Consolidated technical reference. Use this page as an anchor for external links (issues, RFCs, other Antora sites).
Maven artefacts
| Artefact | Role |
|---|---|
|
Public SPI: |
|
Servlet 6.1 engine — dispatcher, filter chain, sessions, error pages, listeners, security, |
|
Bootstrap on the Chappe transport ( |
|
CDI bridge to Vauban ( |
|
Arquillian harness for the official TCK — in-reactor, gated behind the |
Java modules and exports
module io.vidocq.foy.api {
requires transitive jakarta.servlet;
requires static jakarta.annotation;
exports io.vidocq.foy.spi.session; // SessionStore
exports io.vidocq.foy.spi.security; // SecurityProvider, AuthenticatedUser
}
module io.vidocq.foy.core {
requires transitive io.vidocq.foy.api;
requires transitive jakarta.servlet;
requires static jakarta.cdi;
requires static jakarta.annotation;
requires java.xml;
requires static java.net.http;
requires io.vidocq.chappe.api; // M1 coupling — will become an SPI in M2
exports io.vidocq.foy.internal.async;
exports io.vidocq.foy.internal.boot;
exports io.vidocq.foy.internal.bridge;
exports io.vidocq.foy.internal.container;
exports io.vidocq.foy.internal.dispatcher;
exports io.vidocq.foy.internal.error;
exports io.vidocq.foy.internal.http;
exports io.vidocq.foy.internal.listener;
exports io.vidocq.foy.internal.security;
exports io.vidocq.foy.internal.session;
exports io.vidocq.foy.internal.webxml;
}
module io.vidocq.foy.chappe {
requires transitive io.vidocq.foy.api;
requires io.vidocq.foy.core;
requires io.vidocq.chappe.api;
requires jakarta.servlet;
requires jakarta.cdi;
exports io.vidocq.foy.chappe; // FoyChappeBoot
}
module io.vidocq.foy.cdi.vauban {
requires transitive io.vidocq.foy.api;
requires jakarta.cdi;
requires io.vidocq.vauban.core;
exports io.vidocq.foy.cdi.vauban; // FoyVaubanBootstrap
}
|
The |
Public API: FoyChappeBoot
| Method | Description |
|---|---|
|
Returns a fresh |
|
Required. Vauban |
|
URL prefix served by this container. Default: |
|
Session timeout in seconds. Default: |
|
Returns |
|
The |
|
Mount prefix to use ( |
|
The container’s |
|
Fire |
|
Fire |
Public SPI (foy-api)
| Type | Role |
|---|---|
|
Session storage backend. Default: |
|
Application authentication. Default: |
|
Immutable authenticated-user representation (login, roles, attributes). |
web.xml configuration
WebXmlParser reads exactly this subset of the Servlet 6.1 WEB-INF/web.xml (contributed after annotation discovery, never overriding an already-discovered name):
-
<display-name> -
<context-param>(param-name/param-value) exposed viaServletContext.getInitParameter -
<servlet>(servlet-name,servlet-class,init-param,async-supported) /<servlet-mapping>(servlet-name,url-pattern) -
<filter>(filter-name,filter-class,init-param) /<filter-mapping>(filter-name,url-pattern,servlet-name,dispatcher— defaults toREQUEST) -
<listener>(listener-class) -
<error-page>(error-code,exception-type,location) -
<session-config>/<session-timeout>(timeout only — no cookie config) -
<locale-encoding-mapping-list>/<locale-encoding-mapping>(locale,encoding) -
the
versionattribute of<web-app>
Everything else is not parsed — notably <security-constraint>, <login-config>, <security-role>, <welcome-file-list>, <multipart-config>, <mime-mapping>, <load-on-startup> and <jsp-config>.
|
|
Servlet 6.1 API comparison
| Area | Foy status | Notes |
|---|---|---|
Core ( |
✅ |
Near-complete coverage in the official TCK. |
|
✅ |
Cross-context ( |
Web fragments ( |
❌ |
Not implemented yet — the top TCK gap (81 % of failures). See TCK. |
Async ( |
⚠️ |
Standard cases OK; non-blocking I/O listeners and part of the |
Multipart ( |
⚠️ |
Buffered in memory — no streaming parse, no temp-file spill; limit/threshold handling partial (8 of 14 |
Sessions |
✅ |
|
Security (Basic) |
⚠️ |
|
Security (Form, Digest, Jakarta Auth) |
❌ |
Not implemented. |
WebSocket (Servlet 6.1 upgrade) |
❌ |
Not implemented (planned, no date). |
JSP |
❌ |
Not supported, not planned. |