Re: Process multiple uploaded files individually

2024-09-02 Thread Lukasz Lenart
pon., 2 wrz 2024 o 09:59 Florian Schlittgen napisał(a): > The ActionFileUploadInterceptor was introduced with WW-5371 and the API > has been greatly simplified as a result. However, there is a problem if > you upload several files and want to process them individually later. > This is no longer po

Re: Very fast logout of Heartbeat session

2024-08-29 Thread Lukasz Lenart
Based on the stack trace I would double check index.jsp file - looks like it has some references to Session. Just to remind you, the session isn't created anymore if not requested by developer/user, see https://issues.apache.org/jira/browse/WW-4741 wt., 27 sie 2024 o 20:54 Priti Pithadia napisał(

Re: Apache Struts IntelliJ IDEA plugin

2024-08-21 Thread Lukasz Lenart
ot; to the title (Struts > 2) is not necessary. > > If you want to be more creative, ChatGPT came up with a few ideas. ;-) > > Struts Assist > Struts Helper > Struts Toolkit > > And my personal favorite: Struts-a-Lot > > > -- Original Message -- > F

Apache Struts IntelliJ IDEA plugin

2024-08-14 Thread Lukasz Lenart
Hi, As you might know, we took over the Struts2 IDEA plugin and worked on it to be up to date and to support the latest Struts versions. Temporarily you can find the plugin here [1]. And a quick question: what should be the name of the plugin? [1] https://dist.apache.org/repos/dist/dev/struts/id

[ANN] Apache Struts 6.6.0

2024-08-09 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts version 6.6.0 is available as a “General Availability” release. The GA designation is our highest quality grade. The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framewor

Re: Struts 7.0.0-M6 - Runtime Error freemarker.cache.WebappTemplateLoader

2024-06-19 Thread Lukasz Lenart
Nice catch, would you mind creating a JIRA ticket? czw., 20 cze 2024 o 02:15 Rubens Gomes napisał(a): > I am getting the runtime error below with 7.0.0-M6. It appears that method > "rg.apache.struts2.views.freemarker.FreemarkerManager.createTemplateLoader" > > is using "freemarker.cache.WebappT

Re: Struts Java 17 and J2EE9 support

2024-06-19 Thread Lukasz Lenart
śr., 19 cze 2024 o 16:05 Ankit Garg napisał(a): > > TCS Confidential > > Hi Lukasz Lenart, > > May I request to have plan on Struts 7 please? > Any projected dateline would be great. To avoid sharing the same information in many places https://issues.apache.or

Re: Custom CSP settings

2024-06-16 Thread Lukasz Lenart
pon., 17 cze 2024 o 07:27 Nikhil P Kookkiri napisał(a): > > Hello there, > > The default CSP implementation is allowing inline styles in the JSPs. I am > looking for documentation that will help me use custom CSP settings. Since Struts 6.2.0 you can use CspSettingsAware interface to configure th

Re: [EXTERNAL] Re: POP Up Data List Window Struts 6.4 (and 6.3) v 6.1.2.1

2024-06-16 Thread Lukasz Lenart
śr., 12 cze 2024 o 13:14 Nordmeyer, William, E (Serco NA) napisał(a): > Other things we're seeing in developer tools that aren't in the attached logs: > > Content Security Policy blooks inline execution of scripts and stylesheets > The Content Security Policy prevents cross-site scripting attack

Re: [EXTERNAL] Re: POP Up Data List Window Struts 6.4 (and 6.3) v 6.1.2.1

2024-06-11 Thread Lukasz Lenart
Sent: Monday, June 10, 2024 9:26 AM > To: Struts Users Mailing List > Subject: RE: [EXTERNAL] Re: POP Up Data List Window Struts 6.4 (and 6.3) v > 6.1.2.1 > > > Lukas, > > Here are the files. > > -Original Message- > From: Lukasz Lenart > Sent: Friday,

Re: POP Up Data List Window Struts 6.4 (and 6.3) v 6.1.2.1

2024-06-07 Thread Lukasz Lenart
pt., 7 cze 2024 o 14:49 Nordmeyer, William, E (Serco NA) napisał(a): > We are looking to upgrade to Struts 6.4 and seeing issues with our PoP up > data list window. They worked in 6.1.2.1 but in 6.4, the data appears to be > in the HTML but the screens are not rendering. > > The EmployeeID isn’

Re: WW-5419 - Autoloading of tiles.xml fails in Struts-6.4.0 | Testing

2024-05-12 Thread Lukasz Lenart
pon., 29 kwi 2024 o 09:15 SARAVANAN SIVAGURU napisał(a): > I would suggest to align the library version on the struts library as same > as the tomee one. As both are from Apache community we need to have in > alignment to make it work as expected. > This is a bad idea to align to a given versio

Re: WW-5419 - Autoloading of tiles.xml fails in Struts-6.4.0 | Testing

2024-04-24 Thread Lukasz Lenart
iles.xml fails in Struts-6.4.0 | > Testing > > CAUTION: This email originated from outside of the organization. Do not click > links or open attachments unless you recognize the sender and know the > content is safe. > > > Sure, I will do > > Thanks and Regards, > Sar

