Skip to content

feat(theme)!: remove the JSP search UI and the JSP theme plugin type - #3497

Merged
marevol merged 10 commits into
mainfrom
feat/remove-jsp-search-ui
Sep 26, 2026
Merged

marevol merged 10 commits into
mainfrom
feat/remove-jsp-search-ui

Conversation

@marevol

@marevol marevol commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Summary

Remove the JSP search UI and the JSP theme plugin type. Since #3460 the static theme serves the search pages by default, so the JSP search actions, pages and the code only they used are unreachable. The login pages stay JSP and move under the admin view tree.

Changes

  • Login: the login and new-password JSPs move to WEB-INF/view/admin/login/; the URL stays /login/, and the forms post to /login/ explicitly. Every virtual host renders the same login page.
  • Redirects: a user denied an admin page, and a user who finishes the forced password change without an admin role, land on /; an admin lands on the dashboard. After an SSO login the stored search is restored at /search/?…, as before.
  • Removed actions and forms: RootAction, SearchAction, HelpAction, ChatAction, ProfileAction, CacheAction, the five Error*Action classes, ChatForm, ProfileForm, CacheForm, ErrorForm and SearchForm. GET requests to their URLs are served by the static theme (old paging URLs are still redirected); a POST now gets 404.
  • Removed JSPs: the search, advanced search, help, chat, profile and error pages, and all of WEB-INF/orig/view. cache.hbs (used by the v2 cache API) and WEB-INF/orig/open-search/osdd.xml stay.
  • Per-virtual-host JSP copies: saving the General settings no longer copies JSPs into WEB-INF/view/<key>/; SystemHelper.addDesignJspFileName() and the 19 fess.xml entries are gone.
  • JSP themes: ThemeHelper and the fess-theme plugin type are removed, in the admin plugin screen and in fess-setup. Static themes are unaffected.
  • FessSearchAction, SystemHelper, ViewHelper, FessFunctions, fe.tld (29 → 8 functions) and Constants keep only what the remaining actions and JSPs use.
  • 134 labels and 6 messages that no server code reads any more are removed from all 17 bundles (the static themes carry their own copies in their i18n JSON). 20 static files used only by the removed pages are removed.
  • New tests: every FessHtmlPath constant names an existing JSP; fe.tld declares exactly the functions the JSPs call; every la:link / la:form target in the JSPs, including the target a bare la:form derives from its location, resolves to an existing action.

Upgrade notes

  • JSP customizations of the search pages (including per-virtual-host copies under WEB-INF/view/<key>/) are no longer used. Customize a static theme instead; a virtual host picks the theme named after its key.
  • fess-theme-* plugins no longer work. A leftover jar is shown as a plain jar on the plugin screen and can be deleted there or with fess-setup remove plugin <name>.
  • A plugin or app.xml override that calls SystemHelper.addDesignJspFileName(), ViewHelper.setUseSession(), addInitFacetParam(), addInitGeoParam() or setFacetCacheDuration() names a method that no longer exists; initializing that component fails with BeanMethodNotFoundException. Remove those calls.
  • Scripts that called the removed FessFunctions methods (for example formatFileSize, formatNumber, join) need to be updated.
  • POST requests to the removed search, profile, chat, cache, help and error URLs return 404.

Verification

  • mvn test: 7689 tests, 0 failures, 0 errors. Every commit compiles on its own.
  • Jasper JspC over the 135 remaining JSPs (WEB-INF/view/admin/**, WEB-INF/view/common/admin/**): 0 errors; a deliberately broken fe: call makes it fail.
  • bootstrap theme JS tests: 606 passed.
  • A script finds no reference to the removed classes, methods, JSP paths or fe: functions in this repository or in the other Fess repositories (plugins, themes, tools), apart from fess-webapp-example, updated in chore: drop the design-JSP mappings from the systemHelper override fess-webapp-example#18.
  • Built distribution (mvn antrun:run, mvn package) on OpenSearch 3.8: /login/ renders; the admin/admin forced password change lands on the dashboard, a non-admin user's login on /; a non-admin user opening an admin page is redirected to / and the denial is audit-logged; POST /search/ returns 404; GET /search/next?pn=3&num=20 redirects with start=60; / serves the static theme; saving the General settings with a virtual host creates no JSP copy; a leftover fess-theme-simple jar is listed as a plain jar and removable. The DI container also starts standalone.

The login and new-password pages already use the admin UI's assets, and
they are the only non-admin JSPs left once the search screens go. Move
them to WEB-INF/view/admin/login/; the URL stays /login/.

LoginAction and FessLoginAction no longer pick a per-virtual-host copy
of these pages. Every virtual host renders the same login page.

FessHtmlPath is edited by hand (freegen does not run on JDK 21), so add
a test that every constant names an existing JSP.
Three places sent the user to an action that serves a JSP search page.
The static theme answers those URLs now, so redirect to paths instead:

- A user denied an admin page is redirected to the root.
  UserRoleLoginException no longer carries a target action, and
  FessBaseAction gains redirectToRoot(), still routed through
  SystemHelper.getRedirectResponseToRoot().
- After the forced password change, the user lands where a login lands
  (admin dashboard, the admin page their role allows, or the root)
  instead of the JSP profile page.
- After an SSO login, the stored search is restored at
  /search/?name=value&..., the same URL the search action produced.
The static theme has served the search UI by default since the previous
change, so these actions and pages are no longer reachable:

- RootAction, SearchAction, HelpAction, ChatAction, ProfileAction,
  CacheAction and the five Error*Action classes, with ChatForm,
  ProfileForm, CacheForm, ErrorForm and the shared SearchForm.
- The search, advanced search, help, chat, profile and error JSPs and
  their FessHtmlPath entries.
- ViewHelper.getCachedFacetResponse(), which only the JSP pages used.

