Commit Graph

5405 Commits

Author SHA1 Message Date
Yasser Zamani 9e01fbd2dd decouple logMissingProperties from devMode (WW-4999) 2019-06-01 12:52:22 +04:30
Yasser Zamani d4dd3386cc test not throw exception on top missing property (WW-4999)
instead continue to next objects in stack

Also tests not skip returned null values by user method
2019-06-01 09:37:19 +04:30
Yasser Zamani 0999fba8c4 not log user exceptions as missing properties (WW-4999)
Also reaks loop on user method exceptions - but continue to next objects in stack on NoSuchMethodException.
2019-05-31 17:57:25 +04:30
Yasser Zamani 3ac6835c5c fix logMissingProperties (WW-4999)
Moves checking OgnlValueStack.THROW_EXCEPTION_ON_FAILURE outside loop because it shouldn't throw exception on first failure while is trying all root objects.

Returns on first successful call because it's not rational and is confusing user to skip when user method successfully returns null as an actual result.

Fixes WW-4999 via honoring (devMode && logMissingProperties) for OgnlValueStack.THROW_EXCEPTION_ON_FAILURE and REPORT_ERRORS_ON_NO_PROP.
2019-05-30 16:36:54 +04:30
Yasser Zamani b0dd7c1c0d include ref in path as WW-5011 workaround (#353)
* include ref in path for StrutsApplicationResource as WW-5011 workaround

* add license to newly added xml files in previous commit

* WW-5011 include ref in path via .toURI().getPath()

* WW-5011 check protocol and not throw exception due to lazy file existence

* decrease log file size to pass travis build
2019-05-28 09:53:27 +04:30
Lukasz Lenart a63beef1f8 Merge pull request #355 from JCgH4164838Gh792C124B5/localS2_25x_TextProviderFix
Minor enhancement/fix to AbstractLocalizedTextProvider:
2019-05-27 09:45:50 +02:00
Aleksandr Mashchenko e74e5539dd Merge pull request #356 from JCgH4164838Gh792C124B5/local_25x_LibUpd3
Update Three Struts 2.5.x dependencies to latest versions
2019-05-26 20:16:49 +03:00
JCgH4164838Gh792C124B5 2226fcc168 Update Three Struts 2.5.x dependencies to latest versions:
- Jackson 2.9.8 -> 2.9.9
- Log4j2 2.11.1 -> 2.11.2
- OGNL 3.1.22 -> 3.1.23
Struts 2.5.21-SNAPSHOT builds successfully with these versions.
2019-05-25 17:09:33 -04:00
JCgH4164838Gh792C124B5 865b8a20df Update PR with unit test:
- Add a unit test to include test coverage and confirm no failures
in the new methods.
2019-05-11 16:28:34 -04:00
JCgH4164838Gh792C124B5 3c6956116e Minor enhancement/fix to AbstractLocalizedTextProvider:
- Made "constant" RELOADED static to save an initialization every time.
- Updated clearBundle(final String bundleName) method comment as it
  seemed inaccurate, added debug log output when called.
- Introduced protected clearBundle(final String bundleName, Locale locale)
  method for use by descendants, with debug log output when called.
- Introduced protected clearMissingBundlesCache() method for use by
  descendants, with debug log when called.
2019-05-11 13:19:35 -04:00
Lukasz Lenart bb9ce7582b Merge pull request #354 from JCgH4164838Gh792C124B5/localS2_25x_B10
Minor consistency update correction for WW-5029 fix to the 2.5.x branch
2019-04-29 07:42:13 +02:00
JCgH4164838Gh792C124B5 11d373f8b4 Minor consistency update correction for WW-5029 fix to the 2.5.x branch:
- Correct missing verification in buildAllowedMethods()/loadGlobalAllowedMethods() that the nodes are
  of type Node.TEXT_NODE (as buildResults() does).
- Made two class fields final, as suggested by IDE.
2019-04-27 12:35:40 -04:00
Lukasz Lenart b23bfd42d2 Merge pull request #350 from yasserzamani/WW-4958
fix multipart request RegEx (relates to WW-4958)
2019-04-23 08:25:40 +02:00
Yasser Zamani f94b681050 fix multipart request RegEx
Note: Unlike some similar constructs in other header fields, media
type parameters do not allow whitespace (even "bad" whitespace)
around the "=" character.

