mirror of
https://github.com/apache/struts.git
synced 2026-08-07 15:46:57 +00:00
Compare commits
188 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| dcc59937a8 | |||
| 22c88faf38 | |||
| 1191ca3ed0 | |||
| bcfb769005 | |||
| d61be3e4ce | |||
| c7149ab1bc | |||
| 4504e610f1 | |||
| 9b3a23eb28 | |||
| 3220d832d2 | |||
| bd007953ea | |||
| 1b0c743e85 | |||
| 89e02a4fb4 | |||
| 8cb93ad39a | |||
| e8656d5737 | |||
| 7f10ed505f | |||
| 043814b774 | |||
| 0fabde9f97 | |||
| 4457f03c70 | |||
| 3d3512a399 | |||
| 59a6cbf6ca | |||
| 19802b0614 | |||
| e46e662a7a | |||
| 4786fba0d7 | |||
| e32bd7dba9 | |||
| 6e1d2add07 | |||
| 2eeac367fe | |||
| 30b43044a3 | |||
| 5c82f0246e | |||
| fff35cfd9d | |||
| 1526b36dd6 | |||
| 6d6a422db7 | |||
| 5cf57b9132 | |||
| f4c0135878 | |||
| 77cfae3084 | |||
| ec56290056 | |||
| 47c87bc62c | |||
| ce467b7fa5 | |||
| 73eb6ed189 | |||
| 80a91dc75f | |||
| a6edb0d5df | |||
| 3dfc5a4074 | |||
| fdfeb3233a | |||
| ae3ae2be76 | |||
| 8dface4fcb | |||
| 1348971d40 | |||
| dd6d206d78 | |||
| e2b644a4fb | |||
| 13cfba86f8 | |||
| d84d59f53c | |||
| 3651f55869 | |||
| 7ffa750c68 | |||
| 313876aa3c | |||
| 9d7a9f81db | |||
| fe98223724 | |||
| 1de94b2092 | |||
| 706bb560e4 | |||
| 12d4feaf8f | |||
| d88a8382d4 | |||
| 73809eae54 | |||
| 5b4b554d11 | |||
| fcbd29b7f9 | |||
| 220896a0cf | |||
| 632f19eab3 | |||
| 50a145152d | |||
| f7b191f782 | |||
| 4ae1a6a26d | |||
| 79e598f360 | |||
| 9216e8e22c | |||
| 651eac2c57 | |||
| a50af87644 | |||
| 9e01fbd2dd | |||
| d4dd3386cc | |||
| 0999fba8c4 | |||
| 3ac6835c5c | |||
| b0dd7c1c0d | |||
| a63beef1f8 | |||
| e74e5539dd | |||
| 2226fcc168 | |||
| 865b8a20df | |||
| 3c6956116e | |||
| bb9ce7582b | |||
| 11d373f8b4 | |||
| b23bfd42d2 | |||
| f94b681050 | |||
| fb38a919c9 | |||
| e25c826167 | |||
| 4815744eaf | |||
| f5a7776854 | |||
| f45d2752bb | |||
| 0262574095 | |||
| 30cb56a414 | |||
| 63dc85fd7a | |||
| 5b0ec3400d | |||
| d460d71498 | |||
| 53f64cdecf | |||
| aff4d46835 | |||
| a15c12a051 | |||
| e62155c460 | |||
| f7f4fbd47f | |||
| 2d81439553 | |||
| 7afe35cb96 | |||
| fdd1054070 | |||
| 32e88d1a2e | |||
| 6403de4516 | |||
| 13c517fc3c | |||
| 7242a87165 | |||
| 0323795d67 | |||
| 71267a9b4b | |||
| 5524c579d2 | |||
| 873ca8fa20 | |||
| 8988d57644 | |||
| 2e7cf63964 | |||
| 3eb68be674 | |||
| c9f279ec2e | |||
| 881e1b2580 | |||
| cb0ac7c440 | |||
| 96c38b27e4 | |||
| e9108f0feb | |||
| 3653f6e9e1 | |||
| 5a2323a19f | |||
| ea09a8828b | |||
| 17fe42c0f7 | |||
| 87fa5bddf2 | |||
| 45161e88f9 | |||
| 4456620b51 | |||
| f4a8f42ca4 | |||
| a6f8895c90 | |||
| 46dbdbe018 | |||
| 6f176cc5a7 | |||
| db085dbeef | |||
| c3205888b4 | |||
| ce9789c4c9 | |||
| b431755332 | |||
| c694c6fdfb | |||
| 1d49a06272 | |||
| 264e03b7ed | |||
| 2f99110189 | |||
| d33930f3bd | |||
| 360927931c | |||
| bff033e6a3 | |||
| 536d2db4b8 | |||
| 32c8f6f811 | |||
| 06e5dfc2ab | |||
| fe630db5f2 | |||
| b75c0ba5e1 | |||
| 8ab102209f | |||
| d7a7c909ea | |||
| 24e151143e | |||
| c5272d2a0d | |||
| 11de8810e4 | |||
| 75dc4c00d2 | |||
| 415ce3e165 | |||
| fe6257b995 | |||
| 3b81a9edaa | |||