Re: WW-5419 - Autoloading of tiles.xml fails in Struts-6.4.0 | Testing

2024-04-23 Thread Lukasz Lenart
wt., 23 kwi 2024 o 10:54 SARAVANAN SIVAGURU napisał(a): > Hi Luk > > Somehow I was unable to share the report files as a attachment in html > format. Am attaching the text file, output of the gradle dependencies > command for the my application. > This is for Struts 6.4.0, but could you use Stru

Re: WW-5419 - Autoloading of tiles.xml fails in Struts-6.4.0 | Testing

2024-04-22 Thread Lukasz Lenart
pon., 22 kwi 2024 o 22:40 Tellis, Wyatt napisał(a): > We’ve run into this issue as well. Using the workaround of specifying the > location via: > > > > org.apache.tiles.definition.DefinitionsFactory.DEFINITIONS_CONFIG > /WEB-INF/tiles.xml > > > doesn’t work. You can specify all the

Re: Struts2 6.4.0 - Announcements 2024

2024-04-22 Thread Lukasz Lenart
uncements option. > > > > Thanks (again), > > Davo > > > > > > From: Lukasz Lenart > Sent: Monday, April 22, 2024 12:46 PM > To: Brunstein, David > Cc: Struts Users Mailing List > Subject: Re: Struts2 6.4.0 - Announcements 2024 > > > > Hi David

Re: Struts2 6.4.0 - Announcements 2024

2024-04-22 Thread Lukasz Lenart
Hi David, pon., 22 kwi 2024 o 19:42 Brunstein, David napisał(a): > > Hi Lukasz, > > Are you planning to publish a new Announcements 2024 for the new Struts2 > version 6.4.0? > The curent page https://struts.apache.org/announce-2023.html Yes, this was already announced https://lists.apache.org/

Re: WW-5419 - Autoloading of tiles.xml fails in Struts-6.4.0 | Testing

2024-04-22 Thread Lukasz Lenart
Could you run "gradle dependencies" and post the outcome?

Re: Struts 6.4.0: is there a Tiles breaking change?

2024-04-22 Thread Lukasz Lenart
pon., 22 kwi 2024 o 15:16 Matias Rodriguez napisał(a): > > hi! I'm getting an exception when moving from version *6.3.0.2*; should we > add some annotations or something? thanks! > Struts has detected an unhandled exception: > *Messages*: > - Cannot find definition named 'indexServidor' It's pro

Re: WW-5419 - Autoloading of tiles.xml fails in Struts-6.4.0 | Testing

2024-04-22 Thread Lukasz Lenart
This fix wasn't integrated with the SNAPSHOT version yet - it exists only in the PR, if you want to test it you must clone the PR locally and build it. pon., 22 kwi 2024 o 11:08 SARAVANAN SIVAGURU napisał(a): > > Hi Luk > > Faced any issues during the testing of the fix with 6.5-SNAPSHOT version

Re: Need help to migrate to struts2.5.33 from 2.3.37

2024-04-20 Thread Lukasz Lenart
sob., 20 kwi 2024 o 14:56 Anweshan Satapathy napisał(a): > > struts-prepare > > org.apache.struts2.dispatcher.filter.StrutsPrepareFilter > > > StrutsPrepareAndExecute > > org.apache.struts2.dispatcher.filter.StrutsPrepareAndExecuteFilter > >

[ANN] Apache Struts 6.4.0

2024-04-20 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts version 6.4.0 is available as a “General Availability” release. The GA designation is our highest quality grade. The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framewor

Re: Need help to migrate to struts2.5.33 from 2.3.37

2024-04-19 Thread Lukasz Lenart
Could you post your web.xml? - To unsubscribe, e-mail: user-unsubscr...@struts.apache.org For additional commands, e-mail: user-h...@struts.apache.org

Re: Need help to migrate to struts2.5.33 from 2.3.37

2024-04-18 Thread Lukasz Lenart
Could you post the whole stacktrace? PS: Please re-use thread instead of creating a new one pt., 19 kwi 2024 o 08:16 Anweshan Satapathy napisał(a): > Hi Team > > We are trying to migrate from struts 2.3.37 to 2.5.33 updated as per > confluence page(Struts 2.3 to 2.5 migration - Apache Struts 2

Re: Struts 6.4.0 Release Date

2024-04-18 Thread Lukasz Lenart
śr., 17 kwi 2024 o 17:18 Pranish Srigiri napisał(a): > > Hi Team, > We have a major release planned in the next 2 months. For this we need to > upgrade struts to 6.4.0. We've been waiting for it to get released since > January. It would be great if we know the release timeline of v6.4.0. 6.4.0 is

