RFR: 8294241: Deprecate URL public constructors

Alan Bateman Alan.Bateman at oracle.com
Thu Oct 27 06:26:46 UTC 2022


On 26/10/2022 23:53, Peter Firmstone wrote:
> The change will have some performance impact, by requiring redundant 
> parsing.
>
> Just thought I'd mention it, in case it hasn't been thought of. If you 
> do an internet search there are other implementations of RFC3986 in 
> java also.
>
> https://github.com/pfirmstone/JGDMS/blob/e4a5012e71fd9a61b6e1e505f07e6c5358a4ccbc/JGDMS/jgdms-platform/src/main/java/org/apache/river/api/net/Uri.java#L1966 
>
>
> We have a strict URI 3986 implementation, which we use to create all 
> URL instances from.

If your parser is using the one-arg URL constructor to create the URL 
then it will be parsed again, so you may already have duplicate 
parsing.  That said, there may be an argument that libraries should be 
able to do their own parsing and continue to construct a URL from its 
components with the non-validating constructors.

As I'm sure you know, changing URI to strictly implement RFC 3986 is not 
a compatible move. It was attempted in JDK 6 but had to backed out 
quickly as it caused widespread breakage. Hierarchical URIs using 
registry based authority components was one of significant issues. There 
has been exploration and prototypes since then to try to find a 
direction but there isn't a proposal right now.

-Alan


More information about the security-dev mailing list