| 478a9b8f1c | |||
| 12c3d23bdf | |||
| 8293add6aa | |||
| ecb7beef38 | |||
| bac0f2953c | |||
| 7bca98205d | |||
| 567fae9dfc | |||
| f4d7dbe88e | |||
| 289782c583 | |||
| 1e33df947a | |||
| de1a42d34a | |||
| b816cc1374 | |||
| b802baa4a9 | |||
| daac47ee62 | |||
| b1709c5208 | |||
| daf6f6f749 | |||
| 029892d656 | |||
| 65fb0d4a44 | |||
| 58d87025e9 | |||
| 83c0f1cd1e | |||
| eacc002334 | |||
| 45effc3822 | |||
| bad9a49060 | |||
| a75eddb515 | |||
| 6e87474f9a | |||
| 9fcbd912bc | |||
| fbc780e779 | |||
| 6eb83016e3 | |||
| 3ec7fa9d80 | |||
| f9806ee4e1 | |||
| d175836757 | |||
| e55ad3fb45 | |||
| 6efaf900d4 | |||
| b3bad5ea44 |
@@ -62,3 +62,4 @@ bundles/target
|
||||
plugins/target
|
||||
target
|
||||
plugins/testng/test-output
|
||||
test-output
|
||||
|
||||
+110
@@ -0,0 +1,110 @@
|
||||
/*
|
||||
Licensed to the Apache Software Foundation (ASF) under one
|
||||
or more contributor license agreements. See the NOTICE file
|
||||
distributed with this work for additional information
|
||||
regarding copyright ownership. The ASF licenses this file
|
||||
to you under the Apache License, Version 2.0 (the
|
||||
"License"); you may not use this file except in compliance
|
||||
with the License. You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing,
|
||||
software distributed under the License is distributed on an
|
||||
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||
KIND, either express or implied. See the License for the
|
||||
specific language governing permissions and limitations
|
||||
under the License.
|
||||
*/
|
||||
|
||||
import java.net.*;
|
||||
import java.io.*;
|
||||
import java.nio.channels.*;
|
||||
import java.util.Properties;
|
||||
|
||||
public class MavenWrapperDownloader {
|
||||
|
||||
/**
|
||||
* Default URL to download the maven-wrapper.jar from, if no 'downloadUrl' is provided.
|
||||
*/
|
||||
private static final String DEFAULT_DOWNLOAD_URL =
|
||||
"https://repo.maven.apache.org/maven2/io/takari/maven-wrapper/0.4.0/maven-wrapper-0.4.0.jar";
|
||||
|
||||
/**
|
||||
* Path to the maven-wrapper.properties file, which might contain a downloadUrl property to
|
||||
* use instead of the default one.
|
||||
*/
|
||||
private static final String MAVEN_WRAPPER_PROPERTIES_PATH =
|
||||
".mvn/wrapper/maven-wrapper.properties";
|
||||
|
||||
/**
|
||||
* Path where the maven-wrapper.jar will be saved to.
|
||||
*/
|
||||
private static final String MAVEN_WRAPPER_JAR_PATH =
|
||||
".mvn/wrapper/maven-wrapper.jar";
|
||||
|
||||
/**
|
||||
* Name of the property which should be used to override the default download url for the wrapper.
|
||||
*/
|
||||
private static final String PROPERTY_NAME_WRAPPER_URL = "wrapperUrl";
|
||||
|
||||
public static void main(String args[]) {
|
||||
System.out.println("- Downloader started");
|
||||
File baseDirectory = new File(args[0]);
|
||||
System.out.println("- Using base directory: " + baseDirectory.getAbsolutePath());
|
||||
|
||||
// If the maven-wrapper.properties exists, read it and check if it contains a custom
|
||||
// wrapperUrl parameter.
