Docs & Rules

apache/wicketGitHubLast refreshed Oct 3, 2026

This is a public, read-only report. Striff reads this repository's docs, turns each sentence that makes a claim about the code into a rule, and checks the rule against the code on the default branch. How this works

2 names in these docs no longer match the code.

masteree62ec8listed 8h ago

Is this yours? Install to manage it

Once installed, Striff checks every pull request.

62
62
62
62
62
21
16
5
11
2
4
5
4
4
7
2
5
9
9
1
1
7
1
6
1 stale
1
1
1 stale
1
1
31 docs, listed Oct 3
apache/wicketOpen repository

Names these docs write that the code no longer has2

Each sentence below names a type the default branch doesn't declare, or declares somewhere else. Edit the doc so it matches the code, or bring the type back.

  • GoneResourceIsolationPolicy
    To further help against this kind of vulnerability Wicket provides _ResourceIsolationRequestCycleListener_ - a _IRequestCycleListener_ that uses __IResourceIsolationPolicy__ objects to decide whether to allow or reject cross-origin requests.

    The repository once held wicket-core/src/main/java/org/apache/wicket/protocol/http/ResourceIsolationPolicy.java. It doesn't now. Closest names there: IResourceIsolationPolicy, OriginResourceIsolationPolicy, FetchMetadataResourceIsolationPolicy.

    View on GitHub

  • GoneAnnotSpringInjector
    InjectorHolder.setInjector(new AnnotSpringInjector(new ContextLocator(), wrapInProxies));

    The repository once held wicket-spring/src/main/java/org/apache/wicket/spring/injection/annot/AnnotSpringInjector.java. It doesn't now. Closest name there: SpringComponentInjector.

    View on GitHub

apache/wicket — documented rules

62 of 62 rules, printed October 3, 2026.

