This is an automated email from the ASF dual-hosted git repository. kusal pushed a change to branch release/struts-7-0-x in repository https://gitbox.apache.org/repos/asf/struts.git
from 2352c6863 [maven-release-plugin] prepare for next development iteration add f8381fbdb [maven-release-plugin] prepare release STRUTS_6_4_0 add 5e8b81b38 [maven-release-plugin] prepare for next development iteration add a6d6d918f Reverts release and fixes issue with assembly add 9c5c80d17 [maven-release-plugin] prepare release STRUTS_6_4_0 add c6d13f101 [maven-release-plugin] prepare for next development iteration add efa20426c WW-5406 Ensure Action excluded patterns are reinjected add 1a6e2fef7 WW-5406 Add deprecation JavaDocs add ed0c7287d WW-5406 Revert breaking API change add 929a60184 Merge pull request #910 from apache/WW-5406-excluded-patterns add 0074b7028 WW-5407 extend SecurityMemberAccess proxy detection to other proxies add 5f717cdb8 WW-5407 tweak ProxyUtil#isHibernateProxyMember to make it neat add 0aa2f269f Merge pull request #911 from atlassian-forks/issue/WW-5407-extend-SecurityMemberAccess-proxy-detection-to-proxies add e2ec11457 WW-5408 add option to not fallback to empty namespace when unresolved add f9f632757 /WW-5408 rename struts.disableActionConfigFallbackToEmptyNamespace to struts.actionConfig.fallbackToEmptyNamespace add 1d51d00ec WW-5408 add struts.actionConfig.fallbackToEmptyNamespace as true in default.properties add 1562e66a8 Merge pull request #912 from atlassian-forks/issue/WW-5408-add-option-to-not-fallback-to-empty-namespace-when-unresolved add ad49ea866 WW-5406 Fix injection order issue for excluded patterns add 431053679 Merge pull request #917 from apache/WW-5406-injection-order add bf5f29132 WW-5409 introduce final attribute to package element which make them unextendable add 4088f2ee2 WW-5409 update new dtd from 6.4.0 to 6.5.0 add 85783a0cc WW-5409 rename 6.5.0.dtd to 6.5.dtd to follow the naming pattern add 63267a8e0 Merge pull request #914 from atlassian-forks/issue/WW-5409-introduce-final-attribute-to-package-element add 0a720971c WW-5417 bump ognl version to fix security issue add 62b4b65c4 WW-5417 update ognl.version as 3.3.5 add f5cfb88f1 Merge pull request #915 from atlassian-forks/issue/WW-5417-bump-ongl-version-to-fix-security-issue add 100f5052d WW-5418 Forbid enums add 7e9f6e84f WW-5418 Exclude Tomcat Jasper classes add 3c21e8229 Merge pull request #916 from apache/WW-5418-struts-sec add d0204f315 Merge remote-tracking branch 'origin/master' into merge-master-to-70-2024-04-20 add 831689b26 Merge pull request #918 from apache/merge-master-to-70-2024-04-20 No new revisions were added by this update. Summary of changes: assembly/pom.xml | 2 + core/pom.xml | 9 + .../com/opensymphony/xwork2/XWorkTestCase.java | 35 ++- .../xwork2/config/entities/PackageConfig.java | 13 ++ .../xwork2/config/impl/DefaultConfiguration.java | 18 +- .../providers/XmlDocConfigurationProvider.java | 25 ++- .../xwork2/ognl/DefaultOgnlCacheFactory.java | 8 +- .../xwork2/ognl/SecurityMemberAccess.java | 36 ++-- .../com/opensymphony/xwork2/util/ProxyUtil.java | 59 ++++- .../java/org/apache/struts2/StrutsConstants.java | 3 + .../config/StrutsXmlConfigurationProvider.java | 1 + .../struts2/config/entities/ConstantConfig.java | 20 ++ .../org/apache/struts2/dispatcher/Dispatcher.java | 36 ++++ .../apache/struts2/dispatcher/InitOperations.java | 25 +-- .../struts2/dispatcher/PrepareOperations.java | 18 +- .../filter/StrutsPrepareAndExecuteFilter.java | 10 +- .../dispatcher/filter/StrutsPrepareFilter.java | 10 +- .../org/apache/struts2/default.properties | 3 + .../resources/{struts-6.0.dtd => struts-6.5.dtd} | 5 +- .../src/main/resources/struts-excluded-classes.xml | 2 + .../xwork2/config/ConfigurationTest.java | 36 ++++ .../XmlConfigurationProviderPackagesTest.java | 68 ++++-- .../xwork2/ognl/OgnlValueStackTest.java | 8 +- .../xwork2/ognl/SecurityMemberAccessTest.java | 2 +- .../apache/struts2/dispatcher/DispatcherTest.java | 26 +++ .../struts2/dispatcher/InitOperationsTest.java | 86 -------- ...rutsPrepareAndExecuteFilterIntegrationTest.java | 13 +- .../struts2/ognl/OgnlSetPossiblePropertyTest.java | 240 +++++++++++++++++++++ .../apache/struts2/views/jsp/ui/DebugTagTest.java | 22 +- .../xwork-test-package-extends-final.xml} | 14 +- .../config/providers/xwork-test-package-final.xml} | 14 +- plugins/bean-validation/pom.xml | 2 +- plugins/rest/pom.xml | 4 +- .../xwork2/ognl/SecurityMemberAccessProxyTest.java | 54 +++-- pom.xml | 2 +- 35 files changed, 688 insertions(+), 241 deletions(-) copy core/src/main/resources/{struts-6.0.dtd => struts-6.5.dtd} (96%) delete mode 100644 core/src/test/java/org/apache/struts2/dispatcher/InitOperationsTest.java create mode 100644 core/src/test/java/org/apache/struts2/ognl/OgnlSetPossiblePropertyTest.java copy core/src/test/resources/{struts-checkbox-submit-unchecked.xml => com/opensymphony/xwork2/config/providers/xwork-test-package-extends-final.xml} (66%) copy core/src/test/resources/{struts-checkbox-submit-unchecked.xml => com/opensymphony/xwork2/config/providers/xwork-test-package-final.xml} (65%)