Re: Trying to upgrade from struts 2.3 to 2.5-Web links giving 404 error

2024-04-18 Thread Lukasz Lenart
Did you follow the migration guideline [1]? And please post the whole stacktrace [1] https://cwiki.apache.org/confluence/display/WW/Struts+2.3+to+2.5+migration śr., 17 kwi 2024 o 14:11 Sunitha Ganapathy napisał(a): > Hi, > > > > Getting these 3 types of errors after upgrade. > >1. c.o.xwor

Re: Struts examples Hello World

2024-04-16 Thread Lukasz Lenart
niedz., 14 kwi 2024 o 20:56 Tim Mousaw napisał(a): > > I started to go through the Getting Started examples at > https://struts.apache.org/getting-started/index.html. I downloaded all the > examples from https://github.com/apache/struts-examples. I would expect > that I should be able to run `mvn

Re: Struts2 Validator failing constructor call

2024-04-16 Thread Lukasz Lenart
pt., 12 kwi 2024 o 09:57 napisał(a): > > Our path was 2.3.4.1 -> 2.3.24.1 -> 2.5.xx (2, 26, 30) -> 6.0.0 -> 6.1.1 -> > 6.1.2.1 -> 6.3.0.2 (but I left out some minor upgrades) > Currently we are in OpenJDK 17. And the problem started with 6.3.0.2? Could you revert to 6.2.0 and check if everything

Re: Struts2 Validator failing constructor call

2024-04-12 Thread Lukasz Lenart
pt., 12 kwi 2024 o 08:19 napisał(a): > > Sorry for missing the Struts version. We are on 6.3.0.2 and can't wait to > move on to 7 along with JDK 21 😊 Did you migrate from 6.2 recently? And what Java version do you use? Cheers Lulasz

Re: Struts2 Validator failing constructor call

2024-04-11 Thread Lukasz Lenart
czw., 11 kwi 2024 o 17:07 napisał(a): > I have a 10 year old struts2 web application that uses validation with rules > defined in XML files. Do you try to migrate to the latest version? What version do you use? > One of these instantiates a java.util.Date to compare the the value of a bean > w

Re: Intellij Struts 2 Plugin for 6.x DTD

2024-03-29 Thread Lukasz Lenart
I finally managed to figure out what was wrong and now the very first PR is ready https://github.com/apache/struts-intellij-plugin/pull/1 - To unsubscribe, e-mail: user-unsubscr...@struts.apache.org For additional commands, e-mail

Re: Unable to open uploaded pdf and docx file

2024-03-28 Thread Lukasz Lenart
śr., 27 mar 2024 o 02:01 Mahabir Gupta napisał(a): > > Dear Lukasz, > > Uploaded files are ok (access them on the server side once they have been > uploaded). The MD5 for the uploaded file to the server and the downloaded > file from the server is different. There is a decrease in the number of kb

Re: Unable to open uploaded pdf and docx file

2024-03-26 Thread Lukasz Lenart
I have no idea what can be wrong here. You are using your custom download mechanism instead of using Stream result [1] which isn't related to Struts itself. I would double check if uploaded files are ok (access them on the server side once they have been uploaded). [1] https://struts.apache.org/co

Re: struts 2.5.33 - ERROR DefaultClassFinder - Unable to read class - IncompatibleClassChangeError

2024-03-24 Thread Lukasz Lenart
ccessorImpl.invoke0(Native Method) > ~[?:1.8.0_382] > at > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) > ~[?:1.8.0_382] > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) > ~[?:1.8.0_382]

Re: Radio Buttons issue in 6.3.x

2024-03-20 Thread Lukasz Lenart
śr., 20 mar 2024 o 19:45 Nordmeyer, William, E (Serco NA) napisał(a): > > I remember reading a few months back about an issue with radio buttons in > Struts 6.3 and that the issue was going to be resolved in 6.4. > > 2 questions - > 1. is there a bug entry that I can reference and monitor? I

Re: struts 2.5.33 - ERROR DefaultClassFinder - Unable to read class - IncompatibleClassChangeError

2024-03-20 Thread Lukasz Lenart
śr., 20 mar 2024 o 01:34 DAngel napisał(a): > ERROR org.apache.struts2.convention.DefaultClassFinder - Unable to read > class [ mi.action.class] > java.lang.IncompatibleClassChangeError: class > org.apache.struts2.convention.DefaultClassFinder$InfoBuildingVisitor has > interface org.objectweb.asm.

Re: Radio button selection is not being saved on the front end

2024-03-12 Thread Lukasz Lenart
this means I have to wait for Struts > 6.4 before the radio button will be able to display on the frontend? > Kindly confirm. Thank you. > > Regards > Mahabir > > On Mon, Mar 11, 2024 at 5:29 PM Lukasz Lenart wrote: >> >> I assume you meant Struts 2.5 and I ass

Re: Radio button selection is not being saved on the front end

2024-03-11 Thread Lukasz Lenart
l be fixed in Struts 6.4 >> (https://issues.apache.org/jira/browse/WW-5365). While it's not a Boolean >> radio button, it does sound like this is because the value is being >> processed as a string literal and not as an Ognl expression. >> >> Cheers, >> >&g

