Re: Unable to load configuration: /struts2-core-6.4.0.jar!/struts-beans.xml:39:72

2024-04-18 Thread i...@flyingfischer.ch
Am 18.04.24 um 12:18 schrieb Lukasz Lenart: czw., 18 kwi 2024 o 11:17 i...@flyingfischer.ch napisał(a): However, this still seems to be a breaking change, which at least should be documented. Maybe is was wong by not specifying tiles.xml specifically in the first place... Yes

Re: Unable to load configuration: /struts2-core-6.4.0.jar!/struts-beans.xml:39:72

2024-04-18 Thread i...@flyingfischer.ch
is was wong by not specifying tiles.xml specifically in the first place... Thanks! Markus Am 18.04.24 um 11:08 schrieb i...@flyingfischer.ch: I simply use   org.apache.struts2.tiles.StrutsTilesListener   without any further params. Is this incomplete? Markus Am 18.04.24 um 10:29

Re: Unable to load configuration: /struts2-core-6.4.0.jar!/struts-beans.xml:39:72

2024-04-18 Thread i...@flyingfischer.ch
          org.apache.tiles.definition.DefinitionsFactory.DEFINITIONS_CONFIG           /WEB-INF/tiles.xml         On 18/04/2024 08:47, i...@flyingfischer.ch wrote: Am 18.04.24 um 09:27 schrieb Lukasz Lenart: czw., 18 kwi 2024 o 09:05 i...@flyingfischer.ch napisał(a): My tiles

Re: Unable to load configuration: /struts2-core-6.4.0.jar!/struts-beans.xml:39:72

2024-04-18 Thread i...@flyingfischer.ch
Am 18.04.24 um 09:27 schrieb Lukasz Lenart: czw., 18 kwi 2024 o 09:05 i...@flyingfischer.ch napisał(a): My tiles definition remains unchanged under /WEB-INF/tiles.xml If I see this correctly, these changes do not include this situation? https://github.com/apache/struts/pull/896/commits

Re: Unable to load configuration: /struts2-core-6.4.0.jar!/struts-beans.xml:39:72

2024-04-18 Thread i...@flyingfischer.ch
Am 18.04.24 um 08:52 schrieb Lukasz Lenart: czw., 18 kwi 2024 o 08:40i...@flyingfischer.ch napisał(a): Yes, struts2-tiles-plugin-6.4.0.jar is present. It is the same setup as with 6.3.0 This is the only change related to loading Tiles definition, maybe it will help you

Re: Unable to load configuration: /struts2-core-6.4.0.jar!/struts-beans.xml:39:72

2024-04-18 Thread i...@flyingfischer.ch
Am 18.04.24 um 08:34 schrieb Lukasz Lenart: czw., 18 kwi 2024 o 08:22 i...@flyingfischer.ch napisał(a): ...unfortunately, the next issue comes immediately: 18-04-2024 08:19:58.4 WARN org.apache.struts2.views.tiles.TilesResult - could not find @TilesDefinition for action: start 18-04-2024

Re: Unable to load configuration: /struts2-core-6.4.0.jar!/struts-beans.xml:39:72

2024-04-18 Thread i...@flyingfischer.ch
Thanks Lukasz Am 18.04.24 um 08:11 schrieb Lukasz Lenart: czw., 18 kwi 2024 o 08:02 i...@flyingfischer.ch napisał(a): With Struts 6.4.0 I get an error 18-04-2024 07:48:41.4 ERROR org.apache.struts2.dispatcher.Dispatcher - Dispatcher initialization failed Unable to load configuration. - bean

Re: Unable to load configuration: /struts2-core-6.4.0.jar!/struts-beans.xml:39:72

2024-04-18 Thread i...@flyingfischer.ch
i...@flyingfischer.ch: With Struts 6.4.0 I get an error 18-04-2024 07:48:41.4 ERROR org.apache.struts2.dispatcher.Dispatcher - Dispatcher initialization failed Unable to load configuration. - bean - jar:file: .../.metadata/.plugins/org.eclipse.wst.server.core/tmp0/wtpwebapps/SC/WEB-INF/lib

Unable to load configuration: /struts2-core-6.4.0.jar!/struts-beans.xml:39:72

2024-04-18 Thread i...@flyingfischer.ch
With Struts 6.4.0 I get an error 18-04-2024 07:48:41.4 ERROR org.apache.struts2.dispatcher.Dispatcher - Dispatcher initialization failed Unable to load configuration. - bean - jar:file:

Re: [TEST] Apache Struts 7.0.0-M3 test build is ready

2024-02-25 Thread i...@flyingfischer.ch
May be related to this issue in Struts 1: https://github.com/weblegacy/struts1/issues/28 Best regards Markus Am 25.02.24 um 09:41 schrieb Greg Huber: Testing the file upload and it now does not work. I get an error where its using the wrong file name ie

