This is an automated email from the ASF dual-hosted git repository.
asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/struts-site.git
The following commit(s) were added to refs/heads/asf-site by this push:
new e6d191502 Automatic Site Publish by Buildbot
e6d191502 is described below
commit e6d191502cbcffa71114dbd7b44ba4c196432632
Author: buildbot <[email protected]>
AuthorDate: Sun Sep 13 08:39:42 2026 +0000
Automatic Site Publish by Buildbot
---
output/core-developers/csp-interceptor.html | 21 +++++++++++++++++++++
output/core-developers/default-properties.html | 2 +-
2 files changed, 22 insertions(+), 1 deletion(-)
diff --git a/output/core-developers/csp-interceptor.html
b/output/core-developers/csp-interceptor.html
index 671e36602..b440e276b 100644
--- a/output/core-developers/csp-interceptor.html
+++ b/output/core-developers/csp-interceptor.html
@@ -157,6 +157,7 @@
<ul id="markdown-toc">
<li><a href="#description" id="markdown-toc-description">Description</a></li>
<li><a href="#parameters" id="markdown-toc-parameters">Parameters</a></li>
+ <li><a href="#nonce-source" id="markdown-toc-nonce-source">Nonce
source</a></li>
<li><a href="#report-action" id="markdown-toc-report-action">Report
action</a></li>
<li><a href="#action-aware" id="markdown-toc-action-aware">Action
aware</a></li>
<li><a href="#examples" id="markdown-toc-examples">Examples</a></li>
@@ -190,6 +191,26 @@ to allow to define a custom CPS settings. It’s alternative
approach of using t
interface below (since Struts 6.5.0).</li>
</ul>
+<h2 id="nonce-source">Nonce source</h2>
+
+<p>The interceptor generates a fresh nonce on every request and has to keep it
somewhere the tags can read it back from
+when the page renders. By default that is the HTTP session, which means CSP
headers are only added once a session
+exists. Since Struts 6.8.0 the nonce can be kept in a request attribute
instead, which suits stateless or clustered
+deployments that do not want a session created for it:</p>
+
+<div class="language-xml highlighter-rouge"><div class="highlight"><pre
class="highlight"><code><span class="nt"><constant</span> <span
class="na">name=</span><span class="s">"struts.csp.nonce.source"</span> <span
class="na">value=</span><span class="s">"request"</span><span
class="nt">/></span>
+</code></pre></div></div>
+
+<p>Accepted values are <code class="language-plaintext
highlighter-rouge">session</code> (the default) and <code
class="language-plaintext highlighter-rouge">request</code>.</p>
+
+<blockquote>
+ <p>Note: releases before 7.4.0 shipped <code class="language-plaintext
highlighter-rouge">default.properties</code> with this setting under the name
<code class="language-plaintext
highlighter-rouge">struts.csp.nonceSource</code>,
+which the framework never read — configuring it had no effect and the nonce
always stayed in the session. Since
+7.4.0 that name is honoured as well, so a configuration carrying <code
class="language-plaintext
highlighter-rouge">struts.csp.nonceSource=request</code> switches to
+request-scoped nonces on upgrade. The camel-case name is deprecated and logs a
warning; rename it to
+<code class="language-plaintext
highlighter-rouge">struts.csp.nonce.source</code>.</p>
+</blockquote>
+
<h2 id="report-action">Report action</h2>
<p>To receive reports about violations against CSP an abstract <code
class="language-plaintext highlighter-rouge">CspReportAction</code> action has
been created, which you can
diff --git a/output/core-developers/default-properties.html
b/output/core-developers/default-properties.html
index 3c8a45fb2..3dd7b87e7 100644
--- a/output/core-developers/default-properties.html
+++ b/output/core-developers/default-properties.html
@@ -536,7 +536,7 @@ struts.url.encoder=strutsUrlEncoder
struts.url.decoder=strutsUrlDecoder
### Defines source to read nonce value from, possible values are: request,
session
-struts.csp.nonceSource=session
+# struts.csp.nonce.source=session
### Maximum size, in characters, of a CSP violation report accepted by
CspReportAction
### Reports larger than this are discarded. Values outside 1..1048576 are
ignored.