Re: Intellij Struts 2 Plugin for 6.x DTD

2024-03-11 Thread Lukasz Lenart
I started working on IP Clearance procedure and prepared a simple GH Actions workflow (among other things), yet some tests are failing and I wonder if this can be related to my changes https://github.com/apache/struts-intellij-plugin/pull/1 Running locally I get: [ 1623] WARN - #c.i.o.v.n.p.l

Re: Radio button selection is not being saved on the front end

2024-03-10 Thread Lukasz Lenart
pon., 11 mar 2024 o 04:54 Mahabir Gupta napisał(a): > The radio button is working perfectly when using Struts2. I only did an > upgrade the Struts6.3.0.2 without making any changes to the code. When using > Struts6.3.0.2 the radio button issue arises. There is no change of code made. Could you

Re: Radio button selection is not being saved on the front end

2024-03-09 Thread Lukasz Lenart
śr., 6 mar 2024 o 08:08 Mahabir Gupta napisał(a): > DotsCarRental dotsCarRental = new DotsCarRental(); > dotsCarRental = (DotsCarRental) > session.getAttribute(DBConstants.sessionCarId); You don't have to create an instance if in the next line you assign a value from session, this is enough: Do

Re: The absolute uri: [http://tiles.apache.org/tags-tiles] cannot be resolved

2024-03-06 Thread Lukasz Lenart
ou may sustain as a result > of software viruses > -- > *From:* Lukasz Lenart > *Sent:* Saturday, March 2, 2024 2:55 PM > *To:* Struts Users Mailing List > *Subject:* Re: The absolute uri: [http://tiles.apache.org/tags-tiles] > cannot be resolved > > [You don'

Re: Struts 6.3 Issue Uploading Files

2024-03-05 Thread Lukasz Lenart
Can you take a look at this PR? Can you test it? https://github.com/apache/struts/pull/892 śr., 6 mar 2024 o 07:51 Lukasz Lenart napisał(a): > > pon., 4 mar 2024 o 00:28 Zoran Avtarovski > napisał(a): > > I tried to raise a ticket to include some logging in the isMultipartReques

Re: Struts 6.3 Issue Uploading Files

2024-03-05 Thread Lukasz Lenart
pon., 4 mar 2024 o 00:28 Zoran Avtarovski napisał(a): > I tried to raise a ticket to include some logging in the isMultipartRequest > function to record why it failed but I don't have an account anymore. I've created the ticket https://issues.apache.org/jira/browse/WW-5401 Cheers Lukasz -

Re: The absolute uri: [http://tiles.apache.org/tags-tiles] cannot be resolved

2024-03-02 Thread Lukasz Lenart
Please create a new thread instead of mixing in into totally different discussion czw., 29 lut 2024 o 01:53 Mahabir Gupta napisał(a): > > Hi I am doing a struts2 upgrade to struts 6.3.0.2. When I am uploading a > file I am getting java.lang.noclassdeffounderror: could not initialise > class org.a

Re: The absolute uri: [http://tiles.apache.org/tags-tiles] cannot be resolved

2024-03-02 Thread Lukasz Lenart
Do you run it from within Eclipse? Is it related to this bug? https://bugs.eclipse.org/bugs/show_bug.cgi?id=493277 I just tested the example tiles app on Jetty and everything was ok https://github.com/apache/struts-examples/tree/master/tiles czw., 29 lut 2024 o 10:40 SARAVANAN SIVAGURU napisał(a

Re: Struts 6.3 Issue Uploading Files

2024-02-29 Thread Lukasz Lenart
The request must match the following regex [1], more details in the docs [2], yet I notice there is no logging around this logic, feel free to create a ticket to improve that. [1] https://github.com/apache/struts/blob/master/core/src/main/java/org/apache/struts2/dispatcher/Dispatcher.java#L110 [2

Re: Intellij Struts 2 Plugin for 6.x DTD

2024-02-25 Thread Lukasz Lenart
Finally all is set, the code has been donated & imported and also the plugin has been transferred under ASF org https://plugins.jetbrains.com/organizations/apache Time to get familiar with the code base :D Cheers Lukasz wt., 6 lut 2024 o 10:24 Lukasz Lenart napisał(a): > > Cod

Re: Struts Java 17 and J2EE9 support

2024-02-20 Thread Lukasz Lenart
wt., 20 lut 2024 o 15:29 Nate Kerkhofs napisał(a): > Is there a specific launch window Apache is targeting for the launch of > Struts 7 and the associated migration guide? Nope, yet I want to release Struts 6.4.0 and then probably start working on releasing Struts 7. This is also related to EOF

Re: Struts Java 17 and J2EE9 support

2024-02-19 Thread Lukasz Lenart
it would work with Java 17 and J2EE 9? > > Thank you. > > Regards, > Ankit Garg > > -Original Message- > From: Lukasz Lenart > Sent: Thursday, December 7, 2023 1:00 PM > To: announceme...@struts.apache.org > Cc: annou...@apache.org > Subject: [ANN] Ap

