[jira] [Commented] (WW-4900) NotSerializableException: com.opensymphony.xwork2.inject.ContainerImpl$ConstructorInjector when using ExecuteAndWait interceptor

2017-12-13 Thread Erica Kane (JIRA)
[ https://issues.apache.org/jira/browse/WW-4900?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16289195#comment-16289195 ] Erica Kane commented on WW-4900: Glad I could help the security at least. :/ I wrote custom code for my own

[jira] [Created] (WW-4900) NotSerializableException: com.opensymphony.xwork2.inject.ContainerImpl$ConstructorInjector when using ExecuteAndWait interceptor

2017-12-05 Thread Erica Kane (JIRA)
Erica Kane created WW-4900: -- Summary: NotSerializableException: com.opensymphony.xwork2.inject.ContainerImpl$ConstructorInjector when using ExecuteAndWait interceptor Key: WW-4900 URL:

[jira] [Commented] (WW-4873) NotSerializableException - org.apache.struts2.dispatcher.StrutsRequestWrapper

2017-12-05 Thread Erica Kane (JIRA)
[ https://issues.apache.org/jira/browse/WW-4873?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16279077#comment-16279077 ] Erica Kane commented on WW-4873: We are having a very similar issue with the ExecuteAndWait interceptor,

[jira] [Commented] (WW-4900) NotSerializableException: com.opensymphony.xwork2.inject.ContainerImpl$ConstructorInjector when using ExecuteAndWait interceptor

2017-12-12 Thread Erica Kane (JIRA)
[ https://issues.apache.org/jira/browse/WW-4900?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16287770#comment-16287770 ] Erica Kane commented on WW-4900: Hi, after several days of working on this I wanted to make a comment. You

[jira] [Comment Edited] (WW-5177) Support testing with JUnit 5

2023-03-13 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5177?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17699615#comment-17699615 ] Erica Kane edited comment on WW-5177 at 3/13/23 12:48 PM: -- As someone with a

[jira] [Commented] (WW-5294) s:url tag usage in a public page triggers a warning to not expose JSP pages directly

2023-03-13 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5294?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17699672#comment-17699672 ] Erica Kane commented on WW-5294: No, it is not. There is no reason it should, as it is essentially a static

[jira] [Created] (WW-5294) s:url tag usage in a public page triggers a warning to not expose JSP pages directly

2023-03-13 Thread Erica Kane (Jira)
Erica Kane created WW-5294: -- Summary: s:url tag usage in a public page triggers a warning to not expose JSP pages directly Key: WW-5294 URL: https://issues.apache.org/jira/browse/WW-5294 Project: Struts 2

[jira] [Commented] (WW-5177) Support testing with JUnit 5

2023-03-13 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5177?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17699625#comment-17699625 ] Erica Kane commented on WW-5177: It requires Java 8. > Support testing with JUnit 5 >

[jira] [Commented] (WW-5177) Support testing with JUnit 5

2023-03-13 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5177?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17699615#comment-17699615 ] Erica Kane commented on WW-5177: As someone with a similar issue, I can get classes that extend

[jira] [Commented] (WW-5294) s:url tag usage in a public page triggers a warning to not expose JSP pages directly

2023-03-13 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5294?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17699718#comment-17699718 ] Erica Kane commented on WW-5294: I want to make sure I'm understanding this correctly, because this has

[jira] [Closed] (WW-5294) s:url tag usage in a public page triggers a warning to not expose JSP pages directly

2023-03-13 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5294?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Erica Kane closed WW-5294. -- Resolution: Won't Fix Both s:a and s:url trigger the warning, as they should. > s:url tag usage in a public page

[jira] [Commented] (WW-5294) s:url tag usage in a public page triggers a warning to not expose JSP pages directly

2023-03-13 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5294?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17699779#comment-17699779 ] Erica Kane commented on WW-5294: I'm going to close this. I was able to trigger the warning on s:a as well

[jira] [Commented] (WW-5294) s:url tag usage in a public page triggers a warning to not expose JSP pages directly

