Skip to content

fix(flagsmith): upgrade Java client to 8.1.1 - #1880

Open
AllanAlmeida wants to merge 1 commit into
open-feature:mainfrom
AllanAlmeida:fix/flagsmith-client-8-1816
Open

AllanAlmeida wants to merge 1 commit into
open-feature:mainfrom
AllanAlmeida:fix/flagsmith-client-8-1816

Conversation

@AllanAlmeida

Copy link
Copy Markdown

Summary

  • Upgrade flagsmith-java-client from 7.4.3 to 8.1.1.
  • Align OkHttp and MockWebServer with the client's OkHttp 5 dependency, updating test dispatchers for its API.
  • Cover local evaluation of a segment rule against $.identity.identifier for matching and nonmatching identities.

Validation

  • ./mvnw -B -ntp -pl providers/flagsmith verify with JDK 21: 36 tests passed; Checkstyle, PMD, SpotBugs, and Spotless passed.
  • ./mvnw -B -ntp -pl providers/flagsmith dependency:tree -Dincludes=com.squareup.okhttp3: only OkHttp 5 artifacts are resolved.

Closes #1816.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 563c378f-36c3-4316-b9f7-cb9fc4d00b83

📥 Commits

Reviewing files that changed from the base of the PR and between c1c3929 and 3c83833.

📒 Files selected for processing (3)
  • providers/flagsmith/pom.xml
  • providers/flagsmith/src/test/java/dev.openfeature.contrib.providers.flagsmith/FlagsmithProviderTest.java
  • providers/flagsmith/src/test/resources/mock_responses/identity-segment-environment-document.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The Flagsmith client and HTTP dependencies are upgraded. The provider tests use request-based mock-server dispatchers and add coverage for local evaluation against an identity segment.

Changes

Flagsmith local evaluation

Layer / File(s) Summary
Update Flagsmith and HTTP client dependencies
providers/flagsmith/pom.xml
The Flagsmith client is upgraded to 8.1.1. OkHttp changes to okhttp-jvm 5.0.0, and MockWebServer is upgraded to 5.0.0.
Test local identity-segment evaluation
providers/flagsmith/src/test/java/dev.openfeature.contrib.providers.flagsmith/FlagsmithProviderTest.java, providers/flagsmith/src/test/resources/mock_responses/identity-segment-environment-document.json
Request-based dispatchers return fixtures by request path or return HTTP 404; the error dispatcher returns HTTP 500. The new test checks that the matching targeting key returns "matched" and another key returns "default".

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 3c838

The dependency upgrade includes coverage for identity matching and environment-default fallback. No actionable merge-blocking risk is identified; merge after normal checks pass.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 3c838

The upgrade retains the provider’s existing configuration and evaluation paths, and no new production entrypoint or weakened control was identified. Some uncertainty remains because the upgraded libraries’ internal identity-evaluation and transport behavior was not verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated production exposure is applications using the Flagsmith provider with the upgraded SDK and HTTP client. The selected public-entrypoint evidence does not establish a new inbound production attack surface or broader service authority.

Trust Boundaries and Controls

  • observed — Application-supplied identity and context values continue to cross into the Flagsmith SDK through the existing evaluation path. The new test demonstrates targeting behavior, not authentication or authorization enforcement, and does not establish the upgraded SDK’s internal security properties.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 1 files. (2 skipped: 2 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the primary change: upgrading the Flagsmith Java client to 8.1.1.
Description check ✅ Passed The description directly covers the dependency upgrade, OkHttp and MockWebServer alignment, test updates, local-evaluation coverage, and validation results.
Linked Issues check ✅ Passed The PR satisfies the coding requirements in [#1816]. providers/flagsmith/pom.xml upgrades flagsmith-java-client from 7.4.3 to 8.1.1 and aligns okhttp-jvm and MockWebServer to 5.0.0. The test upd…
Out of Scope Changes check ✅ Passed The changes remain within [#1816]. The OkHttp dependency alignment and dispatcher updates support the client upgrade. The fixture and local-evaluation test directly verify the reported identity-segmen…
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 1 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

Signed-off-by: AllanAlmeida <allan.almeida.cpmb@gmail.com>
@AllanAlmeida
AllanAlmeida force-pushed the fix/flagsmith-client-8-1816 branch from 32b5976 to 3c83833 Compare October 1, 2026 17:33

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Flagsmith] Bump flagsmith-java-client from 7.4.3 to 8.x

3 participants