Re: Requesting support on struts tiles plugin migration

2024-02-19 Thread Lukasz Lenart
What is "Screen xxx could not be found in any context"? Is it your custom code? I would suggest migrating to standalone Tiles 3 first and then migrate to the Struts Tiles in Struts 6.x. pon., 19 lut 2024 o 12:28 SARAVANAN SIVAGURU napisał(a): > Hi Team > > I am trying to migrate the Apache Tiles

Re: allowed-methods tag not working

2024-02-08 Thread Lukasz Lenart
czw., 8 lut 2024 o 16:39 apacheStrutsUsers8 napisał(a): > > I have a Struts app which I am upgrading from Struts 2.5 to Struts 6. In my > struts xml file, I currently have actions which have the allowed-methods tag > like this: > > > /done.jsp > start, finish, next > > > However, when I try to

Re: Intellij Struts 2 Plugin for 6.x DTD

2024-02-06 Thread Lukasz Lenart
Code has been donated to ASF, I created a new repo [1], yet I have to import the code [2] [1] https://github.com/apache/struts-intellij-plugin [2] https://github.com/JetBrains/intellij-obsolete-plugins/tree/master/struts2 Cheers Lukasz sob., 30 gru 2023 o 10:57 Lukasz Lenart napisał(a

Re: Velocity tags Issue after Struts upgrade to 2.5.33

2024-01-31 Thread Lukasz Lenart
Damn... my fault :( > I recently upgraded my Struts version from 2.5.22 to 2.5.33 śr., 31 sty 2024 o 16:18 Lukasz Lenart napisał(a): > > śr., 31 sty 2024 o 16:01 Lamia Wertani napisał(a): > > It's unclear why this wasn't necessary in the previous version (2.5.22

Re: Velocity tags Issue after Struts upgrade to 2.5.33

2024-01-31 Thread Lukasz Lenart
śr., 31 sty 2024 o 16:01 Lamia Wertani napisał(a): > It's unclear why this wasn't necessary in the previous version (2.5.22) > because everything worked fine without it. So you have migrated from 2.5.22 (not 2.5.32 as in the first message) to 2.5.33 then :D Regards Łukasz ---

Re: Velocity tags Issue after Struts upgrade to 2.5.33

2024-01-30 Thread Lukasz Lenart
wt., 30 sty 2024 o 10:01 Lamia Wertani napisał(a): > > response: {"messages":["Group Test successfully added"],"result":"success"} > > The same response is displayed on a blank page. But this is JSON so I have no idea how does it relate to Velocity - I would assume you have a problem with JS on

Re: Velocity tags Issue after Struts upgrade to 2.5.33

2024-01-30 Thread Lukasz Lenart
wt., 30 sty 2024 o 09:09 Lamia Wertani napisał(a): > > Yes, the save works fine. > I have attached a screenshot of the response. Attachments won't pass, only .txt files are allowed Regards Łukasz - To unsubscribe, e-mail: use

Re: Velocity tags Issue after Struts upgrade to 2.5.33

2024-01-29 Thread Lukasz Lenart
pon., 29 sty 2024 o 20:11 Lamia Wertani napisał(a): > > I have attached a file containing the generated HTML. This looks good > > However, instead of redirecting me to the domains list, it leads to a > > blank page displaying the result. If the save works, it means the response from action is b

Re: Can I get some help with a file upload issue?

2024-01-27 Thread Lukasz Lenart
It would be better to post the whole tag example plus you action class pon., 22 sty 2024 o 22:31 Doolin, Kyle napisał(a): > name="vfcForm.fileNameDel" "vfcForm" is a field in your action with proper getter, right? "fileNameDel" is a field in the bean "vfcForm", right? If yes, you must h

Re: Struts2 Intellij Plugin v2023.3.2

2024-01-15 Thread Lukasz Lenart
niedz., 14 sty 2024 o 19:16 Burton Rhodes napisał(a): > > If anyone needs a working version of the Intellij Struts 2 Plugin, I > have updated the plugin to work with latest version of Intellij 2023.3.2 > in my personal fork. > > https://github.com/burtonrhodes/intellij-obsolete-plugins/releases/ta

Re: [EXTERNAL] Re: Trouble with tag after upgrading from struts v2.5.31 to v6.3.0.2

2024-01-12 Thread Lukasz Lenart
bbf4[war:BBS/BBSWeb.war] > > Can you please assist us. > > Thanks. > > > Noel Deleon > CRIS/ICRIS, 201-828-8524 > > > > > > > > > -Original Message- > From: Lukasz Lenart > Sent: Friday, January 12, 2024 12:40 AM > To: Struts Users M

Re: Trouble with tag after upgrading from struts v2.5.31 to v6.3.0.2

2024-01-11 Thread Lukasz Lenart
czw., 11 sty 2024 o 22:49 Burton Rhodes napisał(a): > > If I were to guess they removed the "?no_esc" flag in version 6.x in the > .ftl file. That said, it's easy to override this. (Assuming you are > using the Struts "simple" template) Locate the file > [struts2-core-6.3.0.2.jar]\template\simpl

Re: CVE-2023-49735 in Apache Tiles

2024-01-10 Thread Lukasz Lenart
One correction: I missed the word "onwards" which means Tiles 3 is also affected, yet I assume the report itself is invalid.

