Commit Graph

5450 Commits

Author SHA1 Message Date
Lukasz Lenart 2eeac367fe WW-5065 Cleans up code and marks old constructor as deprecated 2020-04-24 09:32:50 +02:00
Lukasz Lenart 30b43044a3 WW-5065 Defines a new flag to control appending params 2020-04-23 07:13:14 +02:00
Lukasz Lenart 5c82f0246e Merge pull request #400 from atkaiser/WW5065-FixAbstractMatcherReplaceParams
[WW-5065] Removing unnecessary part of AbstractMatcher#replaceParameters
2020-04-22 06:59:21 +02:00
Lukasz Lenart fff35cfd9d Merge pull request #402 from JCgH4164838Gh792C124B5/WW-5067-25x-Fix1
WW-5067-Fix1 (correct accidental artifactId change)
2020-04-20 07:45:58 +02:00
Lukasz Lenart 1526b36dd6 Merge pull request #404 from JCgH4164838Gh792C124B5/WW-5069
Initial fix for WW-5069 (improve build behaviour JDK9+)
2020-04-20 07:23:57 +02:00
JCgH4164838Gh792C124B5 6d6a422db7 Initial fix for WW-5069:
- Force US Locale for two tests that use date strings of the form
MM/DD/CCYY.
- When the tests/build are run in an environment with a non-US Locale
and newer JDKs the tests may fail due to inability to parse the US date
format.

Note: Was noticed on Windows 10 with JDK11, but could affect other
environments when run in a non-US Locale.
2020-04-19 21:50:09 -04:00
JCgH4164838Gh792C124B5 5cf57b9132 WW-5067-Fix1
- Accidental change of artifactId when groupId was changed for weld-se in
original PR.  This commit restores the originally intended artifactId.
2020-04-18 15:49:44 -04:00
Lukasz Lenart f4c0135878 Merge pull request #401 from JCgH4164838Gh792C124B5/WW-5067-25x
Proposed WW-5067 change
2020-04-13 09:08:26 +02:00
JCgH4164838Gh792C124B5 77cfae3084 Proposed WW-5067 change.
------
Proposed list of library version updates:
---
- cdi-api 1.0-SP4 -> 1.2
- weld-core 1.0.1-SP4 -> 2.2.16.SP1
- weld-se 1.0.1-Final -> weld-se-core 2.2.16.SP1
- slf4j-api 1.7.28 -> 1.7.30
- slf4j-simple 1.7.28 -> 1.7.30
- jackson 2.10.0 -> 2.10.3
- ognl 3.1.26 -> 3.1.28
- asm 7.1 -> 7.3.1
- spring 4.3.25.RELEASE -> 4.3.26.RELEASE
- freemarker 2.3.28 -> 2.3.30
- org.apache.felix.main 4.6.1 -> 6.0.3
---
Proposed list of Maven plugin version updates:
---
- doxia-core 1.8 -> 1.9.1
- doxia-module-markdown 1.7 -> 1.9.1
- maven-project-info-reports-plugin 2.7 -> 3.0.0
- updateimpact-maven-plugin 1.0.10 -> 1.0.12
- maven-surefire-plugin 2.22.1 -> 3.0.0-M4
- maven-war-plugin 2.1 -> 3.2.3
- maven-dependency-plugin 2.10 -> 3.1.2
- dependency-check-maven 3.3.4 -> 5.3.2
Note: Unable to upgrade maven-bundle-plugin past 2.1.0 as it introduced
      OOM during JDK7 builds with default heap settings.
---
2020-04-12 23:38:43 -04:00
Alex Kaiser ec56290056 Removing unnecessary part of AbstractMatcher#replaceParameters method and adding a test to make sure it is working correctly 2020-04-08 11:23:02 -07:00
Lukasz Lenart 47c87bc62c Merge pull request #385 from JCgH4164838Gh792C124B5/local_25x_TstFix1
Fix incorrect encoding strings in FileUploadInterceptorTest
2019-12-01 12:34:54 +01:00
JCgH4164838Gh792C124B5 ce467b7fa5 Fix incorrect encoding strings provided in FileUPloadInterceptorTest
- Tests were using "text/html" which is not a valid character encoding.
No impact currently, but the tests could fail in the future if this is not
corrected.  If the code is re-used elsewhere for a test of an action a
valid encoding will be needed.
- Switch to a predefined constant CharSet to get the string instead.
2019-11-30 16:06:05 -05:00
Lukasz Lenart 73eb6ed189 Adds a link to Struts Examples pages 2019-11-25 09:39:50 +01:00
Lukasz Lenart 80a91dc75f [maven-release-plugin] prepare for next development iteration 2019-11-17 20:17:42 +01:00
Lukasz Lenart a6edb0d5df [maven-release-plugin] prepare release STRUTS_2_5_22 STRUTS_2_5_22 2019-11-17 20:17:20 +01:00
JCgH4164838Gh792C124B5 3dfc5a4074 Disable expressionMaxLength by default for Struts 2.5.x. (#380)
* Disable struts.ognl.expressionMaxLength by default for Struts 2.5.x.
- Commented out struts.ognl.expressionMaxLength line in default.properties
and provided in-place comments about its usage.
- Changed OgnlValueStack.handleOgnlException() methods to output error
instead of warn for failures to evaluate expressions due to security
constraints.
- Updated existing unit tests to compensate for change in default
behaviour.
- Added a unit test to confirm default behaviour for
struts.ognl.expressionMaxLength is disabled.

