T map(String name, T encoder) {
* Returns the shared stateless Encoder singleton for the specified context.
* The returned instance is thread-safe. Context names are case-sensitive.
*
+ * The deprecated {@code "uri"} context ({@link #URI}) is still
+ * recognized for compatibility.
+ *
* @param contextName the context name (one of the String constants defined
* in this class)
* @return an encoder for the specified context.
diff --git a/core/src/test/java/org/owasp/encoder/EncodersTest.java b/core/src/test/java/org/owasp/encoder/EncodersTest.java
index 64f4c5f..7775e88 100644
--- a/core/src/test/java/org/owasp/encoder/EncodersTest.java
+++ b/core/src/test/java/org/owasp/encoder/EncodersTest.java
@@ -116,6 +116,20 @@ public void testForNameIsNotNull() throws Exception {
assertTrue(count > 0);
}
+ /**
+ * The "uri" context is deprecated everywhere Encode.forUri is, but stays
+ * usable for compatibility.
+ */
+ public void testUriContextIsDeprecatedButRetained() throws Exception {
+ assertTrue(Encoders.class.getField("URI").isAnnotationPresent(Deprecated.class));
+ assertTrue(Encode.class.getMethod("forUri", String.class)
+ .isAnnotationPresent(Deprecated.class));
+ assertTrue(Encode.class.getMethod("forUri", java.io.Writer.class, String.class)
+ .isAnnotationPresent(Deprecated.class));
+ assertFalse(Encoders.class.getField("URI_COMPONENT").isAnnotationPresent(Deprecated.class));
+ assertSame(Encoders.URI_ENCODER, Encoders.forName("uri"));
+ }
+
public void testJsonContext() throws Exception {
assertEquals("json", Encoders.JSON);
Encoder encoder = Encoders.forName(Encoders.JSON);
diff --git a/esapi/pom.xml b/esapi/pom.xml
index c976ee8..e12d053 100644
--- a/esapi/pom.xml
+++ b/esapi/pom.xml
@@ -96,6 +96,10 @@
org.apache.maven.plugins
maven-compiler-plugin
+
+
+ true
+
compile-module-path-test-support
diff --git a/jakarta/pom.xml b/jakarta/pom.xml
index 8e1d0b1..b73968f 100644
--- a/jakarta/pom.xml
+++ b/jakarta/pom.xml
@@ -90,6 +90,10 @@
org.apache.maven.plugins
maven-compiler-plugin
+
+
+ true
+
compile-module-path-test-support
diff --git a/jakarta/src/main/java/org/owasp/encoder/tag/ForUriTag.java b/jakarta/src/main/java/org/owasp/encoder/tag/ForUriTag.java
index e68903f..3586f66 100644
--- a/jakarta/src/main/java/org/owasp/encoder/tag/ForUriTag.java
+++ b/jakarta/src/main/java/org/owasp/encoder/tag/ForUriTag.java
@@ -43,7 +43,12 @@
* This wraps the {@link org.owasp.encoder.Encode#forUri(java.lang.String)}.
*
* @author Jeremy Long (jeremy.long@gmail.com)
+ * @deprecated Use {@link ForUriComponentTag} for each untrusted value
+ * inserted into a URL. See
+ * {@link org.owasp.encoder.Encode#forUri(java.lang.String)} for how to handle
+ * an entire untrusted URL. Retained for compatibility in all 1.x releases.
*/
+@Deprecated
public class ForUriTag extends EncodingTag {
@Override
public void doTag() throws JspException, IOException {
diff --git a/jakarta/src/main/resources/META-INF/java-encoder-advanced.tld b/jakarta/src/main/resources/META-INF/java-encoder-advanced.tld
index bea2fea..857cf7d 100644
--- a/jakarta/src/main/resources/META-INF/java-encoder-advanced.tld
+++ b/jakarta/src/main/resources/META-INF/java-encoder-advanced.tld
@@ -244,7 +244,7 @@
particularly dangerous context to put untrusted content in, as for
example a "javascript:" URL provided by a malicious user would be
"properly" escaped, and still execute.
- Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context.
+ Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context. Always encodes %, so never apply it to an already percent-encoded URI.
forUri
forUri
@@ -469,7 +469,7 @@
particularly dangerous context to put untrusted content in, as for
example a "javascript:" URL provided by a malicious user would be
"properly" escaped, and still execute.
- Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context.
+ Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context. Always encodes %, so never apply it to an already percent-encoded URI.
forUri
forUri
diff --git a/jakarta/src/main/resources/META-INF/java-encoder.tld b/jakarta/src/main/resources/META-INF/java-encoder.tld
index 86fdad0..3327e72 100644
--- a/jakarta/src/main/resources/META-INF/java-encoder.tld
+++ b/jakarta/src/main/resources/META-INF/java-encoder.tld
@@ -160,7 +160,7 @@
particularly dangerous context to put untrusted content in, as for
example a "javascript:" URL provided by a malicious user would be
"properly" escaped, and still execute.
- Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context.
+ Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context. Always encodes %, so never apply it to an already percent-encoded URI.
forUri
forUri
@@ -364,7 +364,7 @@
particularly dangerous context to put untrusted content in, as for
example a "javascript:" URL provided by a malicious user would be
"properly" escaped, and still execute.
- Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context.
+ Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context. Always encodes %, so never apply it to an already percent-encoded URI.
forUri
forUri
diff --git a/jakarta/src/test/java/org/owasp/encoder/tag/ForUriTagDeprecationTest.java b/jakarta/src/test/java/org/owasp/encoder/tag/ForUriTagDeprecationTest.java
new file mode 100644
index 0000000..ead2595
--- /dev/null
+++ b/jakarta/src/test/java/org/owasp/encoder/tag/ForUriTagDeprecationTest.java
@@ -0,0 +1,49 @@
+// Copyright (c) 2026 OWASP
+// All rights reserved.
+//
+// Redistribution and use in source and binary forms, with or without
+// modification, are permitted provided that the following conditions
+// are met:
+//
+// * Redistributions of source code must retain the above
+// copyright notice, this list of conditions and the following
+// disclaimer.
+//
+// * Redistributions in binary form must reproduce the above
+// copyright notice, this list of conditions and the following
+// disclaimer in the documentation and/or other materials
+// provided with the distribution.
+//
+// * Neither the name of the OWASP nor the names of its
+// contributors may be used to endorse or promote products
+// derived from this software without specific prior written
+// permission.
+//
+// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
+// FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
+// COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
+// INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
+// (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
+// SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+// HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
+// STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+// ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
+// OF THE POSSIBILITY OF SUCH DAMAGE.
+
+package org.owasp.encoder.tag;
+
+import junit.framework.TestCase;
+
+/**
+ * ForUriTag is deprecated like Encode.forUri, and its replacement is not.
+ */
+public class ForUriTagDeprecationTest extends TestCase {
+
+ @SuppressWarnings("deprecation") // the test inspects the deprecated tag
+ public void testForUriTagIsDeprecated() {
+ assertTrue(ForUriTag.class.isAnnotationPresent(Deprecated.class));
+ assertFalse(ForUriComponentTag.class.isAnnotationPresent(Deprecated.class));
+ }
+}
diff --git a/jsp/pom.xml b/jsp/pom.xml
index 3fe44ed..cfc6ebe 100644
--- a/jsp/pom.xml
+++ b/jsp/pom.xml
@@ -90,6 +90,10 @@
org.apache.maven.plugins
maven-compiler-plugin
+
+
+ true
+
compile-module-path-test-support
diff --git a/jsp/src/main/java/org/owasp/encoder/tag/ForUriTag.java b/jsp/src/main/java/org/owasp/encoder/tag/ForUriTag.java
index 9b975f5..415b6f7 100644
--- a/jsp/src/main/java/org/owasp/encoder/tag/ForUriTag.java
+++ b/jsp/src/main/java/org/owasp/encoder/tag/ForUriTag.java
@@ -43,7 +43,12 @@
* This wraps the {@link org.owasp.encoder.Encode#forUri(java.lang.String)}.
*
* @author Jeremy Long (jeremy.long@gmail.com)
+ * @deprecated Use {@link ForUriComponentTag} for each untrusted value
+ * inserted into a URL. See
+ * {@link org.owasp.encoder.Encode#forUri(java.lang.String)} for how to handle
+ * an entire untrusted URL. Retained for compatibility in all 1.x releases.