|
||||
File mavenWrapperPropertyFile = new File(baseDirectory, MAVEN_WRAPPER_PROPERTIES_PATH);
|
||||
String url = DEFAULT_DOWNLOAD_URL;
|
||||
if(mavenWrapperPropertyFile.exists()) {
|
||||
FileInputStream mavenWrapperPropertyFileInputStream = null;
|
||||
try {
|
||||
mavenWrapperPropertyFileInputStream = new FileInputStream(mavenWrapperPropertyFile);
|
||||
Properties mavenWrapperProperties = new Properties();
|
||||
mavenWrapperProperties.load(mavenWrapperPropertyFileInputStream);
|
||||
url = mavenWrapperProperties.getProperty(PROPERTY_NAME_WRAPPER_URL, url);
|
||||
} catch (IOException e) {
|
||||
System.out.println("- ERROR loading '" + MAVEN_WRAPPER_PROPERTIES_PATH + "'");
|
||||
} finally {
|
||||
try {
|
||||
if(mavenWrapperPropertyFileInputStream != null) {
|
||||
mavenWrapperPropertyFileInputStream.close();
|
||||
}
|
||||
} catch (IOException e) {
|
||||
// Ignore ...
|
||||
}
|
||||
}
|
||||
}
|
||||
System.out.println("- Downloading from: : " + url);
|
||||
|
||||
File outputFile = new File(baseDirectory.getAbsolutePath(), MAVEN_WRAPPER_JAR_PATH);
|
||||
if(!outputFile.getParentFile().exists()) {
|
||||
if(!outputFile.getParentFile().mkdirs()) {
|
||||
System.out.println(
|
||||
"- ERROR creating output direcrory '" + outputFile.getParentFile().getAbsolutePath() + "'");
|
||||
}
|
||||
}
|
||||
System.out.println("- Downloading to: " + outputFile.getAbsolutePath());
|
||||
try {
|
||||
downloadFileFromURL(url, outputFile);
|
||||
System.out.println("Done");
|
||||
System.exit(0);
|
||||
} catch (Throwable e) {
|
||||
System.out.println("- Error downloading");
|
||||
e.printStackTrace();
|
||||
System.exit(1);
|
||||
}
|
||||
}
|
||||
|
||||
private static void downloadFileFromURL(String urlString, File destination) throws Exception {
|
||||
URL website = new URL(urlString);
|
||||
ReadableByteChannel rbc;
|
||||
rbc = Channels.newChannel(website.openStream());
|
||||
FileOutputStream fos = new FileOutputStream(destination);
|
||||
fos.getChannel().transferFrom(rbc, 0, Long.MAX_VALUE);
|
||||
fos.close();
|
||||
rbc.close();
|
||||
}
|
||||
|
||||
}
|
||||
BIN
Binary file not shown.
+1
@@ -0,0 +1 @@
|
||||
distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.5.3/apache-maven-3.5.3-bin.zip
|
||||
+11
-3
@@ -1,15 +1,23 @@
|
||||
dist: trusty
|
||||
language: java
|
||||
sudo: false
|
||||
|
||||
jdk:
|
||||
- openjdk7
|
||||
- oraclejdk8
|
||||
- oraclejdk9
|
||||
- oraclejdk11
|
||||
|
||||
install: true
|
||||
script: mvn test -DskipAssembly
|
||||
script: mvn test -DskipAssembly -B
|
||||
|
||||
after_success:
|
||||
- mvn clean cobertura:cobertura org.eluder.coveralls:coveralls-maven-plugin:report com.updateimpact:updateimpact-maven-plugin:submit -Ptravis-coveralls,update-impact -DskipAssembly
|
||||
# TODO delete following if statement after fix of https://github.com/cobertura/cobertura/issues/271
|
||||
- if [ "$TRAVIS_JDK_VERSION" == "openjdk8" ] || [ "$TRAVIS_JDK_VERSION" == "oraclejdk8" ]; then
|
||||
mvn cobertura:cobertura org.eluder.coveralls:coveralls-maven-plugin:report com.updateimpact:updateimpact-maven-plugin:submit -Ptravis-coveralls,update-impact -DskipAssembly -B;
|
||||
else
|
||||
echo "Not reporting coverage for $TRAVIS_JDK_VERSION due to incompatibility or to save performance";
|
||||
fi;
|
||||
|
||||
env:
|
||||
global:
|
||||
@@ -18,4 +26,4 @@ env:
|
||||
cache:
|
||||
directories:
|
||||
- $HOME/.m2
|
||||
|
||||
|
||||
|
||||
Vendored
+29
@@ -0,0 +1,29 @@
|
||||
#!groovy
|
||||
pipeline {
|
||||
agent {
|
||||
label 'ubuntu'
|
||||
}
|
||||
options {
|
||||
buildDiscarder logRotator(daysToKeepStr: '14', numToKeepStr: '10')
|
||||
timeout(80)
|
||||
disableConcurrentBuilds()
|
||||
}
|
||||
tools {
|
||||
jdk 'JDK 1.7 (latest)'
