2016-02-05 10:20 GMT+01:00 Greg Huber <gregh3...@gmail.com>: > my lastest comment.. > > The entry that we don't want is {1} style > > PatternAllowedMethod{allowedMethodPattern=(.*), original='\{1\}'\} > > which is don't check anything, effectively disabling SMI. > > run{1}This style could be left in, as they are pretty restrictive, or is > there a regex for the pattern that could be added to the globals, > acknowledging there is a potential risk in your DMI?
Yes, that true, but this approach is very strict and can affect many users/projects. I would like to hear other's opinion Regards -- Ćukasz + 48 606 323 122 http://www.lenart.org.pl/ --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@struts.apache.org For additional commands, e-mail: dev-h...@struts.apache.org