Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

- The MCP dashboard no longer pre-fills the OAuth2 token endpoint, client id and client secret. The form shows hints instead, and warns when the token endpoint is not HTTPS

### Fixed

- #3377 – JSpecify `@Nullable` on a controller method parameter is not reflected as nullable in the parameter schema

## [3.1.1] - 2026-09-06

### Security
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -449,14 +449,15 @@ private TypeAndTypeAnnotations resolveTypeAndTypeAnnotationsForParameter(MethodP
}

List<Annotation> typeAnnotations = Stream.concat(
Arrays.stream(annotationsFromAnnotatedTypeArguments(getParameterAnnotatedType(methodParameter))),
Arrays.stream(annotationsFromAnnotatedType(getParameterAnnotatedType(methodParameter))),
Arrays.stream(methodParameter.getParameterType().getAnnotations())).toList();
return new TypeAndTypeAnnotations(type, typeAnnotations);
}

/**
* Resolves the {@link AnnotatedType} of a method parameter so that annotations declared on its
* generic type arguments (for example inside a {@link List} or an {@link Optional}) can be inspected.
* Resolves the {@link AnnotatedType} of a method parameter so that annotations declared on the
* type itself (for example a JSpecify {@code @Nullable}) or on its generic type arguments (for
* example inside a {@link List} or an {@link Optional}) can be inspected.
*
* @param methodParameter the method parameter
* @return the annotated type, or {@code null} if it cannot be resolved
Expand All @@ -481,10 +482,13 @@ private record TypeAndTypeAnnotations(Type type, List<Annotation> typeAnnotation
* Collects annotations declared on the type itself and on each type argument of an
* {@link AnnotatedParameterizedType}.
*
* @param annotatedType the annotated type
* @param annotatedType the annotated type, possibly {@code null}
* @return a new array, possibly empty
*/
private static Annotation[] annotationsFromAnnotatedType(AnnotatedType annotatedType) {
if (annotatedType == null) {
return new Annotation[0];
}
return Stream.concat(
Arrays.stream(annotatedType.getAnnotations()),
Arrays.stream(annotationsFromAnnotatedTypeArguments(annotatedType))).toArray(Annotation[]::new);
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
/*
*
* *
* * *
* * * *
* * * * * Copyright 2019-2026 the original author or authors.
* * * * *
* * * * * Licensed under the Apache License, Version 2.0 (the "License");
* * * * * you may not use this file except in compliance with the License.
* * * * * You may obtain a copy of the License at
* * * * *
* * * * * https://www.apache.org/licenses/LICENSE-2.0
* * * * *
* * * * * Unless required by applicable law or agreed to in writing, software
* * * * * distributed under the License is distributed on an "AS IS" BASIS,
* * * * * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* * * * * See the License for the specific language governing permissions and
* * * * * limitations under the License.
* * * *
* * *
* *
*
*/
package test.org.springdoc.api.v30.app274;

import org.jspecify.annotations.Nullable;

import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PathVariable;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;

/**
* Declares request parameters whose nullability is expressed with the JSpecify {@link Nullable}
* annotation, which only targets type uses, and a path variable carrying the same annotation,
* which must never be described as nullable.
*
* @author sharanggupta
*/
@RestController
public class HelloController {

@GetMapping("/api/items")
String items(@RequestParam @Nullable String filter, @RequestParam @Nullable Integer limit) {
return null;
}

@GetMapping("/api/items/{id}")
String item(@PathVariable @Nullable String id) {
return null;
}

}
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
/*
*
* *
* * *
* * * *
* * * * * Copyright 2019-2026 the original author or authors.
* * * * *
* * * * * Licensed under the Apache License, Version 2.0 (the "License");
* * * * * you may not use this file except in compliance with the License.
* * * * * You may obtain a copy of the License at
* * * * *
* * * * * https://www.apache.org/licenses/LICENSE-2.0
* * * * *
* * * * * Unless required by applicable law or agreed to in writing, software
* * * * * distributed under the License is distributed on an "AS IS" BASIS,
* * * * * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* * * * * See the License for the specific language governing permissions and
* * * * * limitations under the License.
* * * *
* * *
* *
*
*/
package test.org.springdoc.api.v30.app274;

import test.org.springdoc.api.v30.AbstractSpringDocV30Test;

import org.springframework.boot.autoconfigure.SpringBootApplication;

