothing, the previous URL remaining\u000arequestable.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a(cherry picked from commit 4bd5e04d16207d889d2b271eed87fa1962fa8ab5)\u000a",
          "date" : "2026-09-28 14:43:22 +0200",
          "id" : "03b14dd2f030f634a99944c3272b31500811242f",
          "msg" : "Fix vulnerability #1462 and secure the other writings of the newsletter",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp"
            },
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp"
            },
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp",
            "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp",
            "infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java"
          ],
          "commitId" : "0b6076009ffb133c105e4861267e1cda62176d78",
          "timestamp" : 1790599402000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerabilities #1463\u000a\u000a(GitHub issue of Silverpeas-Core, reported against 6.4.6)\u000a\u000aThe operations on the issues themselves were exposed the same way and are\u000asecured likewise: creating and modifying an issue, and modifying the headers of\u000athe newsletter, were requestable by a GET although their forms are submitted by\u000aPOST, the router not caring about the method.\u000a\u000aNone of the operations of this router had any role check, so any reader was able\u000ato write the content of an issue, to modify the headers of the newsletter, to\u000adelete issues and to read the ones being written. They are now reserved to the\u000apublishers and to the managers, but for the ones on the template and the\u000adeletion of several issues at once, reserved to the managers.\u000a\u000aReading the inlined CSS rendering of an issue is how the readers get it from the\u000alist, so the criterion there isn't the role but the issue itself: it is refused\u000ato them as long as it isn't published.\u000a\u000a(cherry picked from commit e455edb9286b8b429cbb7fc1c54de6f75ead8dfd)\u000a",
          "date" : "2026-09-28 14:43:22 +0200",
          "id" : "0b6076009ffb133c105e4861267e1cda62176d78",
          "msg" : "Fix vulnerabilities #1463",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp"
            },
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp"
            },
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp",
            "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp",
            "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java",
            "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp",
            "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java"
          ],
          "commitId" : "dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc",
          "timestamp" : 1790599402000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1464\u000a\u000a(GitHub issue of Silverpeas-Core, reported against 6.4.6)\u000a\u000aLoading publications into the clipboard and pasting them under another topic\u000awere requestable by a GET, so any logged user lured into a cross-site visit was\u000amoving publications as themselves.\u000a\u000aThe AJAX servlet of kmelia answers the GET as the POST, and none of its URLs\u000aholds any of the keywords making the synchronizer token required on a GET. So\u000anone of its operations was protected, including the deletion of publications\u000awhich the report takes as protected: its URL does hold the delete keyword, but\u000athe rule applied to this servlet requires in addition the path to hold /jsp/,\u000awhich the path of a servlet doesn't.\u000a\u000aThe operations only reading something are now listed apart, every other one\u000abeing taken as writing something so that adding an operation doesn't expose it\u000aby mistake, and a writing operation requested by a GET is refused. That refusal\u000ais performed before the processing, whose catch-all would swallow it.\u000a\u000aThe user interface already submitted by POST the operations the report points\u000aat, as well as the deletion, the copy and the move of publications: what made\u000athe attack possible is the servlet accepting the GET. Three operations were\u000astill requested by a GET and are now submitted by POST: sorting the topics,\u000aemptying the trash from the basket, and binding a publication to another one.\u000a\u000a(cherry picked from commit 9d1faf9ba0366440299b0907b00a0ab5397f5bdd)\u000a",
          "date" : "2026-09-28 14:43:22 +0200",
          "id" : "dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc",
          "msg" : "Fix vulnerability #1464",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java",
            "kmelia/kmelia-war/pom.xml",
            "kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java"
          ],
          "commitId" : "f371b6452d9360af47926ebccceba45e05d252ca",
          "timestamp" : 1790599402000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #939\u000a\u000a(GitHub issue of Silverpeas-Components, reported against 6.4.6)\u000a\u000aUpdating a publication was granted against the component instance referred by\u000athe URL, whereas the publication to update was entirely defined by the request\u000abody, which carries both its identifier and its component instance. Any user\u000acould hence rewrite the metadata of any publication of the platform by referring\u000ait in the body, the identifiers being enumerable.\u000a\u000aThe publication is now refused when it doesn't belong to the instance the\u000aauthorization has been checked against. Note the report states a WRITER role is\u000arequired: it is not, the authorization of the REST framework only validating the\u000aaccess to the instance whatever the role played in it, so the exposure was wider\u000athan reported. Writing a publication, be it created or updated, now requires\u000athat role indeed.\u000a\u000aKmeliaResourceTest covers the checks. The war had no test at all, hence the\u000atest dependency added to its POM.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a(cherry picked from commit 1d8ec7ee0a903b041ffac54b022319ff099b12ce)\u000a",
          "date" : "2026-09-28 14:43:22 +0200",
          "id" : "f371b6452d9360af47926ebccceba45e05d252ca",
          "msg" : "Fix vulnerability #939",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/pom.xml"
            },
            {
              "editType" : "add",
              "file" : "kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java",
            "delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java"
          ],
          "commitId" : "bb7f36a57f96d33b8bd92d826056770e3c14e04c",
          "timestamp" : 1790599402000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Reserve the management of the delegated news to the managers\u000a\u000aModifying and deleting the delegated news is reserved to the managers of the\u000aapplication, as its user interface applies on its side. The REST service was\u000agranted against a mere access to the component instance, whatever the role\u000aplayed in it, so any of its users was able to reorder and to delete them by\u000arequesting it directly.\u000a\u000aFound while auditing the other REST resources against the flaw reported by the\u000aissue #939 of this repository.\u000a\u000aListDelegatedNewsResourceTest covers the check.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a(cherry picked from commit e4271c328772c51f400cbeab7eeb6f7fb2876721)\u000a",
          "date" : "2026-09-28 14:43:22 +0200",
          "id" : "bb7f36a57f96d33b8bd92d826056770e3c14e04c",
          "msg" : "Reserve the management of the delegated news to the managers",
          "paths" : [
            {
              "editType" : "add",
              "file" : "delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java"
            },
            {
              "editType" : "edit",
              "file" : "delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java",
            "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java"
          ],
          "commitId" : "eca5145d6d01f77adce83ef714742073585675ca",
          "timestamp" : 1790599402000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Take into account sonarcloud feedback\u000a",
          "date" : "2026-09-28 14:43:22 +0200",
          "id" : "eca5145d6d01f77adce83ef714742073585675ca",
          "msg" : "Take into account sonarcloud feedback",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java"
            }
          ]
        }
      ],
      "kind" : "git"
    }
  ],
  "culprits" : [
    {
      "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
      "fullName" : "Miguel Moquillon"
    }
  ],
  "inProgress" : False,
  "nextBuild" : None,
  "previousBuild" : {
    "number" : 1163,
    "url" : "https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1163/"
  }
}