Prev Next

API / Apache FreeMarker Interview questions

Why doesn't FreeMarker allow templates unrestricted access to Java reflection and side-effecting method calls?

This is a deliberate security boundary, separate from the general design-philosophy reasoning behind FTL's restricted syntax. If a template - which may come from a less-trusted source such as CMS content or a customer-editable theme - could invoke arbitrary Java methods through reflection, it could just as easily call something like a process-execution API as it could call a harmless getter.

FreeMarker's ObjectWrapper is the actual enforcement point: it decides which properties and methods of a wrapped Java object are visible to template expressions at all, and a more restrictive wrapper such as SimpleObjectWrapper exposes far less than DefaultObjectWrapper does. Static members and enum constants are not reachable from templates by default at all - they must be deliberately exposed, typically via BeansWrapper.getStaticModels() - and a TemplateClassResolver can further restrict which classes a template is even allowed to name. Raising incompatible_improvements can also tighten some of these defaults over time without silently changing behavior for applications that have not opted in.

In short, the safety comes from what the application chooses to expose through the wrapper and resolver settings, not from any restriction baked into the FTL syntax itself.

What is the actual enforcement point that decides which Java methods a template can call?
Are static Java methods and enum constants reachable from a template by default?

More Related questions...

What is Apache FreeMarker? What are the main use cases of FreeMarker? What is a FreeMarker template? What is the purpose of the FreeMarker Configuration object? What are the types in FreeMarker's data model? Define directive in FreeMarker? What is the purpose of interpolation (${...}) in FreeMarker? What is the purpose of the <#if> directive? What are the types of loops available in FreeMarker? How do you use the #assign directive? How do you apply default values for missing variables in FreeMarker? Describe the built-ins available in FreeMarker? List the comparison operators supported in FreeMarker? What is the purpose of the #include directive? What is the purpose of the #import directive? How do you use comments in FreeMarker templates? What is the difference between #include and #import? What is the difference between #assign and #global? What is the difference between #assign and #local? How does FreeMarker handle missing or null values differently from Java? What is the difference between the?? and! operators? Explain the execution flow of template processing in FreeMarker? What happens when a variable referenced in a template is not found in the data model? How do you create a custom directive in FreeMarker using TemplateDirectiveModel? How do you create a user-defined macro using #macro? What is the difference between a macro and a custom directive (TemplateDirectiveModel)? How does FreeMarker's auto-escaping work? Why should you use an ObjectWrapper such as DefaultObjectWrapper in FreeMarker? What is the difference between BeansWrapper and DefaultObjectWrapper? How can you optimize FreeMarker template performance? How do you troubleshoot a TemplateNotFoundException? What is the difference between TemplateException and ParseException? Why does FreeMarker use its own restricted expression language instead of plain Java? When should you choose FreeMarker over other template engines like Velocity or Thymeleaf? What is the difference between FreeMarker and Apache Velocity? What is the difference between FreeMarker and Thymeleaf? Explain the lifecycle of a FreeMarker Template object? What is the purpose of TemplateLoader, and what types are available? How does FreeMarker resolve template paths when a MultiTemplateLoader chains several loaders together? Explain the internal working of FreeMarker's template caching? Why doesn't FreeMarker allow templates unrestricted access to Java reflection and side-effecting method calls? What is the purpose of the incompatible_improvements setting? How do you access static Java members (static methods, fields, and enum constants) from a FreeMarker template? How do you access the current loop position and detect the last item inside a #list block? How do you handle exceptions raised inside a FreeMarker template using TemplateExceptionHandler? How do you internationalize FreeMarker templates for different locales? Explain how FreeMarker integrates with Spring MVC? How do you use a custom TemplateTransformModel to post-process a template's output? Which is generally the better choice for a new project today, FreeMarker or Velocity, and why? What is the difference between FreeMarker's #switch/#case and a chain of #if/#elseif directives?
Show more question and Answers...


Comments & Discussions