Re: [TEST] Struts 6.0.2 test build is ready

2022-08-31 Thread Johannes Geppert
+1 for dedicated stack, but not sure if we should name it "default secure stack" as it implies that the other stacks are not secure.  My 2ct on this Best Regards Johannes i...@flyingfischer.ch schrieb am Mi., 31. Aug. 2022, 14:20: > Creating a new default secure stack sounds good to me.

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-31 Thread i...@flyingfischer.ch
Creating a new default secure stack sounds good to me. Thank for considering. As far as I can see there would be 4 additional interceptors in this secure stack: CoepInterceptor.java CoopInterceptor.java CspInterceptor.java FetchMetadataInterceptor.java And the appropriate resources used by

Re: [TEST] Struts 6.0.2 test build is ready

2022-08-31 Thread Lukasz Lenart
I think disabling them doesn't make sense - these are just interceptors so you can create your own stack without them. I would rather create a new default secure stack and move those interceptors into that stack, wdyt? Regards -- Łukasz + 48 606 323 122 http://www.lenart.org.pl/