Re: CVE-2023-49735 in Apache Tiles

2024-01-10 Thread Lukasz Lenart
Hi Sebastian, To be honest I have no idea why this triggers any alert. The vulnerability targets Tiles 2.0 [1] while Struts (even before merging the codebase) is using Tiles 3 which shouldn't be affected. This could be an issue of false positive alert in OWASP. Also the vulnerability report looks

Re: Trouble with tag after upgrading from struts v2.5.31 to v6.3.0.2

2024-01-09 Thread Lukasz Lenart
wt., 9 sty 2024 o 20:04 Pranish Srigiri napisał(a): > I also noticed that 6.4 requires a new dependency called caffein. My server > wasn't starting until I included this dependency, > https://central.sonatype.com/artifact/com.github.ben-manes.caffeine/caffeine Yes, this is something to be address

Re: Trouble with tag after upgrading from struts v2.5.31 to v6.3.0.2

2024-01-09 Thread Lukasz Lenart
wt., 9 sty 2024 o 20:01 Pranish Srigiri napisał(a): > Hi Lukasz, > I'm not sure if the PR is included in the present Snapshot available here. > https://repository.apache.org/content/groups/snapshots/org/apache/struts/struts2-core/6.4.0-SNAPSHOT/ > I tried to test with this version of the Snapshot

Re: Trouble with tag after upgrading from struts v2.5.31 to v6.3.0.2

2024-01-09 Thread Lukasz Lenart
pon., 8 sty 2024 o 20:21 Pranish Srigiri napisał(a): > Hi Lukasz, > I think the PR could address the problem. I see that the fix-version of > WW-5365 is 6.4. When do you think v6.4 is going to go 'GA'? Is there a way > to test this PR? Version 6.4.0 will be released once this issue is resolved [1

Re: trouble replacing

2024-01-07 Thread Lukasz Lenart
czw., 4 sty 2024 o 12:33 Patrice DUROUX napisał(a): > In the concerned webapp project, some JSP have code like: > > > ... > var speciesData = ; > ... > > > And if I just replace in it

Re: Trouble with tag after upgrading from struts v2.5.31 to v6.3.0.2

2024-01-07 Thread Lukasz Lenart
Could this PR [1] address your problem? [1] https://github.com/apache/struts/pull/835 Regards Łukasz - To unsubscribe, e-mail: user-unsubscr...@struts.apache.org For additional commands, e-mail: user-h...@struts.apache.org

Re: Struts 6.3 tags do not automatically evaluate the value field against the ognl stack

2024-01-07 Thread Lukasz Lenart
This PR [1] should fix the problem. There was a gap in our unit tests which allowed us to introduce the previous change that broke evaluation of the value attribute. [1] https://github.com/apache/struts/pull/835 Regards Łukasz

Re: CVE-2023-49735 in Apache Tiles

2024-01-02 Thread Lukasz Lenart
wt., 2 sty 2024 o 13:34 Sebastian Götz napisał(a): > Hello to anybody and an happy new year! Happy New Year! > Our dependency check startet to fail last year already marking > struts2-tiles-plugin as the source of a security issue. As the plugin > uses Apache Tiles 3.0.8 underneath it is affecte

Re: Intellij Struts 2 Plugin for 6.x DTD

2023-12-30 Thread Lukasz Lenart
pt., 22 gru 2023 o 14:49 Burton Rhodes napisał(a): > > Lukasz, > It appears the Struts 2 Intellij Plugin needs to be updated after > upgrading to Intellij 2023.3. I am happy to help bump the version > numbers, but I'm not sure where the Struts repository is for this > plugin. I know you were goi

Re: New warning message appearing with version 6.3 - SecurityMemberAccess - Access to non-public ... is blocked!

2023-12-19 Thread Lukasz Lenart
pon., 18 gru 2023 o 19:45 Ralph Grove napisał(a): > Ok, so you use the bootstrap plugin so this the problem https://github.com/struts-community-plugins/struts2-bootstrap/pull/109 yet this isn't released yet and we should do it Regards -- Łukasz mobile +48 606 323 122 http://www.lenar

Re: New warning message appearing with version 6.3 - SecurityMemberAccess - Access to non-public ... is blocked!

2023-12-17 Thread Lukasz Lenart
sob., 16 gru 2023 o 19:10 Ralph Grove napisał(a): > The setup action declares it this way: > > private HashMap statuses; > > statuses = User.getStatusMap(); > > > And in the User class it’s created in the get method: > > public static HashMap getStatusMap() { > HashMap

Re: New warning message appearing with version 6.3 - SecurityMemberAccess - Access to non-public ... is blocked!