* Updated commit for disable struts.ognl.expressionMaxLength by default for
Struts 2.5.x
- Additional unit test requested by Y. Zamani for code coverage.
- Corrected accidental use of wrong (static) toString method in one test.
- Addition of a minimum struts.ognl.expressionMaxLength value permitted
by Struts 2 (128).  Any value smaller than that is likely to be a
configuration error and if a user really wishes to force it they may go to
OGNL directly to do so.

* Updated commit for disable struts.ognl.expressionMaxLength by default for
Struts 2.5.x
- Removed minimum struts.ognl.expressionMaxLength (restored to previous
behaviour) as requested by Y. Zamani and L. Lenart.
- Updated unit tests to compensate for the above change.
- Changed log output from warn to error in applyExpressionMaxLength() on
exception since it will likely be considered a fatal condition.
2019-11-16 20:09:19 +03:30
Lukasz Lenart fdfeb3233a Uses the latest struts-master 2019-11-07 20:41:58 +01:00
Lukasz Lenart ae3ae2be76 [maven-release-plugin] prepare for next development iteration 2019-11-07 20:18:06 +01:00
Lukasz Lenart 8dface4fcb [maven-release-plugin] prepare release STRUTS_2_5_21 STRUTS_2_5_21 2019-11-07 20:17:01 +01:00
Lukasz Lenart 1348971d40 Merge pull request #378 from JCgH4164838Gh792C124B5/local_25x_CfgChg1
Minor follow-up changes to PR #371
2019-11-04 08:32:03 +01:00
JCgH4164838Gh792C124B5 dd6d206d78 Additional change
- added unit test (hoping to make coveralls happy).
2019-11-02 14:11:21 -04:00
JCgH4164838Gh792C124B5 e2b644a4fb Minor follow-up changes to PR #371
- added some additional exclusions in struts-default.xml.
- added log warning that specifies the value of maxLength involved if
  applyExpressionMaxLength(maxLength) fails.
- added null guards to two handleOgnlException() methods that could
  result in an NPE with #371 changes (a null OgnlException parameter
  was permissible previously, correct or not).
2019-11-02 13:31:09 -04:00
Lukasz Lenart 13cfba86f8 Merge pull request #371 from yasserzamani/WW-5041
WW-5041 Upgrade to OGNL 3.1.26 and adapt to its new features
2019-10-30 08:18:01 +01:00
Lukasz Lenart d84d59f53c Merge branch 'struts-2-5-x' into WW-5041 2019-10-30 07:50:01 +01:00
Lukasz Lenart 3651f55869 Merge pull request #376 from sepe81/update-jackson-to-210
WW-5042 Upgrade jackson-databind to version 2.10.0
2019-10-16 13:39:13 +02:00
Sebastian Peters 7ffa750c68 WW-5042 Upgrade jackson-databind to version 2.10.0
(cherry picked from commit 4556f404bd)
2019-10-15 18:40:33 +02:00
Lukasz Lenart 313876aa3c Merge pull request #372 from JCgH4164838Gh792C124B5/local_25x_LibUpd4
Update multiple Struts 2.5.x libraries to more recent versions.
2019-10-09 07:24:42 +02:00
JCgH4164838Gh792C124B5 9d7a9f81db Remove jackson-databind 2.9.9.x comment from pom.xml as requested by
S. Peters and L. Lenart.
2019-10-08 21:01:14 -04:00
JCgH4164838Gh792C124B5 fe98223724 Update multiple Struts 2.5.x libraries to more recent versions.
Relates to WW-5033 and PRs: #356, #362.  Updated libraries:

