This is an automated email from the ASF dual-hosted git repository.
asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/struts-site.git
The following commit(s) were added to refs/heads/asf-site by this push:
new 4f27260327 Automatic Site Publish by Buildbot
4f27260327 is described below
commit 4f27260327651e375e2e9c03b6060b1971f1438a
Author: buildbot <[email protected]>
AuthorDate: Fri Oct 9 04:44:19 2026 +0000
Automatic Site Publish by Buildbot
---
output/core-developers/alias-interceptor.html | 45 ++++++++++++++++++++++
output/core-developers/default-properties.html | 6 +--
.../struts-parameter-annotation.html | 4 ++
3 files changed, 52 insertions(+), 3 deletions(-)
diff --git a/output/core-developers/alias-interceptor.html
b/output/core-developers/alias-interceptor.html
index 459a647440..9cf922b799 100644
--- a/output/core-developers/alias-interceptor.html
+++ b/output/core-developers/alias-interceptor.html
@@ -213,6 +213,51 @@ before <code class="language-plaintext
highlighter-rouge">conversionError</code>
<p>There is no <code class="language-plaintext
highlighter-rouge">overwrite</code> flag on this interceptor; the ordering
above is the supported way to get that behavior.</p>
+<h2 id="parameter-authorization">Parameter Authorization</h2>
+
+<p>The value this interceptor copies onto the alias target can come from two
different places, and
+each is authorized differently:</p>
+
+<ul>
+ <li><strong>The source name does not resolve anywhere on the value
stack</strong>, so the interceptor falls back
+to the raw HTTP request parameter of that name — the behavior the <code
class="language-plaintext highlighter-rouge">foo</code>/<code
class="language-plaintext highlighter-rouge">bar</code> example above
+relies on. This path requires <a href="struts-parameter-annotation.html"><code
class="language-plaintext highlighter-rouge">@StrutsParameter</code></a> on the
+target when <code class="language-plaintext
highlighter-rouge">struts.parameters.requireAnnotations</code> is enabled (the
default since Struts 7.0.0),
+the same as the <a href="parameters-interceptor.html">Parameters
Interceptor</a>.</li>
+ <li>
+ <p><strong>The source name resolves on the value stack</strong> —
typically a property an earlier action in a
+chain already holds. Copying this is the same category of operation as the
+<a href="chaining-interceptor.html">Chaining Interceptor</a>, so it follows
the same opt-in constant:</p>
+
+ <div class="language-xml highlighter-rouge"><div class="highlight"><pre
class="highlight"><code><span class="nt"><constant</span> <span
class="na">name=</span><span
class="s">"struts.chaining.requireAnnotations"</span> <span
class="na">value=</span><span class="s">"true"</span><span
class="nt">/></span>
+</code></pre></div> </div>
+
+ <p>With this off (the default), a stack-resolved value is copied
regardless of annotation, matching
+this interceptor’s traditional behavior. With it on, an unannotated target is
rejected here too,
+not just on the request-parameter fallback.</p>
+ </li>
+</ul>
+
+<p>In both cases a rejected target is skipped and logged at <code
class="language-plaintext highlighter-rouge">WARN</code>, and authorization
uses the same
+<code class="language-plaintext highlighter-rouge">ParameterAuthorizer</code>
service the Parameters and Chaining interceptors use. While an application is
+migrating,
+<a href="../../security/#defining-and-annotating-your-action-parameters"><code
class="language-plaintext
highlighter-rouge">struts.parameters.requireAnnotations.transitionMode=true</code></a>
+exempts non-nested alias targets, the same way it exempts any other non-nested
setter, on both paths
+above. Nested targets — an alias map value such as <code
class="language-plaintext highlighter-rouge">'bean.bar'</code> is valid — still
need the
+annotation. In a custom stack that places <code class="language-plaintext
highlighter-rouge">alias</code> after <code class="language-plaintext
highlighter-rouge">modelDriven</code>, a target on the model gets the