/**
* Regression: a JSpecify {@code @Nullable} declared on a controller parameter must make the
* generated parameter schema nullable, as it already does for a flattened
* {@code @ParameterObject} field.
*
* @author sharanggupta
*/
public class SpringDocApp274Test extends AbstractSpringDocV30Test {

@SpringBootApplication
static class SpringDocTestApp {
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
/*
*
* *
* * *
* * * *
* * * * * Copyright 2019-2026 the original author or authors.
* * * * *
* * * * * Licensed under the Apache License, Version 2.0 (the "License");
* * * * * you may not use this file except in compliance with the License.
* * * * * You may obtain a copy of the License at
* * * * *
* * * * * https://www.apache.org/licenses/LICENSE-2.0
* * * * *
* * * * * Unless required by applicable law or agreed to in writing, software
* * * * * distributed under the License is distributed on an "AS IS" BASIS,
* * * * * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* * * * * See the License for the specific language governing permissions and
* * * * * limitations under the License.
* * * *
* * *
* *
*
*/
package test.org.springdoc.api.v31.app274;

import org.jspecify.annotations.Nullable;

import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PathVariable;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;

/**
* Declares request parameters whose nullability is expressed with the JSpecify {@link Nullable}
* annotation, which only targets type uses, and a path variable carrying the same annotation,
* which must never be described as nullable.
*
* @author sharanggupta
*/
@RestController
public class HelloController {

@GetMapping("/api/items")
String items(@RequestParam @Nullable String filter, @RequestParam @Nullable Integer limit) {
return null;
}

@GetMapping("/api/items/{id}")
String item(@PathVariable @Nullable String id) {
return null;
}

}
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
/*
*
* *
* * *
* * * *
* * * * * Copyright 2019-2026 the original author or authors.
* * * * *
* * * * * Licensed under the Apache License, Version 2.0 (the "License");
* * * * * you may not use this file except in compliance with the License.
* * * * * You may obtain a copy of the License at
* * * * *
* * * * * https://www.apache.org/licenses/LICENSE-2.0
* * * * *
* * * * * Unless required by applicable law or agreed to in writing, software
* * * * * distributed under the License is distributed on an "AS IS" BASIS,
* * * * * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* * * * * See the License for the specific language governing permissions and
* * * * * limitations under the License.
* * * *
* * *
* *
*
*/
package test.org.springdoc.api.v31.app274;

import test.org.springdoc.api.v31.AbstractSpringDocTest;

import org.springframework.boot.autoconfigure.SpringBootApplication;

/**
* Regression: a JSpecify {@code @Nullable} declared on a controller parameter must make the
* generated parameter schema nullable, as it already does for a flattened
* {@code @ParameterObject} field.
*
* @author sharanggupta
*/
public class SpringDocApp274Test extends AbstractSpringDocTest {

@SpringBootApplication
static class SpringDocTestApp {
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,87 @@
{
"openapi": "3.0.1",
"info": {
"title": "OpenAPI definition",
"version": "v0"
},
"servers": [
{
"url": "http://localhost",
"description": "Generated server url"
}
],
"paths": {
"/api/items": {
"get": {
"tags": [
"hello-controller"
],
"operationId": "items",
"parameters": [
{
"name": "filter",
"in": "query",
"required": false,
"schema": {
"type": "string",
"nullable": true
}
},
{
"name": "limit",
"in": "query",
"required": false,
"schema": {
"type": "integer",
"format": "int32",
"nullable": true
}
}
],
"responses": {
"200": {
"description": "OK",
"content": {
"*/*": {
"schema": {
"type": "string"
}
}
}
}
}
}
},
"/api/items/{id}": {
"get": {
"tags": [
"hello-controller"
],
"operationId": "item",
"parameters": [
{
"name": "id",
"in": "path",
"required": true,
"schema": {
"type": "string"
}
}
],
"responses": {
"200": {
"description": "OK",
"content": {
"*/*": {
"schema": {
"type": "string"
}
}
}
}
}
}
}
},
"components": {}
}
Loading