The Apache Struts 7.3.0 test build is available. This release contains
seven breaking changes and two deprecations, together with a broad set
of improvements and bug fixes:

Breaking changes

- Struts no longer uses SLF4J or java.util.logging internally, and the
container no longer injects a Logger [WW-5620].
- JSON body population now honours the excluded and accepted
parameter-name patterns [WW-4858].
- Annotated wildcard actions are matched most-specific-first, so action
selection can differ [WW-3784].
- JSONInterceptor uses a fresh reader and writer per request, so custom
ones must not hold state between requests [WW-5650].
- @TypeConversion derives the ConversionRule key prefix automatically
and can now be placed on fields [WW-3871].
- Static content paths are canonicalised and a redundant URL decode was
removed [WW-5645].
- The <s:include> component normalises its path the same way [WW-5646].

Deprecations

- XWorkObjectPropertyAccessor is deprecated [WW-5591].
- ConversionRule.COLLECTION and the Collection_ key prefix are
deprecated; use ConversionRule.ELEMENT and Element_ instead [WW-5656].

Rejected requests

Three tickets were closed against this release without a change to
shipped code. They are listed here so the decision is visible rather
than silent.

[WW-1522] - Automatic Alias ActionConfigs - will not be implemented.
[WW-2635] - Flash scope - will not be implemented; the proposed
mechanism could introduce a security risk.
[WW-3427] - If you alias a property that uses a custom TypeConverter and
it throws TypeConversionException the error is never caught - closed as
Not A Problem; the behaviour was already correct, and a regression test
was added to keep it so.

Bug
[WW-3530] - Invalid cache key in
AnnotationActionValidationManager.buildValidatorKey when using visitor
field validators
[WW-3784] - Greedy and non-greedy matching behaviour should work in
action methods using annotated wildcards
[WW-5413] - Multipart misbehavior with commons-io 2.16.0 and 2.16.1
[WW-5416] - Hello World example does not match documentation and returns
a 404
[WW-5474] - struts.multipart.maxFiles does not work as
described/expected
[WW-5562] - Support for version 2025.2 (252)
[WW-5604] - CDI proxies won't be recognized as proxy in
SecurityMemberAccess
[WW-5641] - JSON plugin ignores struts.json.writer / struts.json.reader
override (regression since 7.2.x)
[WW-5642] - @StrutsParameter authorization bypassed for
record/creator-bound REST body properties
[WW-5643] - StrutsJSONReader parse state shared across concurrent
requests
[WW-5644] - StrutsJSONWriter write state shared across concurrent
requests
[WW-5659] - WithLazyParams resolves dynamic interceptor params onto the
shared interceptor instance

New Feature
[WW-5640] - Add WebJars support to Struts core

Improvement
[WW-2934] - conversion error should short-circuit all validators
[WW-3871] - TypeConversion annotation support improvement
[WW-4858] - JSONInterceptor must not populate value stack directly
[WW-5539] - Concurrency performance enhancements
[WW-5540] - Add caching to AbstractLocalizedTextProvider
[WW-5580] - Use Configuration.VERSION_2_3_34 for Freemaker config
[WW-5591] - Mark XWorkObjectPropertyAccessor as deprecated
[WW-5620] - Replace java.util.logging and SLF4J with Log4j2
[WW-5645] - Canonicalise static content paths and remove redundant URL
decode
[WW-5646] - Modernize path normalization in Include component
[WW-5647] - Use ConcurrentHashMap for XSLT template cache
[WW-5650] - Refactor JSON plugin reader/writer to per-request instances
instead of shared mutable state
[WW-5652] - Support Java record serialization and Optional handling in
Struts JSON plugin
[WW-5653] - Upgrade bundled Bootstrap in sample apps from 3.3.4 to 5.3.x
[WW-5656] - Mark ConversionRule.COLLECTION and the Collection_ prefix as
@Deprecated
[WW-5666] - Apply input length limits consistently when reading request
bodies
[WW-5668] - Make the localized-text provider caches size-bounded and
align request-locale resolution across entry points

Dependency
[WW-5649] - Bump commons-logging:commons-logging from 1.3.6 to 1.4.0

Release notes:
* https://cwiki.apache.org/confluence/display/WW/Version+Notes+7.3.0

Github release
* https://github.com/apache/struts/releases/tag/STRUTS_7_3_0

Distribution:
* https://dist.apache.org/repos/dist/dev/struts/7.3.0/

Maven 2 staging repository:
* https://repository.apache.org/content/groups/staging/

Once you have had a chance to review the test build, please respond
with a vote on its quality:

[ ] Leave at test build
[ ] Alpha
[ ] Beta
[ ] General Availability (GA)

Everyone who has tested the build is invited to vote. Votes by PMC
members are considered binding. A vote passes if there are at least
three binding +1s and more +1s than -1s.

The vote will remain open for at least 72 hours, longer upon request.
A vote can be amended at any time to upgrade or downgrade the quality
of the release based on future experience. If an initial vote
designates the build as "Beta", the release will be submitted for
mirroring and announced to the user list. Once released as a public
beta, subsequent quality votes on a build may be held on the user
list.

As always, the act of voting carries certain obligations. A binding
vote not only states an opinion, but means that the voter is agreeing
to help do the work.

On behalf of the Apache Struts project
Łukasz

Reply via email to