Reference: https://tools.ietf.org/html/rfc7231#section-3.1.1.1
See also: WW-4958
2019-04-23 09:32:43 +04:30
JCgH4164838Gh792C124B5 fb38a919c9 Proposed fix for WW-5029 for the 2.5.x branch (#347)
* Proposed fix for WW-5029 for the 2.5.x branch:
- NOTE: If the PR is accepted please credit Maxime Clement for this change as they found
        the issue, identified the probable cause/related details and opened the JIRA.
- Updated XWorkConfigurationProvider buildAllowedMethods(), loadGlobalAllowedMethods() so that
  they now handle situations when a SAX parser produces multiple elements to represent the tag
  body value.
- No changes to unit tests.

* Update commit to fix weakness identified by Maxime Clement:
- Implementation should now properly concatenate the node children values together (as a single unified string)
  in both buildAllowedMethods(), loadGlobalAllowedMethods() - before generating the method Set to be added.
- Made some eligible variables final.

* Update commit to provide new unit tests:
- Added unit tests to confirm the fixes for buildAllowedMethods(), loadGlobalAllowedMethods()
- Added Mock DOM classes sufficient for these tests.
- Added unit tests to cover buildResults() and loadGlobalResults().
2019-04-20 09:54:36 +04:30
Yasser Zamani e25c826167 Merge pull request #349 from JCgH4164838Gh792C124B5/localS2_25x_B9
Proposed fix for WW-5028 for the 2.5.x branch:
2019-04-20 08:58:07 +04:30
JCgH4164838Gh792C124B5 4815744eaf (Amended commit based on feedback)
Proposed fix for WW-5028 for the 2.5.x branch:
- Disable printing stacktrace on exceptions by the Dispatcher by default.
- Printing stacktrace on exception is only enabled with devMode set to true, as suggested by L. Lenart.
- Now prints stacktrace on exception using LOG, as suggested by A. Mashchenko and the the JIRA reporter.
  Log level set to debug as recommended by Y. Zamani.
- Added two additional unit tests for Dispatcher devMode and handleException states.
2019-04-16 22:26:46 -04:00
Yasser Zamani f5a7776854 Merge pull request #344 from lukaszlenart/WW-4958
[WW-4958] Uses less restrictive RegEx to check if it's a multipart request
2019-04-14 14:06:35 +04:30
Lukasz Lenart f45d2752bb WW-4958 Uses less restrictive Regex to check if it's a multipart request 2019-03-30 09:23:50 +01:00
JCgH4164838Gh792C124B5 0262574095 Proposed fix for WW-5024 in the 2.5.x branch: (#343)
- NOTE: If the PR is accepted please credit Robert Hollencamp (Github @rhollencamp) for this change
        as he found the issue, proposed a solution for 2.6 (master), and opened the JIRA.
- Updated HttpParameters, ActionMappingParametersInterceptor to prevent multi-level Parameter wrapping from occuring.
- Added a new ActionMappingParametersInterceptorTest to verify the fix.
2019-03-29 07:20:56 +01:00
Aleksandr Mashchenko 30cb56a414 Merge pull request #342 from JCgH4164838Gh792C124B5/localS2_25x_B5
WW-5026 TokenSessionStoreInterceptor double-submit failure
2019-03-26 22:55:42 +02:00
JCgH4164838Gh792C124B5 63dc85fd7a Updated commit with changes suggested by reviewers:
- Replace TokenSessionStoreInterceptor inline comment previously added with method comment blocks (better locatioh for explanation)
- Eliminate duplicate savedActionContext.setValueStack call in InvocationSessionStore (typo)
- Improve InvocationSessionStore.loadInvocation() by reording assignment statements to allow single-line assignments
2019-03-25 23:36:07 -04:00
JCgH4164838Gh792C124B5 5b0ec3400d Fix issue introduced with earlier WW-4873 fix:
