This is an automated email from the ASF dual-hosted git repository.

lukaszlenart pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/struts-site.git


The following commit(s) were added to refs/heads/main by this push:
     new 259cb3780 WW-5669 Document the CSP nonce source setting (#332)
259cb3780 is described below

commit 259cb3780c8bc760a77a31763a467d352160c1d9
Author: Lukasz Lenart <[email protected]>
AuthorDate: Sun Sep 13 10:38:44 2026 +0200

    WW-5669 Document the CSP nonce source setting (#332)
    
    * WW-5669 docs(core): document the CSP nonce source setting
    
    The setting was never on the CSP interceptor page under either name. Adds
    a "Nonce source" section with the working name struts.csp.nonce.source,
    and a note that struts.csp.nonceSource (shipped inert in
    default.properties since 6.8.0) is honoured as a deprecated alias from
    6.12.0 / 7.4.0, so existing configs carrying it switch to request-scoped
    nonces on upgrade.
    
    Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
    
    * WW-5669 docs(core): the alias lands in 7.4.0 only
    
    Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
    
    ---------
    
    Co-authored-by: Claude Opus 5 (1M context) <[email protected]>
---
 source/core-developers/csp-interceptor.md | 19 +++++++++++++++++++
 1 file changed, 19 insertions(+)

diff --git a/source/core-developers/csp-interceptor.md 
b/source/core-developers/csp-interceptor.md
index d0d35f7d8..0ec723d83 100644
--- a/source/core-developers/csp-interceptor.md
+++ b/source/core-developers/csp-interceptor.md
@@ -38,6 +38,25 @@ implement CSP in a highly secure fashion.
   to allow to define a custom CPS settings. It's alternative approach of using 
the [CspSettingsAware](#action-aware) 
   interface below (since Struts 6.5.0).
 
+## Nonce source
+
+The interceptor generates a fresh nonce on every request and has to keep it 
somewhere the tags can read it back from
+when the page renders. By default that is the HTTP session, which means CSP 
headers are only added once a session
+exists. Since Struts 6.8.0 the nonce can be kept in a request attribute 
instead, which suits stateless or clustered
+deployments that do not want a session created for it:
+
+```xml
+<constant name="struts.csp.nonce.source" value="request"/>
+```
+
+Accepted values are `session` (the default) and `request`.
+
+> Note: releases before 7.4.0 shipped `default.properties` with this setting 
under the name `struts.csp.nonceSource`,
+> which the framework never read — configuring it had no effect and the nonce 
always stayed in the session. Since
+> 7.4.0 that name is honoured as well, so a configuration carrying 
`struts.csp.nonceSource=request` switches to
+> request-scoped nonces on upgrade. The camel-case name is deprecated and logs 
a warning; rename it to
+> `struts.csp.nonce.source`.
+
 ## Report action
 
 To receive reports about violations against CSP an abstract `CspReportAction` 
action has been created, which you can

Reply via email to