This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/struts-site.git


The following commit(s) were added to refs/heads/asf-staging by this push:
     new 7a93372b5 Updates stage by Jenkins
7a93372b5 is described below

commit 7a93372b5f7ddb9fd9be44b0e327f8a25515d696
Author: jenkins <[email protected]>
AuthorDate: Sun Sep 13 08:19:56 2026 +0000

    Updates stage by Jenkins
---
 content/core-developers/csp-interceptor.html | 21 +++++++++++++++++++++
 1 file changed, 21 insertions(+)

diff --git a/content/core-developers/csp-interceptor.html 
b/content/core-developers/csp-interceptor.html
index 671e36602..f3b3d6df1 100644
--- a/content/core-developers/csp-interceptor.html
+++ b/content/core-developers/csp-interceptor.html
@@ -157,6 +157,7 @@
 <ul id="markdown-toc">
   <li><a href="#description" id="markdown-toc-description">Description</a></li>
   <li><a href="#parameters" id="markdown-toc-parameters">Parameters</a></li>
+  <li><a href="#nonce-source" id="markdown-toc-nonce-source">Nonce 
source</a></li>
   <li><a href="#report-action" id="markdown-toc-report-action">Report 
action</a></li>
   <li><a href="#action-aware" id="markdown-toc-action-aware">Action 
aware</a></li>
   <li><a href="#examples" id="markdown-toc-examples">Examples</a></li>
@@ -190,6 +191,26 @@ to allow to define a custom CPS settings. It’s alternative 
approach of using t
 interface below (since Struts 6.5.0).</li>
 </ul>
 
+<h2 id="nonce-source">Nonce source</h2>
+
+<p>The interceptor generates a fresh nonce on every request and has to keep it 
somewhere the tags can read it back from
+when the page renders. By default that is the HTTP session, which means CSP 
headers are only added once a session
+exists. Since Struts 6.8.0 the nonce can be kept in a request attribute 
instead, which suits stateless or clustered
+deployments that do not want a session created for it:</p>
+
+<div class="language-xml highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code><span class="nt">&lt;constant</span> <span 
class="na">name=</span><span class="s">"struts.csp.nonce.source"</span> <span 
class="na">value=</span><span class="s">"request"</span><span 
class="nt">/&gt;</span>
+</code></pre></div></div>
+
+<p>Accepted values are <code class="language-plaintext 
highlighter-rouge">session</code> (the default) and <code 
class="language-plaintext highlighter-rouge">request</code>.</p>
+
+<blockquote>
+  <p>Note: releases before 6.12.0 and 7.4.0 shipped <code 
class="language-plaintext highlighter-rouge">default.properties</code> with 
this setting under the name
+<code class="language-plaintext 
highlighter-rouge">struts.csp.nonceSource</code>, which the framework never 
read — configuring it had no effect and the nonce always stayed
+in the session. Since 6.12.0 and 7.4.0 that name is honoured as well, so a 
configuration carrying
+<code class="language-plaintext 
highlighter-rouge">struts.csp.nonceSource=request</code> switches to 
request-scoped nonces on upgrade. The camel-case name is deprecated
+and logs a warning; rename it to <code class="language-plaintext 
highlighter-rouge">struts.csp.nonce.source</code>.</p>
+</blockquote>
+
 <h2 id="report-action">Report action</h2>
 
 <p>To receive reports about violations against CSP an abstract <code 
class="language-plaintext highlighter-rouge">CspReportAction</code> action has 
been created, which you can

Reply via email to