GET requests to these URLs are answered by the static theme, and the
old paging URLs are still redirected by StaticThemeFilter. A POST to one
of them now gets 404.

The cached-page template (cache.hbs) stays: the v2 cache API renders it.
These were the originals the page design editor restored from. The
editor is gone and nothing else reads them, so remove the tree and the
unused ResourceUtil.getOrigPath(). WEB-INF/orig/open-search/osdd.xml
stays: it is the OpenSearch description template.
Saving the General settings copied 19 search and login JSPs into
WEB-INF/view/<virtual host key>/ so that each virtual host could edit
its own copy. Those pages are gone or moved, and a virtual host gets its
own look from the static theme named after its key.

Remove SystemHelper's design JSP list and refreshDesignJspFiles(), the
19 addDesignJspFileName entries in fess.xml, the call from the General
settings, VirtualHostHelper.getVirtualHostPath()/getVirtualHostPaths()
and FessSearchAction.virtualHost(). getVirtualHostKey() stays; theme
selection, error pages and search filtering use it.

A plugin that redefines systemHelper and still calls addDesignJspFileName
fails to initialize that component definition with a
BeanMethodNotFoundException, as the plugin's own container tests show;
remove those calls. A real server boot was verified to still come up.
A fess-theme-* jar carried JSP pages that ThemeHelper extracted into
WEB-INF/view/<name>/, and a virtual host picked them up through the
per-host JSP lookup that is now gone. Remove ThemeHelper, the THEME
artifact type and its install/uninstall branches, and stop fess-setup
from listing or installing fess-theme-* jars.

Static themes are not affected: they are published under
org/codelibs/fess/themes/ without this prefix and installed as ZIP
archives by the theme screen and fess-setup.

A fess-theme-*.jar left in the plugin directory by an older release
shows up as a plain jar on the plugin screen, where it can be deleted;
"fess-setup remove plugin <name>" also removes it.
FessSearchAction registered data for the JSP search pages on every
request (labels, languages, popular words, feature flags, the user
name) and showed the permission-state notice through <la:errors>. The
actions that still extend it (login, logout, SSO, go, thumbnail, OSDD)
use none of that; the static theme gets the permission state from the
v2 search API.

Keep only the login requirement, the redirect to login, the thumbnail
flag and the helpers those actions use. Remove what only the JSP pages
called from SystemHelper (language items, search HTML data) and
ViewHelper (localized page paths, the session flag, initial facet and
geo parameters).

ViewHelper.setUseSession(), addInitFacetParam() and addInitGeoParam()
go with them; an app.xml override that still calls them fails to
initialize that component definition with a BeanMethodNotFoundException;
remove those calls.
fe.tld now declares the eight functions the admin and login JSPs call:
html, date, formatDate, base64, fileExists, url, replace and permission.
Remove the other 21 declarations (including mltQuery and mltForm, which
pointed at methods that did not exist), the FessFunctions methods only
they reached, and the request-attribute constants those methods read.

parseDate(String, String) and escapeJs stay because Java code calls
them.

Add a test that fe.tld declares exactly the functions the JSPs call and
that every declaration resolves to a method, since JSPs are not
compiled by the build.
…used

Remove 134 labels and 6 messages from all 17 bundles, with their
FessLabels and FessMessages entries and tests. Each was referenced only
by the removed JSPs, actions, forms (field labels such as labels.hq) or
helper methods, or only by the static themes' own JavaScript naming the
key; a script checked the Fess repositories, plugins, themes, tools and
docs for any other reference.

The static themes look these names up in their own copies in
themes/*/i18n/messages.*.json, never in fess_label/fess_message, so
removing the bundle entries does not change theme behavior.
Remove the search screens' stylesheets, scripts and images (css/style.css,
css/chat.css, js/search.js, js/suggestor.js, the bundled jQuery,
clipboard, marked and DOMPurify copies, and unused images).

Kept: the files the bundled static theme and the fess-themes themes
load from the webapp root (css/bootstrap.min.css,
css/font-awesome.min.css, js/popper.min.js, js/bootstrap.min.js,
favicon.ico), css/fonts (also used by the admin UI's Font Awesome), and
what the admin and login pages use (js/login.js, images/logo-top.png,
images/logo-head.png).
@marevol marevol added this to the 15.9.0 milestone Sep 26, 2026
@marevol marevol self-assigned this Sep 26, 2026
@marevol
marevol merged commit a6a1ea3 into main Sep 26, 2026
2 checks passed
marevol added a commit to codelibs/fess-docs that referenced this pull request Sep 27, 2026
… type (#559)

Fess 15.9 removed the JSP search screens and the fess-theme plugin type
(codelibs/fess#3497). Saving the General settings no longer copies JSP
files per virtual host, the login page is served from
WEB-INF/view/admin/login/ for every virtual host, and a fess-theme-*.jar
is only kept as a plain jar that changes nothing.

Update the 15.9 pages in all seven languages that still described the
old behavior: the virtual host note, the JAR theme section of the theme
development guide (now a short "removed in 15.9, move to a static theme"
section), the plugin type tables, the plugin API type list, the theme
guide note, the webapp plugin guide's addDesignJspFileName advice, the
busy.jsp error page of load control, and the password change flow of the
role search page. The upgrade notes now say that per-virtual-host login
pages and JAR themes are gone, and that custom fields shown in the JSP
results must also be added to query.additional.api.response.fields.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant