This is an automated email from the ASF dual-hosted git repository.
lukaszlenart pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/struts-site.git
The following commit(s) were added to refs/heads/main by this push:
new 259cb3780 WW-5669 Document the CSP nonce source setting (#332)
259cb3780 is described below
commit 259cb3780c8bc760a77a31763a467d352160c1d9
Author: Lukasz Lenart <[email protected]>
AuthorDate: Sun Sep 13 10:38:44 2026 +0200
WW-5669 Document the CSP nonce source setting (#332)
* WW-5669 docs(core): document the CSP nonce source setting
The setting was never on the CSP interceptor page under either name. Adds
a "Nonce source" section with the working name struts.csp.nonce.source,
and a note that struts.csp.nonceSource (shipped inert in
default.properties since 6.8.0) is honoured as a deprecated alias from
6.12.0 / 7.4.0, so existing configs carrying it switch to request-scoped
nonces on upgrade.
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
* WW-5669 docs(core): the alias lands in 7.4.0 only
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
---------
Co-authored-by: Claude Opus 5 (1M context) <[email protected]>
---
source/core-developers/csp-interceptor.md | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
diff --git a/source/core-developers/csp-interceptor.md
b/source/core-developers/csp-interceptor.md
index d0d35f7d8..0ec723d83 100644
--- a/source/core-developers/csp-interceptor.md
+++ b/source/core-developers/csp-interceptor.md
@@ -38,6 +38,25 @@ implement CSP in a highly secure fashion.
to allow to define a custom CPS settings. It's alternative approach of using
the [CspSettingsAware](#action-aware)
interface below (since Struts 6.5.0).
+## Nonce source
+
+The interceptor generates a fresh nonce on every request and has to keep it
somewhere the tags can read it back from
+when the page renders. By default that is the HTTP session, which means CSP
headers are only added once a session
+exists. Since Struts 6.8.0 the nonce can be kept in a request attribute
instead, which suits stateless or clustered
+deployments that do not want a session created for it:
+
+```xml
+<constant name="struts.csp.nonce.source" value="request"/>
+```
+
+Accepted values are `session` (the default) and `request`.
+
+> Note: releases before 7.4.0 shipped `default.properties` with this setting
under the name `struts.csp.nonceSource`,
+> which the framework never read — configuring it had no effect and the nonce
always stayed in the session. Since
+> 7.4.0 that name is honoured as well, so a configuration carrying
`struts.csp.nonceSource=request` switches to
+> request-scoped nonces on upgrade. The camel-case name is deprecated and logs
a warning; rename it to
+> `struts.csp.nonce.source`.
+
## Report action
To receive reports about violations against CSP an abstract `CspReportAction`
action has been created, which you can