This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/struts-site.git


The following commit(s) were added to refs/heads/asf-site by this push:
     new 4f27260327 Automatic Site Publish by Buildbot
4f27260327 is described below

commit 4f27260327651e375e2e9c03b6060b1971f1438a
Author: buildbot <[email protected]>
AuthorDate: Fri Oct 9 04:44:19 2026 +0000

    Automatic Site Publish by Buildbot
---
 output/core-developers/alias-interceptor.html      | 45 ++++++++++++++++++++++
 output/core-developers/default-properties.html     |  6 +--
 .../struts-parameter-annotation.html               |  4 ++
 3 files changed, 52 insertions(+), 3 deletions(-)

diff --git a/output/core-developers/alias-interceptor.html 
b/output/core-developers/alias-interceptor.html
index 459a647440..9cf922b799 100644
--- a/output/core-developers/alias-interceptor.html
+++ b/output/core-developers/alias-interceptor.html
@@ -213,6 +213,51 @@ before <code class="language-plaintext 
highlighter-rouge">conversionError</code>
 
 <p>There is no <code class="language-plaintext 
highlighter-rouge">overwrite</code> flag on this interceptor; the ordering 
above is the supported way to get that behavior.</p>
 
+<h2 id="parameter-authorization">Parameter Authorization</h2>
+
+<p>The value this interceptor copies onto the alias target can come from two 
different places, and
+each is authorized differently:</p>
+
+<ul>
+  <li><strong>The source name does not resolve anywhere on the value 
stack</strong>, so the interceptor falls back
+to the raw HTTP request parameter of that name — the behavior the <code 
class="language-plaintext highlighter-rouge">foo</code>/<code 
class="language-plaintext highlighter-rouge">bar</code> example above
+relies on. This path requires <a href="struts-parameter-annotation.html"><code 
class="language-plaintext highlighter-rouge">@StrutsParameter</code></a> on the
+target when <code class="language-plaintext 
highlighter-rouge">struts.parameters.requireAnnotations</code> is enabled (the 
default since Struts 7.0.0),
+the same as the <a href="parameters-interceptor.html">Parameters 
Interceptor</a>.</li>
+  <li>
+    <p><strong>The source name resolves on the value stack</strong> — 
typically a property an earlier action in a
+chain already holds. Copying this is the same category of operation as the
+<a href="chaining-interceptor.html">Chaining Interceptor</a>, so it follows 
the same opt-in constant:</p>
+
+    <div class="language-xml highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code><span class="nt">&lt;constant</span> <span 
class="na">name=</span><span 
class="s">"struts.chaining.requireAnnotations"</span> <span 
class="na">value=</span><span class="s">"true"</span><span 
class="nt">/&gt;</span>
+</code></pre></div>    </div>
+
+    <p>With this off (the default), a stack-resolved value is copied 
regardless of annotation, matching
+this interceptor’s traditional behavior. With it on, an unannotated target is 
rejected here too,
+not just on the request-parameter fallback.</p>
+  </li>
+</ul>
+
+<p>In both cases a rejected target is skipped and logged at <code 
class="language-plaintext highlighter-rouge">WARN</code>, and authorization 
uses the same
+<code class="language-plaintext highlighter-rouge">ParameterAuthorizer</code> 
service the Parameters and Chaining interceptors use. While an application is
+migrating,
+<a href="../../security/#defining-and-annotating-your-action-parameters"><code 
class="language-plaintext 
highlighter-rouge">struts.parameters.requireAnnotations.transitionMode=true</code></a>
+exempts non-nested alias targets, the same way it exempts any other non-nested 
setter, on both paths
+above. Nested targets — an alias map value such as <code 
class="language-plaintext highlighter-rouge">'bean.bar'</code> is valid — still 
need the
+annotation. In a custom stack that places <code class="language-plaintext 
highlighter-rouge">alias</code> after <code class="language-plaintext 
highlighter-rouge">modelDriven</code>, a target on the model gets the
+same <a href="struts-parameter-annotation.html#modeldriven-actions"><code 
class="language-plaintext highlighter-rouge">ModelDriven</code></a> exemption 
as the Parameters
+Interceptor.</p>
+
+<p>See also <a 
href="struts-parameter-annotation.html#where-authorization-applies">Where 
authorization applies</a>
+for an overview of the channels that can populate an action.</p>
+
+<h3 id="upgrading-an-existing-application">Upgrading an existing 
application</h3>
+
+<p>If an application already uses this interceptor’s documented pattern — the 
<code class="language-plaintext highlighter-rouge">foo</code>/<code 
class="language-plaintext highlighter-rouge">bar</code> example
+above — <code class="language-plaintext highlighter-rouge">bar</code> now 
needs <a href="struts-parameter-annotation.html"><code 
class="language-plaintext highlighter-rouge">@StrutsParameter</code></a> for 
the alias to
+keep working with <code class="language-plaintext 
highlighter-rouge">struts.parameters.requireAnnotations</code> enabled (the 
default). Without it, the
+alias is skipped and logged at <code class="language-plaintext 
highlighter-rouge">WARN</code> instead of setting <code 
class="language-plaintext highlighter-rouge">bar</code>.</p>
+
 <h2 id="extending-the-interceptor">Extending the Interceptor</h2>
 
