mraible commented on code in PR #154:
URL: https://github.com/apache/roller/pull/154#discussion_r4107459551
##########
app/src/main/resources/struts.xml:
##########
@@ -17,10 +17,26 @@
directory of this distribution.
-->
<!DOCTYPE struts PUBLIC
- "-//Apache Software Foundation//DTD Struts Configuration 2.5//EN"
- "http://struts.apache.org/dtds/struts-2.5.dtd">
+ "-//Apache Software Foundation//DTD Struts Configuration 6.5//EN"
+ "https://struts.apache.org/dtds/struts-6.5.dtd">
<struts>
+ <!-- Struts 7 denies OGNL access to any class outside this allowlist, which
+ otherwise blocks reads of Roller's own action and bean properties. -->
+ <constant name="struts.allowlist.packageNames"
+ value="org.apache.roller,java.util,java.lang"/>
+
+ <!-- Struts serves its bundled JS/CSS (tooltips, etc.) from this path,
which
+ must match the /struts/* filter-mapping in web.xml. Struts defaults it
+ to /static, which Roller does not map. -->
+ <constant name="struts.ui.staticContentPath" value="/struts"/>
+
+ <!-- Struts 7 only binds request parameters to properties annotated with
+ @StrutsParameter. Roller's actions predate that annotation, so without
+ this no form in the application can submit data. Annotating the action
+ beans would be the stricter alternative. -->
+ <constant name="struts.parameters.requireAnnotations" value="false"/>
Review Comment:
Switched to annotations. `struts.parameters.requireAnnotations=false` is
gone, so the Struts 7 default applies, and `@StrutsParameter` now marks exactly
the properties forms and URLs bind to: about 70 setters and `getBean()` getters
across the actions, with `depth = 1` on the form-bean getters, the deepest
nesting any form uses.
On the risk: with the gate off, Struts binds a request parameter to any OGNL
path reachable from the action, such as `authenticatedUser.fullName` or
`actionWeblog.creator.fullName`, which lead to persistent objects. Parameters
like those are now rejected (verified on `profile!save` and
`weblogConfig!save`), because getters that return domain objects (users,
weblogs, entries, folders, media directories, templates) are not annotated.
A few details:
- PlanetGroupSubs used to bind `group.title` and `group.handle` straight
onto the persistent `PlanetGroup`. It now binds to a small `PlanetGroupBean`
DTO that is copied onto the group only after validation.
- Bookmarks' `folder.name` input no longer writes to the persistent folder;
renames go through `folderEdit`.
- `StrutsParameterAnnotationTest` checks every Struts form field,
`<s:param>`, and redirect parameter in the JSPs and struts.xml against Struts'
own authorizer, so a form that loses its binding fails the build.
- Every admin and editor form was exercised against a running instance with
the authorizer logging at DEBUG, plus the Playwright suite in all three auth
modes.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]