2023-03-15 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5294?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17700615#comment-17700615 ] Erica Kane commented on WW-5294: Yes, we have quite a few Actions already... :) I will say that it was very

[jira] [Commented] (WW-5141) Support for JEE 9+

2023-07-19 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5141?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17744781#comment-17744781 ] Erica Kane commented on WW-5141: Glad to hear it. :) We also want to move into the Jakarta namespace. >

[jira] [Commented] (WW-5141) Support for JEE 9+

2023-07-19 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5141?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17744797#comment-17744797 ] Erica Kane commented on WW-5141: [~rossgreig] as an FYI, we use the latest version of Tomcat 9 with the

[jira] [Commented] (WW-5141) Support for JEE 9+

2023-07-25 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5141?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17747245#comment-17747245 ] Erica Kane commented on WW-5141: ..and also on Maven Central, albeit a little tricky to find:

[jira] [Commented] (WW-5141) Support for JEE 9+

2023-07-24 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5141?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17746542#comment-17746542 ] Erica Kane commented on WW-5141: 2.0.0-M1 of Commons File Upload has been released now:

[jira] [Commented] (WW-5400) CSP interceptor only allows very limited configuration

2024-03-06 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5400?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17824024#comment-17824024 ] Erica Kane commented on WW-5400: Lukasz I will certainly give that a try. I interpreted `addCspHeaders` as

[jira] [Commented] (WW-5400) CSP interceptor only allows very limited configuration

2024-03-06 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5400?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17824059#comment-17824059 ] Erica Kane commented on WW-5400: The addCspHeaders is singular, which is good. But I still don't want to put

[jira] [Commented] (WW-5084) Content Security Policy support

2024-03-06 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5084?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17824030#comment-17824030 ] Erica Kane commented on WW-5084: I think to disable the CSP interceptor the earlier comment should reference

[jira] [Commented] (WW-5400) CSP interceptor only allows very limited configuration

2024-03-07 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5400?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17824535#comment-17824535 ] Erica Kane commented on WW-5400: I already wrote this for our company, so I will go ahead and make a pull

[jira] [Created] (WW-5400) CSP interceptor only allows very limited configuration

2024-03-05 Thread Erica Kane (Jira)
Erica Kane created WW-5400: -- Summary: CSP interceptor only allows very limited configuration Key: WW-5400 URL: https://issues.apache.org/jira/browse/WW-5400 Project: Struts 2 Issue Type:

[jira] [Commented] (WW-5400) CSP interceptor only allows very limited configuration

2024-03-25 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5400?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17830732#comment-17830732 ] Erica Kane commented on WW-5400: Hi Lukasz, yes, our version is live in production. I am on spring break --

[jira] [Commented] (WW-5400) CSP interceptor only allows very limited configuration

2024-04-10 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5400?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17835910#comment-17835910 ] Erica Kane commented on WW-5400: [~lukaszlenart] I have submitted a pull request for my changes (username

[jira] [Commented] (WW-5400) CSP interceptor only allows very limited configuration

2024-04-10 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5400?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17835911#comment-17835911 ] Erica Kane commented on WW-5400: Also the documentation should be updated, once live, or no one will know

[jira] [Commented] (WW-5400) CSP interceptor only allows very limited configuration

2024-04-15 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5400?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17837280#comment-17837280 ] Erica Kane commented on WW-5400: [~lukaszlenart] I've made the requested code changes. Please see my

[jira] [Commented] (WW-5141) Support for JEE 9+

2024-04-17 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5141?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17838394#comment-17838394 ] Erica Kane commented on WW-5141: Hi, I wanted to check in on this, as Spring 5 and Spring Security 5 are

[jira] [Commented] (WW-5400) CSP interceptor only allows very limited configuration

2024-04-19 Thread Erica Kane (Jira)
[ https://issues.apache.org/jira/browse/WW-5400?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17839004#comment-17839004 ] Erica Kane commented on WW-5400: It seemed the simplest way, this is a parameter in struts.xml. We have