The sentence in your docs
Read Oct 2
These components come with a version of methods onSubmit, onError and onAfterSubmit that takes in input also an instance of _AjaxRequestTarget_.
AjaxSubmitLink has an onSubmit method
Holds
Read Oct 2
These components come with a version of methods onSubmit, onError and onAfterSubmit that takes in input also an instance of _AjaxRequestTarget_.
AjaxSubmitLink has an onError method
Holds
Read Oct 2
These components come with a version of methods onSubmit, onError and onAfterSubmit that takes in input also an instance of _AjaxRequestTarget_.
AjaxSubmitLink has an onAfterSubmit method
Holds
Read Oct 2
These components come with a version of methods onSubmit, onError and onAfterSubmit that takes in input also an instance of _AjaxRequestTarget_.
AjaxButton has an onSubmit method
Holds
Read Oct 2
These components come with a version of methods onSubmit, onError and onAfterSubmit that takes in input also an instance of _AjaxRequestTarget_.
AjaxButton has an onError method
Holds
Read Oct 2
These components come with a version of methods onSubmit, onError and onAfterSubmit that takes in input also an instance of _AjaxRequestTarget_.
AjaxButton has an onAfterSubmit method
Holds
Read Oct 2
Base component AjaxEditableLabel exposes the following set of AJAX-aware methods that can be overridden: *onEdit(AjaxRequestTarget target)*: called when user clicks on component.
AjaxEditableLabel has an onEdit method
Holds
Read Oct 2
*onSubmit(AjaxRequestTarget target)*: called when the value has been successfully updated with the new input.
AjaxEditableLabel has an onSubmit method
Holds
Read Oct 2
When using AutoCompleteTextField we are required to implement its abstract method getChoices(String input) where the input parameter is the current input of the component. This method returns an iterator over the suggestions that will be displayed as a drop-down menu: image::./img/autocomplete-example-screenshot.png[]
AutoCompleteTextField is in org.apache.wicket.extensions.ajax.markup.html.autocomplete
Holds
Read Oct 2
When using AutoCompleteTextField we are required to implement its abstract method getChoices(String input) where the input parameter is the current input of the component.
AutoCompleteTextField has a getChoices method
HoldsPR #1569 · Oct 2
Read Oct 2
Class _org.apache.wicket.extensions.ajax.markup.html.modal.ModalDialog_ is an implementation of a http://en.wikipedia.org/wiki/Modal_dialog[modal dialog] based on AJAX:
ModalDialog is in org.apache.wicket.extensions.ajax.markup.html.modal
Holds
Read Oct 2
To display a modal dialog we must call its method _open(AjaxRequestTarget target)_.
ModalDialog has an open method
HoldsPR #1569 · Oct 2
Read Oct 2
The modal dialog can be closed from code using its method _close(AjaxRequestTarget target)_.
ModalDialog has a close method
HoldsPR #1569 · Oct 2
Read Oct 2
Wicket comes with a built-in implementation of ITreeProvider called TreeModelProvider that works with the same tree model and nodes used by Swing component _javax.swing.JTree_.
TreeModelProvider implements ITreeProvider
HoldsPR #1569 · Oct 2
Read Oct 2
This provider wraps each node in a model invoking its abstract method model.
TreeModelProvider has a model method
HoldsPR #1569 · Oct 2
Read Oct 2
For the second goal (auto select/unselect children and ancestor nodes) we can use _CheckedFolder_'s callback method onUpdate(AjaxRequestTarget) that is invoked after a checkbox is clicked and its value has been updated.
CheckedFolder has an onUpdate method
HoldsPR #1569 · Oct 2
Read Oct 2
All the following behaviors are inside package _org.apache.wicket.ajax_.
AjaxEventBehavior is in org.apache.wicket.ajax
HoldsPR #1569 · Oct 2
Read Oct 2
All the following behaviors are inside package _org.apache.wicket.ajax_.
AjaxFormComponentUpdatingBehavior is in org.apache.wicket.ajax
HoldsPR #1569 · Oct 2
Read Oct 2
All the following behaviors are inside package _org.apache.wicket.ajax_.
AjaxFormSubmitBehavior is in org.apache.wicket.ajax
HoldsPR #1569 · Oct 2
Read Oct 2
All the following behaviors are inside package _org.apache.wicket.ajax_.
AjaxFormChoiceComponentUpdatingBehavior is in org.apache.wicket.ajax
HoldsPR #1569 · Oct 2
Read Oct 2
All the following behaviors are inside package _org.apache.wicket.ajax_.
AbstractAjaxTimerBehavior is in org.apache.wicket.ajax
HoldsPR #1569 · Oct 2
Read Oct 2
Wicket provides a special version of the Form component called StatelessForm which is stateless by default (i.e its method getStatelessHint() returns true), hence it's an ideal solution when we want to build a stateless page with a form.
StatelessForm extends Form
Holds
Read Oct 2
Wicket provides a special version of the Form component called StatelessForm which is stateless by default (i.e its method getStatelessHint() returns true), hence it's an ideal solution when we want to build a stateless page with a form.
StatelessForm has a getStatelessHint method
Holds
Read Oct 2
They are CheckboxMultipleChoiceSelector and CheckBoxSelector classes, both inside package _org.apache.wicket.markup.html.form_.
CheckboxMultipleChoiceSelector is in org.apache.wicket.markup.html.form
Holds
Read Oct 2
They are CheckboxMultipleChoiceSelector and CheckBoxSelector classes, both inside package _org.apache.wicket.markup.html.form_.
CheckBoxSelector is in org.apache.wicket.markup.html.form
Holds
Read Oct 2
They are CheckboxMultipleChoiceSelector and CheckBoxSelector classes, both inside package _org.apache.wicket.markup.html.form_. The difference between these two components is that the first works with an instance of CheckBoxMultipleChoice while the second takes in input a list of CheckBox objects:
CheckboxMultipleChoiceSelector depends on CheckBoxMultipleChoice
Holds
Read Oct 2
They are CheckboxMultipleChoiceSelector and CheckBoxSelector classes, both inside package _org.apache.wicket.markup.html.form_. The difference between these two components is that the first works with an instance of CheckBoxMultipleChoice while the second takes in input a list of CheckBox objects:
CheckBoxSelector depends on CheckBox
Holds
Read Oct 2
The component that is responsible for converting input is the FormComponent itself with its convertInput() method.
FormComponent has a convertInput method
Holds
Read Oct 2
This parameter can be explicitly set with method setType(Class<?> type):
FormComponent has a setType method
Holds
Read Oct 2
To get a converter for a specific type we must call method getConverter(Class<C> type) on the interface IConverterLocator returned by Application's method getConverterLocator():
IConverterLocator has a getConverter method
Holds
Read Oct 2
To get a converter for a specific type we must call method getConverter(Class<C> type) on the interface IConverterLocator returned by Application's method getConverterLocator():
Application has a getConverterLocator method
Holds
Read Oct 2
If we want to add more converters to our application, we can override Application's method newConverterLocator which is used by application class to build its converter locator.