*/
+@Deprecated
public class ForUriTag extends EncodingTag {
@Override
public void doTag() throws JspException, IOException {
diff --git a/jsp/src/main/resources/META-INF/java-encoder-advanced.tld b/jsp/src/main/resources/META-INF/java-encoder-advanced.tld
index 07b9559..da4050f 100644
--- a/jsp/src/main/resources/META-INF/java-encoder-advanced.tld
+++ b/jsp/src/main/resources/META-INF/java-encoder-advanced.tld
@@ -244,7 +244,7 @@
particularly dangerous context to put untrusted content in, as for
example a "javascript:" URL provided by a malicious user would be
"properly" escaped, and still execute.
- Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context.
+ Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context. Always encodes %, so never apply it to an already percent-encoded URI.
forUri
forUri
@@ -469,7 +469,7 @@
particularly dangerous context to put untrusted content in, as for
example a "javascript:" URL provided by a malicious user would be
"properly" escaped, and still execute.
- Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context.
+ Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context. Always encodes %, so never apply it to an already percent-encoded URI.
forUri
forUri
diff --git a/jsp/src/main/resources/META-INF/java-encoder.tld b/jsp/src/main/resources/META-INF/java-encoder.tld
index 48bc264..01ac866 100644
--- a/jsp/src/main/resources/META-INF/java-encoder.tld
+++ b/jsp/src/main/resources/META-INF/java-encoder.tld
@@ -157,7 +157,7 @@
particularly dangerous context to put untrusted content in, as for
example a "javascript:" URL provided by a malicious user would be
"properly" escaped, and still execute.
- Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context.
+ Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context. Always encodes %, so never apply it to an already percent-encoded URI.
forUri
forUri
@@ -361,7 +361,7 @@
particularly dangerous context to put untrusted content in, as for
example a "javascript:" URL provided by a malicious user would be
"properly" escaped, and still execute.
- Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context.
+ Deprecated: prefer java.net.URI when working with complete URIs and forUriComponent for individual inserted components. Validate the URL scheme before use and apply encoding for the enclosing output context. Always encodes %, so never apply it to an already percent-encoded URI.
forUri
forUri
diff --git a/jsp/src/test/java/org/owasp/encoder/tag/ForUriTagDeprecationTest.java b/jsp/src/test/java/org/owasp/encoder/tag/ForUriTagDeprecationTest.java
new file mode 100644
index 0000000..ead2595
--- /dev/null
+++ b/jsp/src/test/java/org/owasp/encoder/tag/ForUriTagDeprecationTest.java
@@ -0,0 +1,49 @@
+// Copyright (c) 2026 OWASP
+// All rights reserved.
+//
+// Redistribution and use in source and binary forms, with or without
+// modification, are permitted provided that the following conditions
+// are met:
+//
+// * Redistributions of source code must retain the above
+// copyright notice, this list of conditions and the following
+// disclaimer.
+//
+// * Redistributions in binary form must reproduce the above
+// copyright notice, this list of conditions and the following
+// disclaimer in the documentation and/or other materials
+// provided with the distribution.
+//
+// * Neither the name of the OWASP nor the names of its
+// contributors may be used to endorse or promote products
+// derived from this software without specific prior written
+// permission.
+//
+// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
+// FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
+// COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
+// INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
+// (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
+// SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+// HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
+// STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+// ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
+// OF THE POSSIBILITY OF SUCH DAMAGE.
+
+package org.owasp.encoder.tag;
+
+import junit.framework.TestCase;
+
+/**
+ * ForUriTag is deprecated like Encode.forUri, and its replacement is not.
+ */
+public class ForUriTagDeprecationTest extends TestCase {
+
+ @SuppressWarnings("deprecation") // the test inspects the deprecated tag
+ public void testForUriTagIsDeprecated() {
+ assertTrue(ForUriTag.class.isAnnotationPresent(Deprecated.class));
+ assertFalse(ForUriComponentTag.class.isAnnotationPresent(Deprecated.class));
+ }
+}