+same <a href="struts-parameter-annotation.html#modeldriven-actions"><code
class="language-plaintext highlighter-rouge">ModelDriven</code></a> exemption
as the Parameters
+Interceptor.</p>
+
+<p>See also <a
href="struts-parameter-annotation.html#where-authorization-applies">Where
authorization applies</a>
+for an overview of the channels that can populate an action.</p>
+
+<h3 id="upgrading-an-existing-application">Upgrading an existing
application</h3>
+
+<p>If an application already uses this interceptor’s documented pattern — the
<code class="language-plaintext highlighter-rouge">foo</code>/<code
class="language-plaintext highlighter-rouge">bar</code> example
+above — <code class="language-plaintext highlighter-rouge">bar</code> now
needs <a href="struts-parameter-annotation.html"><code
class="language-plaintext highlighter-rouge">@StrutsParameter</code></a> for
the alias to
+keep working with <code class="language-plaintext
highlighter-rouge">struts.parameters.requireAnnotations</code> enabled (the
default). Without it, the
+alias is skipped and logged at <code class="language-plaintext
highlighter-rouge">WARN</code> instead of setting <code
class="language-plaintext highlighter-rouge">bar</code>.</p>
+
<h2 id="extending-the-interceptor">Extending the Interceptor</h2>
<p>This interceptor does not have any known extension points.</p>
diff --git a/output/core-developers/default-properties.html
b/output/core-developers/default-properties.html
index 3dd7b87e78..f650141efb 100644
--- a/output/core-developers/default-properties.html
+++ b/output/core-developers/default-properties.html
@@ -452,9 +452,9 @@ struts.parameters.requireAnnotations=true
### Useful for transitioning legacy applications, but highly recommended to
set to false as soon as possible!
struts.parameters.requireAnnotations.transitionMode=false
-### Whether ChainingInterceptor enforces @StrutsParameter on the target action
when copying properties.
-### Opt-in hardening; default false preserves legacy chaining behaviour. Only
has effect when
-### struts.parameters.requireAnnotations is also enabled.
+### Whether ChainingInterceptor and AliasInterceptor enforce @StrutsParameter
on the target action when
+### copying a value already resolved on the stack. Opt-in hardening; default
false preserves legacy
+### chaining/aliasing behaviour. Only has effect when
struts.parameters.requireAnnotations is also enabled.
struts.chaining.requireAnnotations=false
### Whether to throw a RuntimeException when a property is not found
diff --git a/output/core-developers/struts-parameter-annotation.html
b/output/core-developers/struts-parameter-annotation.html
index 4cddbdeb55..fe0a3de5d2 100644
--- a/output/core-developers/struts-parameter-annotation.html
+++ b/output/core-developers/struts-parameter-annotation.html
@@ -190,6 +190,10 @@ channel that can populate an action from request data:</p>
(default, governed by <code class="language-plaintext
highlighter-rouge">struts.parameters.requireAnnotations</code>).</li>
<li><a href="chaining-interceptor.html">Chaining Interceptor</a> —
value-stack copying during
action chaining (opt-in via <code class="language-plaintext
highlighter-rouge">struts.chaining.requireAnnotations</code>).</li>
+ <li><a href="alias-interceptor.html">Alias Interceptor</a> — its
raw-request-parameter fallback follows
+<code class="language-plaintext
highlighter-rouge">struts.parameters.requireAnnotations</code> like the
Parameters Interceptor; copying a value already
+resolved on the stack follows <code class="language-plaintext
highlighter-rouge">struts.chaining.requireAnnotations</code> like the Chaining
Interceptor
+(since Struts 7.5.0 — see <a
href="alias-interceptor.html#parameter-authorization">Parameter
Authorization</a>).</li>
<li><a href="cookie-interceptor.html">Cookie Interceptor</a> — cookie
values.</li>
<li><a href="../../plugins/json">JSON</a> and <a
href="../../plugins/rest">REST</a> plugins — per-property
authorization performed during deserialization, so an unauthorized property is
not set on