Application has a newConverterLocator method
Holds
Read Oct 2
We must bind this component to the <input> tag with the attribute type set to "text" PasswordTextField is a subtype of TextField and it must be used with an <input> tag with the attribute type set to "password".
PasswordTextField extends TextField
HoldsPR #1569 · Oct 2
Read Oct 2
Class FormComponent provides method _setRequired(boolean required)_ to change this behavior.
FormComponent has a setRequired method
HoldsPR #1569 · Oct 2
Read Oct 2
Both methods are defined in class Component (see class diagram from illustration 9.1).
Component has a setDefaultModelObject method
Holds
Read Oct 2
Both methods are defined in class Component (see class diagram from illustration 9.1).
Component has a getDefaultModelObject method
Holds
Read Oct 2
RefreshingView defines abstract methods populateItem(Item) and getItemModels().
RefreshingView has a populateItem method
Holds
Read Oct 2
RefreshingView defines abstract methods populateItem(Item) and getItemModels().
RefreshingView has a getItemModels method
Holds
Read Oct 2
Wicket already provides implementations of IDataProvider to work with a List as data source (ListDataProvider) and to support data sorting (SortableDataProvider).
ListDataProvider implements IDataProvider
Holds
Read Oct 2
Wicket already provides implementations of IDataProvider to work with a List as data source (ListDataProvider) and to support data sorting (SortableDataProvider).
SortableDataProvider implements IDataProvider
Holds
Read Oct 2
DataView comes with abstract method populateItem(Item) that must be implemented to configure children components.
DataView has a populateItem method
Holds
Read Oct 2
Wicket provides also component PageableListView which is a subclass of ListView that implements interface IPageable, hence it can be considered a pageable repeater even if it doesn't use interface IDataProvider as data source.
PageableListView extends ListView
Holds
Read Oct 2
Wicket provides also component PageableListView which is a subclass of ListView that implements interface IPageable, hence it can be considered a pageable repeater even if it doesn't use interface IDataProvider as data source.
PageableListView implements IPageable
Holds
Read Oct 2
As we have mentioned talking about _RequestCycle_, also class Session provides a static _get()_ method which returns the session associated to the current thread.
Session has a get method
Holds
Read Oct 2
*setAttribute(String name, Serializable value):* creates an attribute identified by the given name.
Session has a setAttribute method
HoldsPR #1569 · Oct 2
Read Oct 2
*getAttribute(String name):* returns the value of the attribute identified by the given name, or _null_ if the name does not correspond to any attribute.
Session has a getAttribute method
HoldsPR #1569 · Oct 2
Read Oct 2
*removeAttribute(String name):* removes the attribute identified by the given name.
Session has a removeAttribute method
HoldsPR #1569 · Oct 2
Read Oct 2
To know if the current session is temporary, we can use the isTemporary() method:
Session has an isTemporary method
HoldsPR #1569 · Oct 2
Read Oct 2
If a session is not temporary (i.e. it is permanent), it's identified by an unique id which can be read calling the getId() method.
Session has a getId method
Holds
Read Oct 2
In the snippet above we have also bolded Session's bind() method which converts temporary session into a permanent one.
Session has a bind method
Holds
Read Oct 2
To be sure that a permanent session will be discarded at the end of the current request, class Session provides the invalidate() method.
Session has an invalidate method
HoldsPR #1569 · Oct 2
Read Oct 2
If we want to immediately invalidate a given session without waiting for the current request to complete, we can invoke the invalidateNow() method.
Session has an invalidateNow method
HoldsPR #1569 · Oct 2
Read Oct 2
The only method defined in this interface is _renderHead(IHeaderResponse response)_ where _IHeaderResponse_ is an interface which defines method _render(HeaderItem item)_ to write static resources or free-form text into the header section of the page.
IHeaderResponse has a render method
Holds
Read Oct 2
Class AuthenticatedWebSession comes with the following set of public methods to manage user authentication:
AuthenticatedWebSession is in org.apache.wicket.authroles.authentication
Holds
Read Oct 2
Inside _IAuthorizationStrategy_ we can also find a default implementation of the interface (called ALLOW_ALL) that allows everyone to instantiate every component and perform every possible action on it.
IAuthorizationStrategy has ALLOW_ALL
HoldsPR #1569 · Oct 2
Read Oct 2
Abstract class SimplePageAuthorizationStrategy (in package _org.apache.wicket.authorization.strategies.page_) is a strategy that checks user authorizations calling abstract method _isAuthorized_ only for those pages that are subclasses of a given supertype.
SimplePageAuthorizationStrategy is declared abstract, and SimplePageAuthorizationStrategy is in org.apache.wicket.authorization.strategies.page, and SimplePageAuthorizationStrategy has an isAuthorized method
Holds
Read Oct 2
At the end of <<security.adoc#_authentication,paragraph 22.1>> we have introduced AbstractAuthenticatedWebSession's method getRoles() which is provided to support role-based authorization returning the set of roles granted to the current user.
AbstractAuthenticatedWebSession has a getRoles method
HoldsPR #1569 · Oct 2
Read Oct 2
Class _Roles_ already defines roles Roles.USER and Roles.ADMIN.
Roles has USER and ADMIN
HoldsPR #1569 · Oct 2
Read Oct 2
The session class in the following example returns a custom “SIGNED_IN” role for every authenticated user and it adds an Roles.ADMIN role if username is equal to superuser:
Roles is in org.apache.wicket.authroles.authorization.strategies.role
Holds
Read Oct 2
The class defines a set of static methods authorize that can be used to specify which roles are allowed to instantiate a component and which roles can perform a given action on a component.
MetaDataRoleAuthorizationStrategy has an authorize method
HoldsPR #1569 · Oct 2
Read Oct 2
Usually, we will use our application class as _WebApplication_, but we can also decide to build WicketTester invoking its no-argument constructor and letting it automatically build a mock web application (an instance of class _org.apache.wicket.mock.MockApplication_).
WicketTester depends on WebApplication
HoldsPR #1569 · Oct 2
Read Oct 2
Now to use a custom mapper context in our application we must override the newMapperContext() method declared in the Application class and make it return our custom implementation of IMapperContext:
Application has a newMapperContext method
Holds
62 rules from 14 docs

See these where the change is. The browser extension puts a pull request's doc findings, and a diagram of what it changed, on the GitHub page itself, so the code and what your docs say about it are side by side.