Re: Dependency upgrade process

2024-01-31 Thread i...@flyingfischer.ch
LGTM Markus Am 31.01.24 um 09:53 schrieb Lukasz Lenart: Hi, I would like to grasp your opinion about how do feel about the following upgrade process of dependencies: - Dependabot prepares PRs with upgraded dependencies - if this is patch upgrade and all the tests have passed, we can approve

Re: [VOTE] Apache Struts 6.3.0

2023-09-04 Thread i...@flyingfischer.ch
[X] General Availability (GA) Markus Am 01.09.23 um 08:44 schrieb Lukasz Lenart: The Apache Struts 6.3.0 test build is available. With this release the following issues were addressed: Improvement [WW-5233] - Include Apache Tiles code base in the Tiles plugin [WW-5321] - notify / document

Re: Unblocking dev list

2023-09-01 Thread i...@flyingfischer.ch
Perfect Łukasz thanks for all your work. Best regards Markus Am 01.09.23 um 09:01 schrieb Lukasz Lenart: Hi, If you take a look at the list messages [1] you notice the most of them are related to failed builds from Jenkins and then back to normal notifications. This is clustering the list

Re: [TEST] Apache Struts 6.3.0-RC1 test build is read

2023-07-16 Thread i...@flyingfischer.ch
No issues herey, so far. I am using tiles. I did delete all tiles-*.jar related libraries from the classpath. Everything seems to work fine. Just as a side note, there exists also newer libraries for: * commons-lang3 * javassist Best regards Markus Am 16.07.23 um 10:23 schrieb Lukasz

Re: [VOTE] Apache Struts 6.2.0

2023-07-05 Thread i...@flyingfischer.ch
[X] General Availability (GA) Markus Fischer Am 05.07.23 um 12:25 schrieb Lukasz Lenart: The Apache Struts 6.2.0 test build is available. With this release the following issues were addressed: Bug [WW-4434] - datetextfield.ftl is missing [WW-5199] - StrutsPrepareFilter and StrutsExecuteFilter

Re: [TEST] Apache Struts 6.2.0 test build is ready

2023-07-04 Thread i...@flyingfischer.ch
Runs fine here in production since some days. No issues discovered. Best regards Markus Am 28.06.23 um 09:22 schrieb Lukasz Lenart: Hello, This is another minor version of Struts 6.x series. Please take the time and test the bits - any help is appreciated. Please report any problems you

Re: [TEST] Apache Struts 6.2.0 test build is ready

2023-06-28 Thread i...@flyingfischer.ch
Runs fine here. Just to note, newer versions are available (and running here) from: asm-9.5 commons-io-2.13.0 (Java 8) log4j-api-2.20.0 (Java 8) slf4j-api-2.0.7 (Java 8) Best regards Markus Am 28.06.23 um 09:22 schrieb Lukasz Lenart: Hello, This is another minor version of Struts 6.x

Re: [VOTE] [FASTTRACK] Apache Struts 6.1.2

2023-03-08 Thread i...@flyingfischer.ch
[ ] Leave at test build [ ] Alpha [ ] Beta [X] General Availability (GA) Thanks for the great work! Best Markus Am 08.03.23 um 21:10 schrieb Lukasz Lenart: The Apache Struts 6.1.2 test build is now available. It includes the latest security patch which fixes potential security vulnerability:

Re: [VOTE] Apache Struts 6.1.1

2022-11-24 Thread i...@flyingfischer.ch
[ ] Leave at test build [ ] Alpha [ ] Beta [X] General Availability (GA) Works fine here. Thanks for taking care to transform 6.1.1 to be a drop in replacement again, with no need to override anything in custom interceptors due to [WW-4173]. Great work! Best regards Markus Am 24.11.22 um

Re: [TEST] Apache Struts 6.1.0 test build is ready

2022-11-08 Thread i...@flyingfischer.ch
I like the new feature to disable a specific interceptor within an existing stack: https://issues.apache.org/jira/browse/WW-4173 But this change has consequences: This basically means that each custom implementation of the class Interceptor, now needs to add a method

Re: Struts 6.1.0

2022-11-07 Thread i...@flyingfischer.ch
;-))) Thanks Łukasz for this huge work! Looking forward to test the bits. Markus Am 08.11.22 um 07:45 schrieb Lukasz Lenart: Hi, I'm ready to prepare a new test build as preparation for releasing Struts 6.1.0 - all the issues have been addressed :) Cheers -- Łukasz pt., 21 paź 2022 o

Re: failureaccess-1.0.1.jar for standalone artifacts

2022-09-16 Thread i...@flyingfischer.ch
Sure. Done. Regards Markus Am 16.09.22 um 09:39 schrieb Lukasz Lenart: pt., 16 wrz 2022 o 09:13 i...@flyingfischer.ch napisał(a): commons-text has a dependency to failureaccess-1.0.1.jar. Maybe we should consider to add failureaccess to the standalone artifacts. Sure, it makes sense

failureaccess-1.0.1.jar for standalone artifacts

2022-09-16 Thread i...@flyingfischer.ch
commons-text has a dependency to failureaccess-1.0.1.jar. Maybe we should consider to add failureaccess to the standalone artifacts. Markus - To unsubscribe, e-mail: dev-unsubscr...@struts.apache.org For additional commands,