- Fixes error 500 processing failures for double-submit results with TokenSessionStoreInterceptor processing
- Fix to InvocationSessionStore, new unit test confirming fix in InvocationSessionStoreTest
- Minor whitespace fix to TokenSessionStoreInterceptor
2019-03-25 01:00:10 -04:00
Yasser Zamani d460d71498 Merge pull request #341 from JCgH4164838Gh792C124B5/localS2_25x_Testfix
Backport OgnlValueStackTest test fix and unit test additions from master
2019-03-18 09:55:17 +03:30
JCgH4164838Gh792C124B5 53f64cdecf Backport applicable OgnlValueStackTest test fix and unit test additions from 2.6:
- This backport resulted from a review inspired/suggested by Y. Zamani in discussions for PR#334.
- Backports fix of error in testNullMethod().
- Backports applicable static access tests (static method access only), cleanup of unused imports.
- As with 2.6, it uses Y. Zamani's improved/enhanced reload mechanism.
2019-03-16 17:50:18 -04:00
Lukasz Lenart aff4d46835 Merge pull request #336 from JCgH4164838Gh792C124B5/local_25x_LibUpd2
Upgrade SLF4J to 1.7.26 (WW-5023)
2019-02-25 08:40:42 +01:00
Yasser Zamani a15c12a051 add properties support to XWorkTestCase.loadButAdd
also includes cleanups for PRs #292 and #320
2019-02-24 17:53:45 +03:30
JCgH4164838Gh792C124B5 e62155c460 Upgrade SLF4J to 1.7.26 (WW-5023) 2019-02-21 12:25:23 -05:00
Lukasz Lenart f7f4fbd47f Merge pull request #333 from JCgH4164838Gh792C124B5/localS2_25x_Appfix
Minor config fixes for the Showcase Application in 2.5.x:
2019-02-12 09:33:18 +01:00
JCgH4164838Gh792C124B5 2d81439553 Minor config fixes for the Showcase Application in 2.5.x:
1) Token examples. Examples 2 and 3 previously resulted in 403's upon submit (config issue).
2) Token examples. Example 4 resulted in error 500 when selected from the menu (FTL param type issue).
3) Validation examples.  Examples quizBasic, quizClient and quizClientCss resulted in 404's when selected from menu (config issue).
4) File upload examples.  Multiple file upload missing result page (list and array), added missing JSP.  Added missing input results in configuration.
5) Add manual test for public constant access via expression (to If tag JSP).
Similar to PR#255 for 2.6.x.
2019-02-11 19:37:11 -05:00
Lukasz Lenart 7afe35cb96 Adds a Jenkinsfile to allow build this branch as well 2019-02-11 09:32:49 +01:00
Yasser Zamani fdd1054070 Merge pull request #328 from aleksandr-m/feature/WW-5009
WW-5009 EmptyStackException in JSON plugin due to concurrency
2019-02-05 14:37:57 +03:30
Aleksandr Mashchenko 32e88d1a2e Merge pull request #322 from aleksandr-m/feature/WW-4991
WW-4991 Not existing property in listValueKey throws exception
2019-02-04 21:52:26 +02:00
Lukasz Lenart 6403de4516 Merge pull request #315 from yasserzamani/WW-5005
WW-5005 upgrade to ASM 7
2019-02-04 10:57:33 +01:00
Yasser Zamani 13c517fc3c Merge branch 'struts-2-5-x' into WW-5005 2019-02-04 12:47:23 +03:30
Aleksandr Mashchenko 7242a87165 WW-5009 Fix tests 2019-02-03 12:58:43 +02:00
Aleksandr Mashchenko 0323795d67 WW-5009 EmptyStackException in JSON plugin due to concurrency 2019-02-03 12:41:18 +02:00
Aleksandr Mashchenko 71267a9b4b Revert some changes to be more consistent with 2.6 version 2019-01-31 17:32:36 +02:00
JCgH4164838Gh792C124B5 5524c579d2 Fix for NPE issue discovered in WW-5004. (#316)
* Fix for NPE issue discovered in WW-5004.
- Guard fix for a NPE that can arise under certain conditions, identified by A. Mashchenko.

