Skip to content

Fix #6260: honor @JsonView on @JsonAnySetter when deserializing - #6248

Open
pjfanning wants to merge 4 commits into
FasterXML:3.1from
pjfanning:any-setter-json-view
Open

pjfanning wants to merge 4 commits into
FasterXML:3.1from
pjfanning:any-setter-json-view

Conversation

@pjfanning

@pjfanning pjfanning commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Fixes #6260.

static class Bean {
    @JsonView(ViewA.class) public String a;
    @JsonAnySetter @JsonView(ViewB.class)
    public Map<String, Object> other = new LinkedHashMap<>();
}

mapper.readerWithView(ViewA.class).forType(Bean.class)
    .readValue("{\"a\":\"1\",\"x\":\"3\"}");
// before: other == {x=3}; after this PR merged: other == {}

Changes

  • SettableAnyProperty now stores views (setViews(), visibleInView(), hasViews()), and withValueDeserializer() carries them over.
  • BeanDeserializerFactory reads an explicit @JsonView from the any-setter accessor. This works for methods, fields and creator parameters.
  • BeanDeserializerBuilder._anyViews() enables view processing when the any-setter has views.
  • New BeanDeserializerBase._skipIfAnySetterNotInView(), called at every point where a value goes to the any-setter: the vanilla, creator, record-update, unwrapped and external-type-id paths, BuilderBasedDeserializer, and ThrowableDeserializer. A hidden value is skipped. If FAIL_ON_UNEXPECTED_VIEW_PROPERTIES is enabled, it is reported instead, the same way as for regular properties.

Tradeoff

Only an explicit @JsonView on the any-setter counts. Class-level default views and DEFAULT_VIEW_INCLUSION are not applied to it. That differs from regular properties and from @JsonAnyGetter. Applying them would mean that with 3.x defaults (DEFAULT_VIEW_INCLUSION disabled), an un-annotated any-setter stops receiving any values once a view is active. That seemed too big a behavior change for a patch release. If full symmetry is wanted, it could be done in 3.3.

Tests

Added AnySetterViewDeserializationTest, which covers method, field, creator-bean, record creator-parameter and builder any-setters, an un-annotated any-setter (behavior unchanged), and FAIL_ON_UNEXPECTED_VIEW_PROPERTIES. Without the fix, 6 of its 7 tests fail. ./mvnw verify passes.

🤖 Generated with Claude Code

pjfanning and others added 2 commits September 29, 2026 10:36
Views declared on an any-setter were ignored on deserialization, so values
were passed to it regardless of the active view -- unlike regular properties,
and unlike `@JsonAnyGetter` on serialization. Now, if the any-setter is not
visible in the active view, the value is skipped (or, with
`DeserializationFeature.FAIL_ON_UNEXPECTED_VIEW_PROPERTIES`, reported),
same as for regular properties.

Only an explicit `@JsonView` on the any-setter itself is considered; class-level
default views are not applied, so un-annotated any-setters behave as before.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

🧪 Code Coverage Report

Metric Coverage
Instructions coverage 81.48%
Branches branches 74.83%

Coverage data generated from JaCoCo test results

@github-actions

Copy link
Copy Markdown

🧪 Code Coverage Report

Metric Coverage
Instructions coverage 81.48%
Branches branches 74.82%

Coverage data generated from JaCoCo test results

@github-actions

Copy link
Copy Markdown

🧪 Code Coverage Report

Metric Coverage Change
Instructions coverage 81.43% 📈 +0.000%
Branches branches 74.93% 📉 -0.040%

Coverage data generated from JaCoCo test results

@cowtowncoder

Copy link
Copy Markdown
Member

@pjfanning Since this is a new feature, let's target 3.x (3.3) instead of 3.1.

@cowtowncoder cowtowncoder changed the title Honor @JsonView on @JsonAnySetter when deserializing Fix #6260: honor @JsonView on @JsonAnySetter when deserializing Oct 1, 2026
@cowtowncoder cowtowncoder linked an issue Oct 1, 2026 that may be closed by this pull request
@gitar-bot

gitar-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown
Code Review ✅ Approved

🟡 Medium risk · Deserialization now filters any-setter values across multiple bean construction paths.

Fixes deserialization to honor @JsonView on @JsonAnySetter by storing and checking view visibility in SettableAnyProperty, reading explicit view annotations in BeanDeserializerFactory, and skipping any-setter values outside the active view across all deserialization paths. No issues found.

Review coverage

📋 Rules No rules evaluated

🧪 Functional validation Not enabled · Set up

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Powered by Gitar — free for open source

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

🧪 Code Coverage Report

Metric Coverage Change
Instructions coverage 81.47% 📈 +0.040%
Branches branches 74.99% 📈 +0.020%

Coverage data generated from JaCoCo test results

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support @JsonView for @JsonAnySetter deserialization

2 participants