Re: [TEST] Struts 6.0.3 test build is ready

2022-09-09 Thread i...@flyingfischer.ch
Looks all good to me and runs in production very smoothely. Markus Am 09.09.22 um 10:26 schrieb Johannes Geppert: Tested with AWS serverless and did not see any issues. Any blockers to release this version? # web: http://www.jgeppert.com

Re: [TEST] Struts 6.0.2 test build is ready

2022-09-01 Thread i...@flyingfischer.ch
Resolved the other "phenomenon". Was an issue on my side around Modeldriven and mixed up getters. Best regards Markus Am 01.09.22 um 09:07 schrieb i...@flyingfischer.ch: Thanks Łukasz looks good to me. Provides the possibility to opt out on any given fine grained use case while

Re: [TEST] Struts 6.0.2 test build is ready

2022-09-01 Thread i...@flyingfischer.ch
it implies that the other stacks are not secure.  My 2ct on this Best Regards Johannes i...@flyingfischer.ch schrieb am Mi., 31. Aug. 2022, 14:20: Creating a new default secure stack sounds good to me. Thank for considering. As far as I can see there would be 4 additional interceptors in this se

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-31 Thread i...@flyingfischer.ch
Creating a new default secure stack sounds good to me. Thank for considering. As far as I can see there would be 4 additional interceptors in this secure stack: CoepInterceptor.java CoopInterceptor.java CspInterceptor.java FetchMetadataInterceptor.java And the appropriate resources used by

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-30 Thread i...@flyingfischer.ch
knows     name="fetchMetadata.exemptedPaths">/path1,/path2,/path3     Am 30.08.22 um 16:43 schrieb i...@flyingfischer.ch: Thanks Łukasz Any chance to disable this on domain basis, or even totally? I fear coopInterceptor.exemptedPaths will not be sufficiant in my case.

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-30 Thread i...@flyingfischer.ch
-interceptor https://struts.apache.org/core-developers/coop-interceptor https://struts.apache.org/core-developers/fetch-metadata-interceptor W dniu wt., 30.08.2022 o 15:54 i...@flyingfischer.ch napisał(a): It looks like an cross-site issue: The error does only appear, when the request is called

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-30 Thread i...@flyingfischer.ch
It looks like an cross-site issue: The error does only appear, when the request is called from a third party domain. When called from a subdomain of the main domain, the error does not appear. Regards Markus Am 30.08.22 um 15:35 schrieb i...@flyingfischer.ch: I am puzzled, calling the same

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-30 Thread i...@flyingfischer.ch
-Policy-Report-Only: require-corp Cross-Origin-Opener-Policy: same-origin Location: /context/otherpath?url=urlEncodedUrl Content-Language: de-CH Content-Length: 0 Date: Tue, 30 Aug 2022 13:23:17 GMT Server: Apache I need to meditate... Regards Markus Am 30.08.22 um 14:41 schrieb i...@flyingfischer.ch

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-30 Thread i...@flyingfischer.ch
Indeed I use http://xmlns.jcp.org/xml/ns/javaee; xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance;     xsi:schemaLocation="http://xmlns.jcp.org/xml/ns/javaee http://xmlns.jcp.org/xml/ns/javaee/web-app_3_1.xsd; version="3.1"> Regards Markus Am 30.08.22 um 14:39 schrieb Lukasz Lenart:

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-30 Thread i...@flyingfischer.ch
sult for this action in struts.xml? wdyt? On 8/29/2022 8:32 PM, i...@flyingfischer.ch wrote: Hi Yasser sure. Regards Markus 29-08-2022 16:12:47.8 WARN org.apache.struts2.dispatcher.Dispatcher - Could not find action or result: /context/mypath?url=urlEncodedUrl No result defined for action ch.xx.

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-29 Thread i...@flyingfischer.ch
The corresponding request is OPTIONS /context/mypath?url=urlEncodedUrl HTTP/1.1" 404 The same request as GET or POST will work fine. OPTIONS and HEAD requests crash. Regards Markus Am 29.08.22 um 18:02 schrieb i...@flyingfischer.ch: Hi Yasser sure. Regards Markus 29-08-2022 16:12

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-29 Thread i...@flyingfischer.ch
28b On 8/29/2022 5:22 PM, i...@flyingfischer.ch wrote: If I see this correctly, this happens only with OPTIONS and HEAD requests Am 29.08.22 um 14:09 schrieb i...@flyingfischer.ch: After removing commons-digester3-3.2 and leaving commons-digester-2.1 only, I still get the Warnings/Errors in

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-29 Thread i...@flyingfischer.ch
If I see this correctly, this happens only with OPTIONS and HEAD requests Am 29.08.22 um 14:09 schrieb i...@flyingfischer.ch: After removing commons-digester3-3.2 and leaving commons-digester-2.1 only, I still get the Warnings/Errors in production: WARN org.apache.struts2

