As of Broadleaf Release Train 3.0.0-GA, all microservices have been upgraded to support Spring Boot 4.1 and Java 25.
|
Important
|
Spring Cloud Gateway 5.0, which ships with Spring Boot 4, moved the whole Broadleaf relocates legacy keys automatically at startup so existing configuration keeps working, and logs each key it relocates. Treat those log lines as a to-do list and move the keys in your own configuration. See the Upgrade Guide below. |
Please refer to Session Token Blacklisting documentation for more details on this feature.
The filter is off by default. Enable it by selecting an implementation under broadleaf.gateway.auth.access-token-blacklist-filter:
implementation — NONE (default), LOCAL_MEMORY, or REDIS
include-paths (default /**) and exclude-paths (default empty) — Ant-style patterns selecting the requests the filter applies to. A path matching both is excluded.
blacklist-check-operation-timeout-ms (default 2000) — the end-to-end budget for a blacklist lookup. On timeout the request fails open and proceeds downstream, where signature and expiration validation still apply.
circuit-breaker-failure-rate-threshold (default 50.0), circuit-breaker-wait-duration-in-open-state-ms (default 10000), circuit-breaker-sliding-window-size (default 100), circuit-breaker-permitted-number-of-calls-in-half-open-state (default 10) — the circuit breaker that bounds the cost of an unhealthy blacklist store. Once open, lookups fail open immediately rather than waiting out the timeout.
Redis auto-configuration stays fully dormant unless broadleaf.gateway.redis.enabled is true, so adding the Redis dependencies does not introduce an Actuator health check that can restart a pod on an unrelated Redis outage.
The gateways now ship ERROR as the log level for org.apache.kafka.clients.consumer.internals.OffsetFetcherUtils.
Kafka 4.2 logs Not updating high watermark for partition … as it is no longer assigned at WARN during normal rebalancing; the condition is benign and suppression is the expected response.
See KAFKA-20449.
Fix an issue where the Forwarded and X-Forwarded-* headers were stripped from every proxied request, so downstream applications could not resolve their own scheme, host or port and generated links against the gateway’s internal address instead
Spring Cloud Gateway 5.0.2 began registering "remove" header filters whenever the corresponding out-of-box header filter is not created, which is exactly the configuration Broadleaf requires in order to substitute its own trusted-proxy-aware filters. Both ended up in the context, every filter involved reported the same order, and the remove filters won on registration order — stripping the headers Broadleaf had just added, without consulting the trusted proxies or the remote address.
The remove filters are now dropped from the context whenever Broadleaf’s replacements are present.
Update the gateway base images to the latest OS and JRE builds for CVE remediation. For more details, please visit Broadleaf Security and review the security advisories page.
spring.cloud.gateway.* PropertiesSpring Cloud Gateway 5.0 binds GatewayProperties under spring.cloud.gateway.server.webflux.
Broadleaf’s GatewayServerPropertyRelocationApplicationContextInitializer contributes a lowest-precedence property source that answers a read of spring.cloud.gateway.server.webflux.<x> from the legacy spring.cloud.gateway.<x> key, so existing configuration continues to bind — including configuration served by Spring Cloud Config Server, and including {cipher} values, because the relocation runs as a context initializer after remote configuration has been assembled and decrypted.
An explicitly set spring.cloud.gateway.server.webflux.* value always wins over a relocated legacy one, so properties can be moved incrementally. The general rule is:
spring.cloud.gateway.<x> becomes spring.cloud.gateway.server.webflux.<x>
keys already under spring.cloud.gateway.server.* are left alone — do not add a second prefix
The keys Broadleaf’s own gateway configuration uses:
| Legacy property | Spring Cloud Gateway 5 property |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
unchanged — not relocated |