Upgrade to Wicket 9

In version 15 of Bloomreach Content, Wicket has been upgraded from version 7.18.0 to 9.7.0. The primary motivation for this change is Wicket 9's built-in support for Content Security Policy (CSP), which enhances application security.

This page outlines the impact of the Wicket upgrade on community plugins and custom Wicket code.

Upgrade to Wicket v8

Before upgrading to Wicket 9, update your Wicket codebase to the latest release of Wicket 8 (v8.9.0).

Refer to the full migration guide: https://cwiki.apache.org/confluence/display/WICKET/Migration+to+Wicket+8.0

Key changes to address when migrating to Wicket 8:

  • Wicket 6 deprecated JavaScript event names prefixed with "on" (such as “onclick”, “onblur”). Use the short form without the "on" prefix, such as “click” or “blur”. In Wicket 8, the old event names are no longer supported.

  • RequestCycle.find(Class<T>) now returns an Optional<T>. If your code retrieves the current AjaxRequestTarget as shown below, review the logic:

    if (RequestCycle.get().find(AjaxRequestTarget.class) == null) { // Executed for non-Ajax requests in Wicket 7 // Never executed in Wicket 8 ... }
  • IModel is now a @FunctionalInterface. You can define a read-only IModel using a lambda expression:

    final IModel<String> nameModel = () -> "Bloomreach";

Upgrade to Wicket v9

After migrating to Wicket 8, upgrade your Wicket code to version 9.7.0.

Refer to the full migration guide: https://cwiki.apache.org/confluence/display/WICKET/Migration+to+Wicket+9.0

Key changes to address when migrating to Wicket 9:

Deprecation of org.apache.wicket.util.time.** Classes

Wicket previously provided custom classes for handling time entities such as durations and instants. These have been replaced with standard Java 8 classes: java.time.Duration and java.time.Instant. Update your code to use the java.time.* classes.

The previous Wicket-specific duration format (e.g., "1 second", "2 days") is no longer supported. Use the ISO-8601 duration format instead.

For backward compatibility, the old format is still accepted, but a WARNING is logged. Update your configurations to the new format.

Browser User Agent Detection

Wicket's built-in user-agent detection has been removed. User agent detection now uses the YAUAA library. Access user agent information as follows:

final Main main = (Main) Main.get(); final WebClientInfo clientInfo = WebSession.get().getClientInfo(); final UserAgent.ImmutableUserAgent userAgent = main.getUserAgentAnalyzer().parse(clientInfo.getUserAgent());

Parsing the user-agent string is resource-intensive. Only the "agent-name" and "agent-major-version" fields are extracted by default.

JUnit 5

Wicket test classes now depend on JUnit 5.x instead of 4.x. If your test code extends Wicket test classes and you are still running tests with JUnit 4, you must manually invoke super.commonBefore() from your @Before method:

@Before public void beForeEach() { // Manually call JUnit 5 annotated before methods super.commonBefore(); }

Wicket Ajax Debug Window

The Wicket Ajax debug window has been removed. JavaScript debug messages are now logged to the browser console. By default, Wicket JavaScript debug logging is disabled to avoid cluttering the console. To enable debug logging, start the CMS with the CLI flag -Dwicket.js.debug=true. This also requires the cargo.dev Maven profile.

Page Serialization Disabled in DEVELOPMENT Mode

Page serialization is now disabled in DEVELOPMENT mode, consistent with PRODUCTION mode. This change does not affect application code and may improve performance during development.

Content Security Policy

By default, both the CMS and the NavApp application now enforce a Content Security Policy (CSP). The current policy is not strict due to dependencies on legacy JavaScript libraries that require certain "unsafe" features. Future releases will address these dependencies to further restrict the CSP.

The most significant CSP rules define which domains are permitted in elements such as <iframe>, <script>, and <style>. This is especially relevant for OpenUI extensions. At this time, you must manually add allowed domains to the CSP configuration in the repository at:

/hippo:configuration/hippo:modules/application-settings/hippo:moduleconfig/content-security-policy

The following CSP directives are supported for configuration:

  • connect-src
  • frame-ancestors
  • frame-src
  • img-src
  • script-src
  • style-src
  • font-src
Share Feedback
Page: /about/upgrade-guides/archived-upgrades-pre-v15/v14-v15/upgrade-to-wicket-9
Section: About
Category *
1. Upgrade to Wicket 9 | Bloomreach Content Documentation