2023-12-16 Thread Lukasz Lenart
pt., 15 gru 2023 o 16:34 Grove, Ralph - groverf napisał(a): > > After upgrading from Struts 6.1.1 to 6.3.0.2, these messages began appearing > in the log, always four at a time: > > [WARN ] 2023-12-15 07:33:15 [https-jsse-nio-8443-exec-109] > SecurityMemberAccess - Access to non-public [protecte

Re: Add context to CspInterceptor reportUri

2023-12-16 Thread Lukasz Lenart
sob., 16 gru 2023 o 17:04 Andreas Sachs napisał(a): > > Hello, > i'm using the CspInterceptor and want to add a reportUri. The destination is > an action defined in my application. > > To set the reportUri in struts.xml i have to specify the complete url (with > context). > > /context/report.act

Re: FW: [ANN] Apache Struts 6.3.0.2 & 2.5.33

2023-12-11 Thread Lukasz Lenart
pon., 11 gru 2023 o 16:09 Ankit Garg napisał(a): > May I check if Struts 6.x supports Java 17 with J2EE 9 specification? Java 17 is supported but JakartaEE is a totally different kind of beast and it will be supported in Struts 7.x - there is a plan to release a first M1 version soon [1] [1] htt

Fwd: [ANN] Apache Struts 6.3.0.2 & 2.5.33

2023-12-06 Thread Lukasz Lenart
FYI -- Forwarded message - Od: Lukasz Lenart Date: czw., 7 gru 2023 o 08:30 Subject: [ANN] Apache Struts 6.3.0.2 & 2.5.33 To: Cc: The Apache Struts group is pleased to announce that Apache Struts versions 6.3.0.2 & 2.5.33 are available as “General Availability” relea

CVE-2023-50164: Apache Struts: File upload component had a directory traversal vulnerability

2023-12-06 Thread Lukasz Lenart
Severity: critical Affected versions: - Apache Struts 2.0.0 through 2.5.32 - Apache Struts 6.0.0 through 6.3.0.1 Description: An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to p

Re: The different output with Date whether the Http request have application/json

2023-12-05 Thread Lukasz Lenart
I wouldn't mix the REST plugin (which has it's own JSON handler) with the JSON plugin - use one or another. Regards -- Łukasz mobile +48 606 323 122 http://www.lenart.org.pl/ - To unsubscribe, e-mail: user-unsubscr...@struts.ap

Re: Struts 6.3 tags do not automatically evaluate the value field against the ognl stack

2023-11-30 Thread Lukasz Lenart
wt., 28 lis 2023 o 17:43 Yasser Zamani napisał(a): > > Hi Nate, > > Thanks for the detailed info and the PoC which enabled me to debug the issue! > > The issue is introduced by [1] lines insertions which has changed the path of > the execution to findValue(expr, class) instead of findValue(expr).

Re: Struts 6.3 tags do not automatically evaluate the value field against the ognl stack

2023-11-25 Thread Lukasz Lenart
Hello Nate, I approved your message but to get replies from the members of the Struts User group please subscribe to the list [1] [1] https://struts.apache.org/mail.html Cheers Lukasz pt., 24 lis 2023 o 16:32 Yasser Zamani napisał(a): > > Hi Nate, > > Thanks for reaching out! > > What I can't u

[ANN] Apache Struts 2.5.x EOL

2023-10-30 Thread Lukasz Lenart
The Apache Struts Project Team would like to inform you that the Struts 2.5.x web framework will reach its end of life in 6 months and won’t be officially supported. Please check the following reading to find more details. https://struts.apache.org/struts25-eol-announcement Apache Struts 2.5.x EO

Commercial support

2023-10-20 Thread Lukasz Lenart
Hi, I've prepared a PR with a list of companies which provide Commercial Support for Apache Struts and JavaEE applications built based on the framework. Do you know any of that? https://github.com/apache/struts-site/pull/207 Regards -- Łukasz + 48 606 323 122 http://www.lenart.org.pl/ ---

Re: ViewPreparer issue after updating from 6.2.0 to 6.3.0.1

2023-10-03 Thread Lukasz Lenart
wt., 3 paź 2023 o 17:05 Chris Scroll napisał(a): > > After I updated to struts 6.3.0.1 I am receiving the following exception: > > java.lang.ClassCastException: helpers.preparer.BreadCrumbPreparer cannot be > cast to org.apache.tiles.api.preparer.ViewPreparer > > If I revert back to struts2-tiles-

Re: Form array data disappearing if array is over 256?