Spring Platform 4.3.24 -> 4.3.25
Log4j2 2.11.2 -> 2.12.1
Jackson 2.9.9 -> 2.9.10 (allows removal of jackson 2.9.9.3 "micro patch"
entry, taking care of pom.xml FIXME).
stax2-api 4.1 -> 4.2 (noted during Jackson update)
Fluido Skin 1.7 -> 1.8
SLF4J 1.7.26 -> 1.7.28
2019-10-06 18:29:57 -04:00
Yasser Zamani 1de94b2092 WW-5041 Upgrade to OGNL 3.1.26 and adapt to its new features 2019-10-01 14:57:46 +03:30
Lukasz Lenart 706bb560e4 Merge pull request #367 from JCgH4164838Gh792C124B5/local_25x_SendRedirectEnh
Minor improvement proposed for ServletRedirectResult sendRedirect()
2019-09-23 08:54:14 +02:00
Lukasz Lenart 12d4feaf8f Merge pull request #366 from JCgH4164838Gh792C124B5/local_25x_SendErrorEnh
Improved logging for DefaultDispatcherErrorHandler, DefaultStaticContentLoader
2019-09-23 08:54:02 +02:00
JCgH4164838Gh792C124B5 d88a8382d4 Changed the styling of log outputs (as suggested by A. Mashchenko and
L. Lenart).
Added comment to explain why the log output avoids a stacktrace (due to
exceptions being re-thrown).
Updated existing ServletRedirectResultTest to supply tests that exercise
the new code paths and demonstrate expected logging.
2019-09-22 21:45:44 -04:00
JCgH4164838Gh792C124B5 73809eae54 Changed the styling of log outputs (as suggested by A. Mashchenko).
Changed the log outputs to output full stacktraces (as suggested by
A. Mashchenko and L. Lenart).
Updated existing DefaultStaticContentLoaderTest and created a new
DefaultDispatcherErrorHandlerTest to supply tests that exercise the new
code paths and demonstrate expected logging.
2019-09-21 23:29:24 -04:00
JCgH4164838Gh792C124B5 5b4b554d11 Minor improvement proposed for ServletRedirectResult sendRedirect()
Supply log warning when an IOException or IllegalStateException occurs to
better allow developers to track the failed redirect location and status
details.  The exceptions are re-thrown to ensure existing flow-control
behaviour is preserved.

When getWriter() is called, utilize a finally block to ensure close is
called.
2019-09-17 22:22:41 -04:00
JCgH4164838Gh792C124B5 fcbd29b7f9 Changed the log outputs in this PR to utilize log4j2 {} notation (as per
suggestion by A. Mashchenko and L. Lenart)
Changed the log outputs in this PR from info level to warn level (as per
 suggestion by L. Lenart).
Note: The info level was originally chosen to make it easier to filter out
in the very unlikely case of log flood.
2019-09-17 21:10:34 -04:00
JCgH4164838Gh792C124B5 220896a0cf Improved logging for DefaultDispatcherErrorHandler and
DefaultStaticContentLoader.

Provide informational logging for the processing of the two dispatcher
classes when an http sendError fails for the two known failure types
(IOException, IllegalStateException).

In both circumstances it is beneficial to have the developer aware of the
failures via the logs.  These are not events that should be happening on a
regular basis, so there is little risk of a log flood.