* Fix for NPE issue discovered in WW-5004 (amended commit).
- Guard fix for a NPE that can arise under certain conditions, identified by A. Mashchenko.
- Requires the following elements to implement a fuller fix:
  - Back-port relevant guard logic in ProxyUtil from master into 2.5.x to deal with the NPE.
  - Update SecurityMemberAccess to block access to static fields.
  - Upgrade to OGNL 3.1.22 (re-enables access to public static fields w/out access checks).
  - Add unit test to confirm proper functionality of the fix.
  - Correct missing entry in 4 test configuration XML files (needed for new unit test).
- Replaced literal injection parameter name for setStaticFieldAccessLevel in OgnlValueStackFactory with the appropriate constant.
  Note: Even though a constant was defined in StrutsConstants, the value for the injection name in all places is the XWorkConstants.
        It has to remain the same to avoid breaking anything.
2019-01-31 18:01:41 +03:30
Aleksandr Mashchenko 873ca8fa20 WW-4991 Not existing property in listValueKey throws exception 2019-01-30 23:10:06 +02:00
Yasser Zamani 8988d57644 Merge pull request #318 from lukaszlenart/WW-5007-jackson-ugrade-s25
[WW-5007] Upgrades Jackson libraries to version 2.9.8
2019-01-25 15:23:18 +03:30
Lukasz Lenart 2e7cf63964 WW-5007 Upgrades Jackson libraries to version 2.9.8 2019-01-25 12:29:48 +01:00
Yasser Zamani 3eb68be674 upgrade to ASM 7
fixes WW-5005
2019-01-23 16:24:40 +03:30
Yasser Zamani c9f279ec2e Merge pull request #314 from JCgH4164838Gh792C124B5/localS2_25x_B2
Minor cleanup/consistency changes for 3 modules.
2019-01-23 11:51:58 +03:30
JCgH4164838Gh792C124B5 881e1b2580 Minor cleanup/consistency changes for 3 modules.
- Made a private ConcurrentMap reference final, made initial sets immutable (consistency).
- Made sets for Accepted and Excluded patterns checkers immutable in 2 modules (consistency).
- Added @Override annotations missing from a few methods in 2 modules.
- Updated the 3 relevant unit tests to verify immutable states of various sets.
2019-01-18 00:09:29 -05:00
Lukasz Lenart cb0ac7c440 [maven-release-plugin] prepare for next development iteration 2019-01-09 09:00:04 +01:00
Lukasz Lenart 96c38b27e4 [maven-release-plugin] prepare release STRUTS_2_5_20 STRUTS_2_5_20 2019-01-09 08:59:40 +01:00
Lukasz Lenart e9108f0feb Merge pull request #310 from aleksandr-m/feature/WW-4998_i18ninterceptor
WW-4998 I18nInterceptor's default storage should store locale
2019-01-09 08:45:23 +01:00
Lukasz Lenart 3653f6e9e1 Merge pull request #309 from JCgH4164838Gh792C124B5/localS2_25x_B1
Address devMode log flooding concern raised by Greg Huber (on Dev List)
2019-01-09 08:43:49 +01:00
JCgH4164838Gh792C124B5 5a2323a19f Update after comments by Y. Zamani and L. Lenart
- Reverted the 6 modified files back to 2.5.19 baseline.
- Removed most of the logging added in PR#291.
- Left the added logging for the setExcludedPatterns and setAcceptedPatterns methods in their respective modules.
  L. Lenart's comment indicated their benefit outweighs overhead (not something that changes often).
  Made the if-else blocks consistent with preferred styling for the log blocks.
- Removed a dangling "/**" start comment tag with no proper close (and the whitespace between it and the next "/**"
  in the OgnlValueStack module.
(Note: Amended previous commit)
2019-01-07 23:29:32 -05:00