[
https://issues.apache.org/jira/browse/WW-5713?focusedWorklogId=1042195&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1042195
]
ASF GitHub Bot logged work on WW-5713:
--------------------------------------
Author: ASF GitHub Bot
Created on: 17/Sep/26 05:24
Start Date: 17/Sep/26 05:24
Worklog Time Spent: 10m
Work Description: sonarqubecloud[bot] commented on PR #1961:
URL: https://github.com/apache/struts/pull/1961#issuecomment-5709230744
## [](https://sonarcloud.io/dashboard?id=apache_struts&pullRequest=1961)
**Quality Gate passed**
Issues
 [0 New
issues](https://sonarcloud.io/project/issues?id=apache_struts&pullRequest=1961&issueStatuses=OPEN,CONFIRMED&sinceLeakPeriod=true)
 [0 Accepted
issues](https://sonarcloud.io/project/issues?id=apache_struts&pullRequest=1961&issueStatuses=ACCEPTED)
Measures
 [0 Security
Hotspots](https://sonarcloud.io/project/security_hotspots?id=apache_struts&pullRequest=1961&issueStatuses=OPEN,CONFIRMED&sinceLeakPeriod=true)
 [100.0% Coverage on New
Code](https://sonarcloud.io/component_measures?id=apache_struts&pullRequest=1961&metric=new_coverage&view=list)
 [0.0% Duplication on New
Code](https://sonarcloud.io/component_measures?id=apache_struts&pullRequest=1961&metric=new_duplicated_lines_density&view=list)
<!
Issue Time Tracking
-------------------
Worklog Id: (was: 1042195)
Time Spent: 2h (was: 1h 50m)
> Fail closed for legacy Tiles OGNL evaluation
> --------------------------------------------
>
> Key: WW-5713
> URL: https://issues.apache.org/jira/browse/WW-5713
> Project: Struts 2
> Issue Type: Improvement
> Components: Plugin - Tiles
> Reporter: Karan Kurani
> Priority: Major
> Fix For: 7.4.0
>
> Time Spent: 2h
> Remaining Estimate: 0h
>
> The Struts Tiles plugin registers separate {{S2:}} and legacy {{OGNL:}}
> attribute-expression evaluators.
> The {{S2:}} evaluator processes ValueStack expressions through the Struts
> OGNL facilities. The legacy {{OGNL:}} evaluator evaluates against the Tiles
> {{Request}} and does not use the Struts OGNL security controls used by
> {{{}S2:{}}}.
> This hardening change keeps {{OGNL:}} registered but makes it fail closed by
> default. Evaluation throws Tiles {{EvaluationException}} with migration
> guidance directing users to {{{}S2:{}}}.
> Applications that temporarily require the existing raw behavior may
> explicitly set:
> {{struts.tiles.ognl.legacy.enabled=true}}
> The compatibility flag defaults to {{false}} and is targeted for removal in
> Struts 8.0.0.
> The raw evaluator and its global {{OgnlRuntime}} {{Request}}
> property-accessor setup are constructed only when legacy mode is explicitly
> enabled. This avoids mutating the shared OGNL runtime for applications using
> the secure default.
> When legacy mode is enabled, the existing raw behavior is preserved and a
> clear startup migration warning is emitted.
> {{{}S2:{}}}, {{{}I18N:{}}}, and {{EL:}} remain unchanged.
> Tests cover:
> * default fail-closed behavior;
> * exact migration guidance;
> * non-evaluation of expression markers;
> * construction gating;
> * absence of global accessor initialization under the default;
> * explicit legacy compatibility behavior;
> * startup warning behavior; and
> * real servlet-backed {{S2:}} evaluation.
> This is defense-in-depth hardening. No attacker-controlled expression source
> or concrete vulnerability impact has been demonstrated, and no security
> advisory is proposed.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)