# ColdFusion Version Compatibility Matrix

Reference compatto per scegliere quali famiglie di controlli includere quando il target e' ColdFusion 2025. Non sostituisce le fonti primarie Adobe o TESISQUARE.

## Matrice cumulativa

| Source CF | Controlli cumulativi da considerare |
| :--- | :--- |
| 8/9 | legacy CF10+ + 2016 + 2018 + 2021 + 2023 + 2025 |
| 10/11 | post-CF10 + 2016 + 2018 + 2021 + 2023 + 2025 |
| 2016 | 2018 + 2021 + 2023 + 2025 |
| 2018 | 2021 + 2023 + 2025 |
| 2021 | 2023 + 2025 |
| 2023 | 2025 |

La matrice indica cosa cercare, non cosa sostituire automaticamente. Una regola piu' recente puo' rendere obsoleta una remediation storica.

## Regole CF2025 ad alta priorita'

| ID | Pattern / rischio | Provenienza | Remediation |
| :--- | :--- | :--- | :--- |
| CF25-001 | `HTMLEditFormat()` | Adobe + TESISQUARE | `EncodeForHTML()`, safe solo su call site semplice |
| CF25-002 | `cfheader statusText` | Adobe + TESISQUARE | rimuovere attributo preservando il resto |
| CF25-003 | `ParameterExists()` | Adobe + TESISQUARE | `IsDefined()` dopo review semantica |
| CF25-004 | `new query()` | Adobe + TESISQUARE | semantic rewrite a `QueryExecute()` |
| CF25-005 | `new http()` | TESISQUARE + Adobe deprecation | semantic rewrite a `cfhttp()` |
| TS25-006 | `generateSecretKey("AES")` | TESISQUARE | key length esplicita dopo compatibility review |
| TS25-007 | `URLEncodedFormat()` | TESISQUARE + Adobe recommendation | `EncodeForURL()` con review argomenti |
| CF25-008 | `CFMX_COMPAT` | Adobe | blocker: scegliere algoritmo esplicito |
| CF25-009 | `ThreadTerminate` | Adobe | blocker: ridisegnare lifecycle/cancellation |
| CF25-010 | `cfschedule.requestTimeOut` | Adobe | blocker/config review |

## Regole cumulative TESISQUARE incluse nello scanner

| ID | Pattern / rischio | Nota |
| :--- | :--- | :--- |
| TS23-011 | `org.apache.poi.hssf.usermodel.HSSFDateUtil` | usare `org.apache.poi.ss.usermodel.DateUtil`, review `.init()` |
| TS16-012 | alias `cfsqltype` legacy/errati | scegliere il tipo supportato in base a valore e colonna |
| TS16-013 | `CF_SQL_DATETIME` | candidato a `CF_SQL_TIMESTAMP` dopo review |
| TS16-014 | `cf_sql_string` | candidato a `cf_sql_varchar` dopo review |
| TS21-015 | `hash()` a un argomento | rendere esplicito l'algoritmo dopo compatibility review |
| TS25-016 | wrapper `HTMLEditFormat(maskParse(...))` in `header.cfc` | usare `escapeSingleItems=true`; commit Platform `cc81d0e7` |
| TS25-017 | contratto item-level di `simpleTextParser` / `maskParse` | propagare `encodeItems` / `escapeSingleItems`; commit Platform `cc81d0e7` |
| TS25-018 | encoding indiscriminato in `xgrid_common.cfc` | limitare `EncodeForHTML` a metadata `varchar`/`nvarchar`; commit Platform `d07112fd` |

## Regole interne Platform verificate

I diff primari sono stati verificati nel monorepo Platform:

- `cc81d0e79616006764fd5d786f1cc02290c48023` per `header.cfc` e `strutil.cfc`;
- `d07112fdd2abb9437271331130e85ad659765514` per `xgrid_common.cfc`.

Lo scanner limita la detection ai path canonici e classifica i finding come `CONTEXTUAL_FIX`. Non generalizzare questi interventi a file omonimi esterni a Platform e non convertirli in autofix.

## Conflitti noti tra guida legacy e target CF2025

### Axis1

Le guide storiche possono indicare Axis1 come configurabile. Adobe lo rimuove in CF2025. Sul target CF2025 la remediation storica e' superseded e deve diventare blocker/migrazione del servizio.

### Scheduler timeout

Le guide storiche possono includere workaround basati su timeout dello scheduler. Adobe rimuove `cfschedule.requestTimeOut` in CF2025. Verifica il design corrente e non reintrodurre l'attributo.

## Fonti Adobe ufficiali

- Deprecated Features: https://helpx.adobe.com/coldfusion/deprecated-features.html
- HTMLEditFormat: https://helpx.adobe.com/coldfusion/cfml-reference/coldfusion-functions/functions-h-im/htmleditformat.html
- cfheader: https://helpx.adobe.com/coldfusion/cfml-reference/coldfusion-tags/tags-g-h/cfheader.html
- ParameterExists: https://helpx.adobe.com/coldfusion/cfml-reference/coldfusion-functions/functions-m-r/parameterexists.html
- Script Functions Implemented as CFCs: https://helpx.adobe.com/coldfusion/cfml-reference/script-functions-implemented-as-cfcs/function-summary.html
- URLEncodedFormat: https://helpx.adobe.com/coldfusion/cfml-reference/coldfusion-functions/functions-t-z/urlencodedformat.html
- EncodeForURL: https://helpx.adobe.com/coldfusion/cfml-reference/coldfusion-functions/functions-e-g/encodeforurl.html
- GenerateSecretKey: https://helpx.adobe.com/coldfusion/cfml-reference/coldfusion-functions/functions-e-g/generatesecretkey.html

## Fonti TESISQUARE di questa estensione

- snapshot Platform 8.0 `breaking changes`, sezione ColdFusion compatibility, fornito durante l'analisi;
- `proc0064_app_to_cf10-_migration_guide.md`, fornito durante l'analisi;
- analisi tecnica: `docs/analisi-tecniche/analisi-tecnica-integrazione-coldfusion-2025.md`.