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-29 Thread i...@flyingfischer.ch
related to commons-digester? Unfortunately I cannot reproduce the issue straightforward. I just see the error in the log. Calling the path directly does not cause the issue. May there be a connection with a not present session? Markus Am 29.08.22 um 11:36 schrieb i...@flyingfischer.ch: Removing

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-29 Thread i...@flyingfischer.ch
.dispatcher.Dispatcher disappear. Regards Markus Am 29.08.22 um 10:19 schrieb Lukasz Lenart: Could you exclude commons-digester in the Tiles plugin? Regards Łukasz pon., 29 sie 2022 o 10:11 i...@flyingfischer.ch napisał(a): hmm, in production I see from time to time: WARN org.apache.struts2

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-29 Thread i...@flyingfischer.ch
idea, what is causing this warning, which seems to be rather an error? Best Markus Am 27.08.22 um 12:28 schrieb i...@flyingfischer.ch: Works fine here. Tested with tiles-plugin. Best regards Markus Am 25.08.22 um 07:52 schrieb Lukasz Lenart: Hello, This is the first patch version of Struts

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-27 Thread i...@flyingfischer.ch
Works fine here. Tested with tiles-plugin. Best regards Markus Am 25.08.22 um 07:52 schrieb Lukasz Lenart: Hello, This is the first patch version of Struts 6.x series. Please take the time and test the bits - any help is appreciated. Please report any problems you will spot. Here are the

Re: Tiles support

2022-08-08 Thread i...@flyingfischer.ch
I use all the jars below, except tiles-request-servlet-1.0.7.jar. However that may be an outlier here. It seems all the jars are needed. Best regards Markus Am 08.08.22 um 20:43 schrieb Greg Huber: Sounds like a good idea, maybe add the required code to our plugin? ...I have had a look at

Re: [TEST] Struts 2 ver. 6.0.0-RC4 test build is ready

2022-05-25 Thread i...@flyingfischer.ch
Besides incrementing or disabling this arbitrary limit with You may also work with a most ugly hack by defining a variable in your jsp and then use this very short variables in your too long OGNL expression. Ugly, does add to code complexity and increases the overall failure rate.But may

Re: [TEST] Struts 2 ver. 6.0.0-RC4 test build is ready

2022-05-25 Thread i...@flyingfischer.ch
You may use this in Struts.xml   You need to find you longest OGNL value, discipline yourself to shorten those, rethink you variable name length or disable this completly   Not that much of a convincing approach to improve security, but maybe better than not. I did not like it at all,

Re: [VOTE] Struts 2.5.30

2022-03-30 Thread i...@flyingfischer.ch
[X] General Availability (GA) Works fine in production since some days. Thanks! Markus Am 30.03.22 um 11:39 schrieb Lukasz Lenart: [ ] Leave at test build [ ] Alpha [ ] Beta [ ] General Availability (GA) Everyone who has tested the build is invited to vote. Votes by PMC members are

Re: New Struts 2.5.x release

2021-09-20 Thread i...@flyingfischer.ch
+1 Am 20.09.21 um 15:59 schrieb Dave Newton: +1 On Mon, Sep 20, 2021 at 1:25 AM Lukasz Lenart wrote: Hi, I would like to release the last 2.5.x version and focus on Struts 2.6. All the PRs that are targeting Struts 2.5.x should be re-targeted to Struts 2.6 (the master branch) and we

Re: lazy consensus state for PR#483,496

2021-07-24 Thread i...@flyingfischer.ch
I did take a look at https://github.com/apache/struts/pull/483 https://github.com/apache/struts/pull/496 This seems to me too big of a change for the current 2.5 branch. It should be reconsidered or reevaluated eventually for an upcoming 2.6 branch. It also seems sensible to me to have a

Re: [TEST] Struts 2.5.26 test build is ready

2020-11-21 Thread i...@flyingfischer.ch
Seems to work fine here. Markus Am 21.11.20 um 09:02 schrieb Lukasz Lenart: > Hi, > > Please take a time and test the bits - any help is appreciated. Please > report any problems. I'll call for a vote in a few days if no problems > will be spotted. > > Staging Maven repo >

Re: [VOTE] Struts 2.5.25

2020-09-26 Thread i...@flyingfischer.ch
Am 24.09.20 um 07:07 schrieb Lukasz Lenart > [ ] Leave at test build > [ ] Alpha > [ ] Beta > [X] General Availability (GA) > Thanks! Markus - To unsubscribe, e-mail: dev-unsubscr...@struts.apache.org For additional commands,

Re: [VOTE] Struts Maven Archetypes 2.5.22

2020-08-26 Thread i...@flyingfischer.ch
Absolutely! Best regards Markus Am 26.08.20 um 08:46 schrieb Lukasz Lenart: > Can we assume a silence consensus here? > > http://community.apache.org/committers/lazyConsensus.html > https://www.apache.org/foundation/voting.html#LazyConsensus > > Regards