2023-09-30 Thread Lukasz Lenart
pt., 29 wrz 2023 o 23:42 Chris Scroll napisał(a): > > I upgraded from struts 2.5.30 to 6.3.0.1 and updated to the new > jakarta-stream to fix an issue. > > My List: > private List tags; > > If a form has over 256 array elements (Example: tag[0] to tag[300]) and it > is submitted/posted I only get

Re: Implementation Of Authorization and Authorization in struts2.5

2023-09-15 Thread Lukasz Lenart
pt., 15 wrz 2023 o 07:09 Tanveer Alaie napisał(a): > Could you suggest the best way to implement the Authorization and > Authorization in struts2.5 This is a wide question and it would be good to be more specific, what kind of requirements do you have? In most cases you can use a dedicated inter

Re: 💥Митна база 2023. Оновлення ✅

2023-09-13 Thread Lukasz Lenart
Sorry, my mistake :( I approved a wrong message instead of the announcement one :\ śr., 13 wrz 2023 o 15:54 Імпорт, експорт України napisał(a): > > імпорт та експорт в Excel, CronosДоступна > повна митна база України > 01 січня - 31 серпня 2023 > Це єдине в Україні джерело: > - реальних клієнтів

[ANN] Apache Struts 6.3.0.1, 6.1.2.2, 2.5.32

2023-09-13 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts versions 6.3.0.1, 6.1.2.2 & 2.5.32 are available as “General Availability” releases. The GA designation is our highest quality grade. The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web appli

[ANN] Apache Struts 6.3.0

2023-09-04 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts version 6.3.0 is available as a “General Availability” release. The GA designation is our highest quality grade. The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framewor

Re: Intellij Struts 2 Plugin for 6.x DTD

2023-09-03 Thread Lukasz Lenart
Just to keep you in the loop - we are in touch with Jetbrains to donate the plugin to ASF :) sob., 26 sie 2023 o 15:50 Burton Rhodes napisał(a): > > Nice. Sounds good. > > > -- Original Message -- > From "Lukasz Lenart" > To "Struts Users Mailin

Re: How to implement s:checkbox inverse value?

2023-09-02 Thread Lukasz Lenart
As far I understand you need this pt., 1 wrz 2023 o 14:15 Burton Rhodes napisał(a): > > Not sure why I am hung up on this, but I'm trying to present a simple > checkbox that functions inversely to the parameter value. In other words, > when the value is true, the checkbox should be unchecked (a

Re: Jakarta EE9/10

2023-08-29 Thread Lukasz Lenart
Not yet wt., 29 sie 2023 o 17:11 Prasanth napisał(a): > > Hi Lukasz, > > Do you know if the work has started to migrate Struts2 to Jakarta EE? > > Thanks, > Prasanth > > On 11/1/22 4:05 AM, Lukasz Lenart wrote: > > pon., 31 paź 2022 o 15:20 Prasanth napisał(a):

Re: Intellij Struts 2 Plugin for 6.x DTD

2023-08-26 Thread Lukasz Lenart
sob., 26 sie 2023 o 14:09 Burton Rhodes napisał(a): > Curious... with a separate repository, how would you submit a PR to intellij > with an updated version? Do you think they review/accept a version from > another repository or would you have to copy code over to the > "intellij-obsolete-plugi

Re: Intellij Struts 2 Plugin for 6.x DTD

2023-08-26 Thread Lukasz Lenart
#1 is solved in my current release. However, with #2 I am stuck. If you > can figure out how to implement some tests, the PR would be accepted and > patched into the Intellij Plugin Repository which would be ideal. > > Thanks, > Burton > > On Sun, Jul 30, 2023 at 12:57 AM Lukasz

Re: Tiles in Struts 6.2.0

2023-08-17 Thread Lukasz Lenart
śr., 16 sie 2023 o 12:44 Yew Hwa Ho napisał(a): > > Hi Lukasz, > > Can I check if there is a timeline for the release of Struts 6.2 version > which contains the integrated Tiles package? Tiles will be integrated into Struts 6.3.0 - 6.2.0 has been already released [1]. And all the important issues

Re: Set tag not working in 6.2.0

2023-08-16 Thread Lukasz Lenart
pon., 14 sie 2023 o 19:52 Tellis, Wyatt napisał(a): > Any luck with tracking the cause? Yeah, I finally found the core issue, it's related to https://issues.apache.org/jira/browse/WW-5196 Basically instead of using: public Object get(final String key) { return request.getAttribute(key); }

Re: Set tag not working in 6.2.0

2023-08-02 Thread Lukasz Lenart
; On 6.1.2.1 you get: > > Set attempt #1: success > Set attempt #2: success > > > But on 6.2.0 you only get: > > Set attempt #1: success > Set attempt #2: > > > > Note: the call to returns nothing in > 6.2.0 > > Wyatt > > > -Origina

Re: Intellij Struts 2 Plugin for 6.x DTD

2023-07-29 Thread Lukasz Lenart
czw., 13 lip 2023 o 19:11 Burton Rhodes napisał(a): > > Apologies for the additional email, but I believe this latest version is > working properly: > https://github.com/burtonrhodes/intellij-obsolete-plugins/releases/tag/v2023.2.2 > > I welcome any feedback. Thanks a lot Burton for taking care o

Re: Set tag not working in 6.2.0

2023-07-29 Thread Lukasz Lenart
sob., 29 lip 2023 o 15:38 Tellis, Wyatt napisał(a): > > No, its just the standard JSTL Core set tag: Just tested the following setup and it just works with Struts 6.2.0 and Java 8/11/17 ${listType} / ${lcType} Regards -- Łukasz + 48 606 323 122 http://www.lenart.org.pl/ -

  1   2   3   4   5   6   7   8   9   10   >