DefaultStaticContentLoader didn't catch either exception type previously,
so changing it to make handling the same as DefaultDispatcherErrorHandler.

For DefaultDispatcherErrorHandler the IOException was caught with no
notice of failure previously.  Now there will be an info level log output.
Previously the IllegalStateException was not caught, which resulted in the
unrecoverable exception being thrown up to the calling thread, usually
resulting in an ugly stacktrace to stdout/stderr.  Now there will be an
info level log output instead.

If devMode is true, the info log outputs will include the exception
parameter to the log, so a stacktrace can be viewed for more details.  If
devMode is false (production mode), then only the exception's tostring()
output will be produced.
2019-09-15 20:48:15 -04:00
Lukasz Lenart 632f19eab3 WW-5038 Upgrades jackson-databind to version 2.9.9.3
plus upgrades jackson-core to 2.9.9

(cherry picked from commit 8187006)
2019-09-07 16:39:12 +04:30
Sebastian Haas 50a145152d Fix typo in MultiselectInterceptor javadoc
(cherry picked from commit dca0dd2)
2019-09-07 15:31:38 +04:30
JCgH4164838Gh792C124B5 f7b191f782 WW-5033 - Update to latest versions for some Struts 2.5.x dependencies: (#362)
* WW-5033 - Update to latests versions for some Struts 2.5.x dependencies:
- ASM 7 -> 7.1
- Spring 4.3.20.RELEASE -> 4.3.24.RELEASE

* fix Travis build
2019-09-07 14:33:34 +04:30
Yasser Zamani 4ae1a6a26d Merge pull request #361 from JCgH4164838Gh792C124B5/localS2_25x_OgnlCachecontrol
Proposed WW-5035 enhancement:
2019-09-07 14:32:03 +04:30
Lukasz Lenart 79e598f360 WW-5037 Upgrades commons-beanutils to version 1.9.4 2019-09-02 12:20:23 +02:00
JCgH4164838Gh792C124B5 9216e8e22c Proposed WW-5035 enhancement:
- Provide cache clearing methods for OgnlUtil (expression cache, BeanInfo
cache).
- Provide methods to check the cache sizes (entry number for expression
cache, BeanInfo cache).
- Provide static method to clear the OgnlRuntime cache (convenience
method).
2019-06-15 11:44:28 -04:00
Lukasz Lenart 651eac2c57 Merge pull request #358 from yasserzamani/WW-4999
fix logMissingProperties (WW-4999)
2019-06-03 08:25:32 +02:00
Yasser Zamani a50af87644 test false for logMissingProperties (WW-4999) 2019-06-02 17:22:28 +04:30
Yasser Zamani 9e01fbd2dd decouple logMissingProperties from devMode (WW-4999) 2019-06-01 12:52:22 +04:30
Yasser Zamani d4dd3386cc test not throw exception on top missing property (WW-4999)
instead continue to next objects in stack

Also tests not skip returned null values by user method
2019-06-01 09:37:19 +04:30
Yasser Zamani 0999fba8c4 not log user exceptions as missing properties (WW-4999)
Also reaks loop on user method exceptions - but continue to next objects in stack on NoSuchMethodException.
2019-05-31 17:57:25 +04:30
Yasser Zamani 3ac6835c5c fix logMissingProperties (WW-4999)
Moves checking OgnlValueStack.THROW_EXCEPTION_ON_FAILURE outside loop because it shouldn't throw exception on first failure while is trying all root objects.

Returns on first successful call because it's not rational and is confusing user to skip when user method successfully returns null as an actual result.

Fixes WW-4999 via honoring (devMode && logMissingProperties) for OgnlValueStack.THROW_EXCEPTION_ON_FAILURE and REPORT_ERRORS_ON_NO_PROP.
2019-05-30 16:36:54 +04:30
Yasser Zamani b0dd7c1c0d include ref in path as WW-5011 workaround (#353)
* include ref in path for StrutsApplicationResource as WW-5011 workaround

* add license to newly added xml files in previous commit

* WW-5011 include ref in path via .toURI().getPath()

* WW-5011 check protocol and not throw exception due to lazy file existence

* decrease log file size to pass travis build
2019-05-28 09:53:27 +04:30