Re: [TEST] Struts 2.5.24 test build is ready

2020-08-19 Thread i...@flyingfischer.ch
in a couple of days, since this is a dynamic situation. So we may leave this very well up to individual responsibility to do so. Best Markus Am 19.08.20 um 08:52 schrieb Lukasz Lenart: > wt., 18 sie 2020 o 10:27 i...@flyingfischer.ch > napisał(a): >> PS: maybe to consider for an upco

Re: [TEST] Struts 2.5.24 test build is ready

2020-08-18 Thread i...@flyingfischer.ch
Seems to run fine here. Thank for you steady good work! Best regards Markus PS: maybe to consider for an upcoming release: there are some newer version of used librarires which do work fine in Struts2, as commons-collections4-4.4 commons-io-2.7 commons-lang3-3.11 (would need to check, if

Re: StrutsBoot

2020-07-08 Thread i...@flyingfischer.ch
I second NOT dropping XML configuration support. Best Markus Am 08.07.20 um 09:19 schrieb Lukasz Lenart: > wt., 7 lip 2020 o 16:37 Yasser Zamani napisał(a): >> Yes it's awesome and I've also been thought for long time to add boot >> and auto-config (because I've seen people have concerns about

Re: [VOTE] Struts 2.5.22

2019-11-26 Thread i...@flyingfischer.ch
Am 26.11.19 um 09:32 schrieb Lukasz Lenart: > [ ] Leave at test build > [ ] Alpha > [ ] Beta > [X] General Availability (GA) Works perfect in production. Thanks for your good work! Markus - To unsubscribe, e-mail:

Re: Struts 2.5.22 test build is ready

2019-11-17 Thread i...@flyingfischer.ch
Seems to run fine too. Thanks! Markus Am 17.11.19 um 20:42 schrieb Lukasz Lenart: > Hi, > > Please take a time and test the bits - any help is appreciated. Please > report any problems. I'll call for a vote in a few days if no problems > will be spotted. > > Staging Maven repo >

Re: Struts 2.5.21 test build is ready

2019-11-17 Thread i...@flyingfischer.ch
Hello I am running 2.5.21 in production in several projects. Everything is running fine and smooth. No issues so far. Markus Am 18.11.19 um 02:30 schrieb J C: > Hello. > > Did some testing of the showcase and rest-showcase applications in the 2.5.21 > test build (and a very quick test of the

Re: Struts 2.5.21 test build is ready

2019-11-11 Thread i...@flyingfischer.ch
per Markus' comments), with >> individual >> applications still able to set a limit, should they wish to do so via >> configuration. >> >> For 2.6 maybe a lower value for a default (such as Łukasz' suggestion of 256) >> would be OK, provided it is a clearly document

Re: Struts 2.5.21 test build is ready

2019-11-08 Thread i...@flyingfischer.ch
them with us? (Does that one look rational? Is it easily readable and > maintainable? If not, isn't it better to move that logic into your > action and just use maintainable?). > > Please see inline... > > On 11/8/2019 9:43 AM, i...@flyingfischer.ch wrote: >> Hello JC >>

Re: Struts 2.5.21 test build is ready

2019-11-07 Thread i...@flyingfischer.ch
eply to the dev list to let us know if that helps or not. > > Thanks, > > James. > >> It is reported in WARN level: >> >> WARN com.opensymphony.xwork2.ognl.OgnlValueStack - Could not evaluate >> this expression due to security constraints: >> >> Mar

Re: Struts 2.5.21 test build is ready

2019-11-07 Thread i...@flyingfischer.ch
It is reported in WARN level: WARN com.opensymphony.xwork2.ognl.OgnlValueStack - Could not evaluate this expression due to security constraints: Markus Am 07.11.19 um 23:12 schrieb i...@flyingfischer.ch: > See new errors like this: > > Caused by: java.lang.SecurityException: This e

Re: Struts 2.5.21 test build is ready

2019-11-07 Thread i...@flyingfischer.ch
See new errors like this: Caused by: java.lang.SecurityException: This expression exceeded maximum allowed length:.. followed by a longer OGNL expression in JSP. Markus Am 07.11.19 um 20:57 schrieb Lukasz Lenart: > Hi, > > Please take a time and test the bits - any help is appreciated. Please

Re: Max length for OGNL expression

2019-09-16 Thread i...@flyingfischer.ch
Dear Yasser I perfectly understood that the proposed change is proactive and that there are no open known vulnerabilities. ;-) Best regards Markus Am 16.09.19 um 15:42 schrieb Yasser Zamani: >> -Original Message- >> From: i...@flyingfischer.ch >> Sent: Monday, Septe

Re: Max length for OGNL expression

2019-09-16 Thread i...@flyingfischer.ch
Dear Yasser we definitively need an option to totally disable this "feature". It really depends on what kind of application you deploy. Logging a warning seems appropriate. But we should avoid logging a warning while the "feature" is disabled. I also fear that this will lead to vulnerable

Re: Max length for OGNL expression

2019-09-15 Thread i...@flyingfischer.ch
Seems to me not to be the right place to correct any possible problems, and far off any related root of a possible issue. The config would definitively need an option to be disabled totally. I expect very unexpected and hard to trace side effects, depending on the application in place. Markus

Struts Coverity Scan

2019-05-12 Thread i...@flyingfischer.ch
Just stumbled over: https://scan.coverity.com/projects/apache-struts-2 Could this be of interest? Best Markus - To unsubscribe, e-mail: dev-unsubscr...@struts.apache.org For additional commands, e-mail:

Re: Not seen this attempt before?

