This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/struts-site.git


The following commit(s) were added to refs/heads/asf-site by this push:
     new decb431cb Automatic Site Publish by Buildbot
decb431cb is described below

commit decb431cb364c2e9d8e158cf19da701104695c03
Author: buildbot <[email protected]>
AuthorDate: Fri Sep 11 04:01:23 2026 +0000

    Automatic Site Publish by Buildbot
---
 .../struts-parameter-annotation.html               | 26 +++++++++++++++++++++-
 1 file changed, 25 insertions(+), 1 deletion(-)

diff --git a/output/core-developers/struts-parameter-annotation.html 
b/output/core-developers/struts-parameter-annotation.html
index a55c7b7c6..9bf7b6b09 100644
--- a/output/core-developers/struts-parameter-annotation.html
+++ b/output/core-developers/struts-parameter-annotation.html
@@ -157,6 +157,7 @@
 <ul id="markdown-toc">
   <li><a href="#where-authorization-applies" 
id="markdown-toc-where-authorization-applies">Where authorization applies</a>   
 <ul>
       <li><a href="#creator-bound-properties" 
id="markdown-toc-creator-bound-properties">Creator-bound properties</a></li>
+      <li><a href="#jackson-any-setters" 
id="markdown-toc-jackson-any-setters">Jackson any-setters</a></li>
     </ul>
   </li>
   <li><a href="#modeldriven-actions" 
id="markdown-toc-modeldriven-actions">ModelDriven actions</a></li>
@@ -187,7 +188,10 @@ channel that can populate an action from request data:</p>
 action chaining (opt-in via <code class="language-plaintext 
highlighter-rouge">struts.chaining.requireAnnotations</code>).</li>
   <li><a href="cookie-interceptor.html">Cookie Interceptor</a> — cookie 
values.</li>
   <li><a href="../../plugins/json">JSON</a> and <a 
href="../../plugins/rest">REST</a> plugins — per-property
-authorization performed during deserialization, so unauthorized fields are 
never set.</li>
+authorization performed during deserialization, so an unauthorized property is 
not set on
+the target object. This covers the properties the deserializer binds 
<strong>by name</strong>; in the
+REST plugin a Jackson any-setter is a separate sink that is not covered — see
+<a href="#jackson-any-setters">Jackson any-setters</a> below.</li>
 </ul>
 
 <h3 id="creator-bound-properties">Creator-bound properties</h3>
@@ -208,6 +212,26 @@ object under construction is dropped instead of failing 
the request.</p>
 the same way as any nested object: <code class="language-plaintext 
highlighter-rouge">@StrutsParameter(depth = ...)</code> on the getter that 
reaches them, or a <code class="language-plaintext 
highlighter-rouge">ModelDriven</code>
 model. Otherwise those values silently stop arriving.</p>
 
+<h3 id="jackson-any-setters">Jackson any-setters</h3>
+
+<p>A class that declares a Jackson any-setter — <code 
class="language-plaintext highlighter-rouge">@JsonAnySetter</code> on a method, 
on a field, or on a
+<code class="language-plaintext highlighter-rouge">@JsonCreator</code> 
parameter — tells Jackson to route <strong>every otherwise-unknown key</strong> 
in the request body
+to that member. The REST plugin’s authorization wrapper covers the properties 
Jackson binds by name;
+an any-setter is a separate sink and is not wrapped. Keys arriving through it 
are therefore set
+without an <code class="language-plaintext 
highlighter-rouge">@StrutsParameter</code> check, even with <code 
class="language-plaintext 
highlighter-rouge">struts.parameters.requireAnnotations</code> enabled, and
+even in the same request in which an ordinary unannotated setter on the same 
class is correctly
+rejected.</p>
+
+<p>Two limits are worth knowing. An any-setter beneath an <strong>unauthorized 
parent</strong> is still unreachable:
+the parent is rejected first and its whole subtree is skipped. And <code 
class="language-plaintext highlighter-rouge">@JsonUnwrapped</code> is a named
+property, so it is unaffected by this.</p>
+
+<p class="alert alert-warning">Declaring an any-setter on a class bound from a 
REST request body is the application accepting
+arbitrary names and values off the wire — the same decision as binding a <code 
class="language-plaintext highlighter-rouge">Map</code>, and it deserves the
+same scrutiny. Where that is not what you want, do not declare one on a 
request-bound class, or
+narrow what the method accepts before storing it. Tracked as
+<a href="https://issues.apache.org/jira/browse/WW-5712";>WW-5712</a>.</p>
+
 <h2 id="modeldriven-actions">ModelDriven actions</h2>
 
 <p>When an action implements <code class="language-plaintext 
highlighter-rouge">ModelDriven</code> and the <a 
href="model-driven-interceptor.html">Model Driven

Reply via email to