 <p>This interceptor does not have any known extension points.</p>
diff --git a/output/core-developers/default-properties.html 
b/output/core-developers/default-properties.html
index 3dd7b87e78..f650141efb 100644
--- a/output/core-developers/default-properties.html
+++ b/output/core-developers/default-properties.html
@@ -452,9 +452,9 @@ struts.parameters.requireAnnotations=true
 ### Useful for transitioning legacy applications, but highly recommended to 
set to false as soon as possible!
 struts.parameters.requireAnnotations.transitionMode=false
 
-### Whether ChainingInterceptor enforces @StrutsParameter on the target action 
when copying properties.
-### Opt-in hardening; default false preserves legacy chaining behaviour. Only 
has effect when
-### struts.parameters.requireAnnotations is also enabled.
+### Whether ChainingInterceptor and AliasInterceptor enforce @StrutsParameter 
on the target action when
+### copying a value already resolved on the stack. Opt-in hardening; default 
false preserves legacy
+### chaining/aliasing behaviour. Only has effect when 
struts.parameters.requireAnnotations is also enabled.
 struts.chaining.requireAnnotations=false
 
 ### Whether to throw a RuntimeException when a property is not found
diff --git a/output/core-developers/struts-parameter-annotation.html 
b/output/core-developers/struts-parameter-annotation.html
index 4cddbdeb55..fe0a3de5d2 100644
--- a/output/core-developers/struts-parameter-annotation.html
+++ b/output/core-developers/struts-parameter-annotation.html
@@ -190,6 +190,10 @@ channel that can populate an action from request data:</p>
 (default, governed by <code class="language-plaintext 
highlighter-rouge">struts.parameters.requireAnnotations</code>).</li>
   <li><a href="chaining-interceptor.html">Chaining Interceptor</a> — 
value-stack copying during
 action chaining (opt-in via <code class="language-plaintext 
highlighter-rouge">struts.chaining.requireAnnotations</code>).</li>
+  <li><a href="alias-interceptor.html">Alias Interceptor</a> — its 
raw-request-parameter fallback follows
+<code class="language-plaintext 
highlighter-rouge">struts.parameters.requireAnnotations</code> like the 
Parameters Interceptor; copying a value already
+resolved on the stack follows <code class="language-plaintext 
highlighter-rouge">struts.chaining.requireAnnotations</code> like the Chaining 
Interceptor
+(since Struts 7.5.0 — see <a 
href="alias-interceptor.html#parameter-authorization">Parameter 
Authorization</a>).</li>
   <li><a href="cookie-interceptor.html">Cookie Interceptor</a> — cookie 
values.</li>
   <li><a href="../../plugins/json">JSON</a> and <a 
href="../../plugins/rest">REST</a> plugins — per-property
 authorization performed during deserialization, so an unauthorized property is 
not set on

Reply via email to