2019-01-20 Thread i...@flyingfischer.ch
Possibly in this section?: https://github.com/rapid7/metasploit-framework/issues/8064 Am 20.01.19 um 13:02 schrieb Greg Huber: > Any ideas? > > 14.98.162.41 - - [18/Jan/2019:18:13:32 +] "POST >

Re: [VOTE] Struts 2.5.20

2019-01-12 Thread i...@flyingfischer.ch
> [ ] Leave at test build > [ ] Alpha > [ ] Beta > [X] General Availability (GA) > Markus Do not know if this is by intention: The release notes state many library updates, and also commons-collections4 4.1 -> 4.2 https://issues.apache.org/jira/browse/WW-4978 However, the standalone

Re: jdk8 in 2.6

2019-01-12 Thread i...@flyingfischer.ch
+1 Markus Am 11.01.19 um 21:35 schrieb Aleksandr Mashchenko: > We discussed it before but it was quite some time ago. How about > upgrading to jdk8 in 2.6 version? > > - Java versions are now released more frequently > - 2.5.x will still be on jdk7 > - Currently custom converters must be

Re: [VOTE] Struts 2.5.18

2018-10-08 Thread i...@flyingfischer.ch
[ ] Leave at test build [ ] Alpha [ ] Beta [X] General Availability (GA) Thanks! Markus - To unsubscribe, e-mail: dev-unsubscr...@struts.apache.org For additional commands, e-mail: dev-h...@struts.apache.org

Re: Struts 2.5.18 test build is ready

2018-09-26 Thread i...@flyingfischer.ch
Seems to run fine here. Thanks! Markus Am 26.09.2018 um 11:50 schrieb Lukasz Lenart: > Hi, > > Please take a time and test the bits - any help is appreciated. Please > report back any problems. I'll call for a vote in a week if no > problems will be spotted. > > Staging Maven repo >

Re: New releases

2018-09-17 Thread i...@flyingfischer.ch
No further issues discovered here. Good to go. Thanks for your sustaining and continuing work! Markus Am 17.09.2018 um 08:06 schrieb Lukasz Lenart: > Hi, > > I think we are ready to release two new releases, 2.3.36 and 2.5.18: > - 2.3.36 is going to fix an issue with using ArrayList (backed

Re: [VOTE][FASTTRACK] Struts 2.5.17

2018-08-20 Thread i...@flyingfischer.ch
[ ] Leave at test build [ ] Alpha [ ] Beta [X] General Availability (GA) Works fine here. Already in production. Markus - To unsubscribe, e-mail: dev-unsubscr...@struts.apache.org For additional commands, e-mail:

Re: CVE-2014-0114

2018-06-24 Thread i...@flyingfischer.ch
1++ commons-beanutils-1.9.3.jar works here in production since ages. Markus Am 24.06.2018 um 11:37 schrieb Greg Huber: > Should we bump commons-beanutils-1.8.0.jar to the latest 1.9.3? > > struts2-tiles-plugin > > Cheers Greg >

Re: [VOTE] Struts 2.5.16

2018-03-13 Thread i...@flyingfischer.ch
[ ] Leave at test build [ ] Alpha [ ] Beta [X] General Availability (GA) +1 nb Markus - To unsubscribe, e-mail: dev-unsubscr...@struts.apache.org For additional commands, e-mail: dev-h...@struts.apache.org

Re: [VOTE][FASTTRACK] Struts 2.5.14.1

2017-11-29 Thread i...@flyingfischer.ch
[X] General Availability (GA) Markus - To unsubscribe, e-mail: dev-unsubscr...@struts.apache.org For additional commands, e-mail: dev-h...@struts.apache.org

Re: Support for actors/asynchronous request handling

2017-10-22 Thread i...@flyingfischer.ch
Am 21.10.2017 um 14:51 schrieb Yasser Zamani: > With thanks to Struts good design, fortunately, it was not as hard as I > thought and I almost finished :) > > Just one blocking problem :( Currently Struts is on servlet-api 2.4. I > remember Struts 2.6 will have servlet 2.5. And so so ... As I

Re: [VOTE][FASTTRACK] Struts 2.5.13

2017-09-04 Thread i...@flyingfischer.ch
Am 04.09.2017 um 12:07 schrieb Lukasz Lenart: > > [ ] Leave at test build > [ ] Alpha > [ ] Beta > [X] General Availability (GA) Works already perfect in production. Markus - To unsubscribe, e-mail:

Re: Struts 2.5.13 test build is ready

2017-08-25 Thread i...@flyingfischer.ch
Am 25.08.2017 um 11:53 schrieb Lukasz Lenart: > Thanks Yasser! > > Anyone else having problems with this build? > > > Regards Seems to run fine. Markus - To unsubscribe, e-mail: dev-unsubscr...@struts.apache.org For additional

Re: FW: [jira] [Comment Edited] (WW-4815) Migrating Struts 2.3.16.3 to 2.3.32

2017-08-08 Thread i...@flyingfischer.ch
On Unix try to add something like: struts.multipart.saveDir=/tmp Markus Am 08.08.2017 um 19:26 schrieb Deborah White: > Thank you, got it. :) One more question. Do you know why I am seeing this > since migrating? > > Unable to find 'struts.multipart.saveDir' property setting. Defaulting to >

Re: Struts 2.5.x

2017-07-18 Thread i...@flyingfischer.ch
Am 18.07.2017 um 07:54 schrieb Lukasz Lenart: > Hi, > > There is a few issues registered that pop up after releasing 2.5.12, I > would like to fix them and push out an another version of 2.5.x > branch. > > https://issues.apache.org/jira/projects/WW/versions/12341116 > > > Regards I didn't want to

Re: [VOTE][FASTTRACK] Struts 2.5.12

2017-07-11 Thread i...@flyingfischer.ch
[ ] Leave at test build [ ] Alpha [ ] Beta [X] General Availability (GA) Already in production and working great! Markus Am 11.07.2017 um 09:10 schrieb Lukasz Lenart: > The Apache Struts 2.5.12 test build is now available. With this > release the following security vulnerabilities were

Re: Struts 2.5.12 test build is ready

2017-07-06 Thread i...@flyingfischer.ch
Works like a charm! Thank a lot! Markus Am 06.07.2017 um 11:28 schrieb Lukasz Lenart: > Hi, > > Please take a time and test the bits - any help is appreciated. Please > report back any problems. I'll call for vote in few days if no > problems will be spotted. > > Staging Maven repo >

Re: Struts 2.5.11 not serving iclass icons

2017-07-06 Thread i...@flyingfischer.ch
lt;lukaszlen...@apache.org>: >> I was able confirm this somehow ... but I need your exact setup, what >> version of Bootstrap do you use? Do you use FontAwesome directly? >> >> There is no issue when I used a pure reference to FontAwesome (with >> their CDN) but it d

Re: Struts 2.5.11 not serving iclass icons

2017-07-05 Thread i...@flyingfischer.ch
Am 05.07.2017 um 13:23 schrieb Lukasz Lenart: > This is very strange ... I don't understand where is the problem :\ Do > you serve those CSSs files via the Strust filter as a static content? > The CSS file seems to get through. The Layout is as should. The CSS file is packed in a subdirectory of

Re: redirectAction: different behaviour depending on the name of the result

2017-06-29 Thread i...@flyingfischer.ch
> This may have other reasons. Is there a value for myParam in every case? > What have you configured for struts.url.includeParams? > > > Regards, > Christoph > > This Email was scanned by Sophos Anti Virus > You are right! It's been an issue with myParam and not the architecture. Shame... It

redirectAction: different behaviour depending on the name of the result

2017-06-29 Thread i...@flyingfischer.ch
No big deal and probably not related to 2.5.11. Is this on purpose: redirectAction behaves differently depending on the name of the result. login ${myParam} Called in action as: return "redirectToLogin"; => myParam gets transmitted as expected.

Re: Calling empty Locale

2017-06-27 Thread i...@flyingfischer.ch
> Right... switching to LocaleUtils from commons wasn't that easy as I > thought ;-) Can you register a ticket in JIRA and I will fix that :) > > > Regards Thanks Łukasz, for your ongoing great work! :-) Markus - To

Re: Struts 2.5.11 test build is ready

2017-06-27 Thread i...@flyingfischer.ch
Am 27.06.2017 um 10:05 schrieb Lukasz Lenart: > 2017-06-27 8:59 GMT+02:00 i...@flyingfischer.ch <i...@flyingfischer.ch>: >> For the time being, it really can't be shorter than this?: >> >> final LocaleProviderFactory factory = >> Actio

Calling empty Locale

2017-06-27 Thread i...@flyingfischer.ch
Sorry for all these mails. One thing more that seems to have changed: <2.5.11 calling empty locale "?request_local=" will result in locale en, if I am not mistaken. 2.5.11 calling empty locale "?request_local=" will result in locale object (not null) with property languageTag null Both versions

Re: Struts 2.5.11 test build is ready

2017-06-27 Thread i...@flyingfischer.ch
Am 27.06.2017 um 08:42 schrieb Lukasz Lenart: > 2017-06-27 8:38 GMT+02:00 i...@flyingfischer.ch <i...@flyingfischer.ch>: >> Thanks! This works fine. And you are perfectly right: >> >> StringEscapeUtils.unescapeHtml4(value.replaceAll("''", "'"));

Re: Struts 2.5.11 test build is ready

2017-06-27 Thread i...@flyingfischer.ch
> It must be a bean create by the framework, e.g. an action, then the > LocalizedTextProvider gets injected. If you want to use it in some > other context you can use this approach: > > LocalizedTextProvider provider = > ActionContext.getContext().getInstance(LocalizedTextProvider.class) >

Re: Struts 2.5.11: js based messages not showing up, when chanching default locale [resolved]

2017-06-27 Thread i...@flyingfischer.ch
Am 27.06.2017 um 08:12 schrieb Lukasz Lenart: > 2017-06-26 21:27 GMT+02:00 i...@flyingfischer.ch <i...@flyingfischer.ch>: >> Now EL brings replaces >> >> >> >> in locale en with 0.9 and in all other locales with 0,9 (note the COMMA). > Oh... thanks a

Re: Struts 2.5.11: js based messages not showing up, when chanching default locale [resolved]

2017-06-26 Thread i...@flyingfischer.ch
> Very strange: values do get replaced: > > > notif({ > msg: "Ungültige Angaben!", > type: "info", > position: "center", > opacity: 0,9, > timeout: 5000, > multiline: true, > autohide: true, > clickable: false > }); > > > But JS box will still not show up, when not on default locale... > >

Re: Struts 2.5.11: js based messages not showing up, when chanching default locale

2017-06-26 Thread i...@flyingfischer.ch
> I did some more tests: > > Test 1: in action hardcoded messages: > > jsmsg = new JSMessage("Show up!"); > > On default locale: message shows up. > Any other locale: No show up > > => Problem persists > > Test 2: in JSP hardcoded message > > > notif({ >msg: "Show up!", >

Re: Struts 2.5.11: js based messages not showing up, when chanching default locale

2017-06-26 Thread i...@flyingfischer.ch
> At the moment testing locally and not online: > > Browser send en-US,en;q=0.5 on default > OS linux on german locale > changing locale in application by ?request_locale=it > in struts.properties: struts.custom.i18n.resources=global-messages > > properties files: > >

Re: Struts 2.5.11 test build is ready

2017-06-26 Thread i...@flyingfischer.ch
Am 26.06.2017 um 08:57 schrieb Lukasz Lenart: > 2017-06-25 8:07 GMT+02:00 i...@flyingfischer.ch <i...@flyingfischer.ch>: >> I get stuck with the refactored LocalizedTextUtil: >> >> We had a change in 2.5.2 which disallowed the use of getText(String key) >&

Re: Struts 2.5.11 not serving iclass icons

2017-06-26 Thread i...@flyingfischer.ch
Am 26.06.2017 um 11:55 schrieb Lukasz Lenart: > 2017-06-26 11:50 GMT+02:00 i...@flyingfischer.ch <i...@flyingfischer.ch>: >> Yes, the import statement is already there. It is a combined css file >> (fonts and other CSS statements). Works perfect, also for 2.5.11. But

Re: Struts 2.5.11 not serving iclass icons

2017-06-26 Thread i...@flyingfischer.ch
Am 26.06.2017 um 11:01 schrieb Lukasz Lenart: > 2017-06-26 10:23 GMT+02:00 i...@flyingfischer.ch <i...@flyingfischer.ch>: >> Using FontAwesome > Same here > >> I am on thin ice: I fear the images do display as kind of textual >> representation of private use unico

Re: Struts 2.5.11 not serving iclass icons [resolved]

2017-06-26 Thread i...@flyingfischer.ch
Am 26.06.2017 um 11:17 schrieb Lukasz Lenart: > 2017-06-26 10:50 GMT+02:00 i...@flyingfischer.ch <i...@flyingfischer.ch>: >> Using >> >> instead of >> >> resolves the issue. But I still suspect a change in coding / treating >> unicode in Struts. >

Re: Struts 2.5.11 not serving iclass icons [resolved]

2017-06-26 Thread i...@flyingfischer.ch
Am 26.06.2017 um 10:23 schrieb i...@flyingfischer.ch: > Am 26.06.2017 um 09:04 schrieb Lukasz Lenart: >> 2017-06-25 15:26 GMT+02:00 i...@flyingfischer.ch <i...@flyingfischer.ch>: >>> I detected a strange issue. The problem is not present in 2.5.10.1 but >>&g

Re: Struts 2.5.11 not serving iclass icons

2017-06-26 Thread i...@flyingfischer.ch
Am 26.06.2017 um 09:04 schrieb Lukasz Lenart: > 2017-06-25 15:26 GMT+02:00 i...@flyingfischer.ch <i...@flyingfischer.ch>: >> I detected a strange issue. The problem is not present in 2.5.10.1 but >> only in 2.5.11: >> >> In jsp: >> >> This will not s

  1   2   >