|
||||
maven 'Maven 3 (latest)'
|
||||
}
|
||||
triggers {
|
||||
pollSCM 'H/15 * * * *'
|
||||
}
|
||||
environment {
|
||||
MAVEN_OPTS = '-Xmx1024m -XX:MaxPermSize=256m'
|
||||
}
|
||||
stages {
|
||||
stage('Build') {
|
||||
steps {
|
||||
sh 'mvn --version'
|
||||
sh 'mvn clean source:jar javadoc:jar install deploy -DskipWiki -Dhttps.protocols=TLSv1,TLSv1.1,TLSv1.2'
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
+1
-1
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.5.16</version>
|
||||
<version>2.5.24</version>
|
||||
</parent>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<packaging>pom</packaging>
|
||||
|
||||
@@ -24,12 +24,12 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<version>2.5.16</version>
|
||||
<version>2.5.24</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-rest-showcase</artifactId>
|
||||
<packaging>war</packaging>
|
||||
<version>2.5.16</version>
|
||||
<version>2.5.24</version>
|
||||
<name>Struts 2 Rest Showcase Webapp</name>
|
||||
<description>Struts 2 Rest Showcase Example</description>
|
||||
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<version>2.5.16</version>
|
||||
<version>2.5.24</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-showcase</artifactId>
|
||||
@@ -167,7 +167,7 @@
|
||||
<dependency>
|
||||
<groupId>org.hibernate</groupId>
|
||||
<artifactId>hibernate-validator</artifactId>
|
||||
<version>5.1.3.Final</version>
|
||||
<version>5.4.3.Final</version>
|
||||
</dependency>
|
||||
|
||||
<!-- The Servlet API mocks in Spring Framework 4.x only supports Servlet 3.0 and higher.
|
||||
|
||||
+8
@@ -84,4 +84,12 @@ public class FileUploadAction extends ActionSupport {
|
||||
public void setCaption(String caption) {
|
||||
this.caption = caption;
|
||||
}
|
||||
|
||||
public long getUploadSize() {
|
||||
if (upload != null) {
|
||||
return upload.length();
|
||||
} else {
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@
|
||||
<validators>
|
||||
<field name="upload">
|
||||
<field-validator type="fieldexpression">
|
||||
<param name="expression"><![CDATA[upload.length() > 0]]></param>
|
||||
<param name="expression"><![CDATA[getUploadSize() > 0]]></param>
|
||||
<message>File cannot be empty</message>
|
||||
</field-validator>
|
||||
</field>
|
||||
|
||||
@@ -40,6 +40,7 @@
|
||||
</action>
|
||||
|
||||
<action name="doMultipleUploadUsingList" class="org.apache.struts2.showcase.fileupload.MultipleFileUploadUsingListAction" method="upload">
|
||||
<result name="input">/WEB-INF/fileupload/multipleUploadUsingList.jsp</result>
|
||||
<result>/WEB-INF/fileupload/multiple-success.jsp</result>
|
||||
</action>
|
||||
|
||||
@@ -49,6 +50,7 @@
|
||||
</action>
|
||||
|
||||
<action name="doMultipleUploadUsingArray" class="org.apache.struts2.showcase.fileupload.MultipleFileUploadUsingArrayAction" method="upload">
|
||||
<result name="input">/WEB-INF/fileupload/multipleUploadUsingArray.jsp</result>
|
||||
<result>/WEB-INF/fileupload/multiple-success.jsp</result>
|
||||
</action>
|
||||
|
||||
|
||||
@@ -48,7 +48,7 @@
|
||||
<interceptor-ref name="defaultStack"/>
|
||||
<interceptor-ref name="token"/>
|
||||
<result name="invalid.token">/WEB-INF/token/doublePost.jsp</result>
|
||||
<result name="success" type="redirect">/WEB-INF/token/transferDone.jsp</result>
|
||||
<result name="success">/WEB-INF/token/transferDone.jsp</result>
|
||||
</action>
|
||||
|
||||
|
||||
@@ -62,7 +62,7 @@
|
||||
<interceptor-ref name="defaultStack"/>
|
||||
<interceptor-ref name="tokenSession"/>
|
||||
<result name="invalid.token">/WEB-INF/token/doublePost.jsp</result>
|
||||
<result name="success" type="redirect">/WEB-INF/token/transferDone.jsp</result>
|
||||
<result name="success">/WEB-INF/token/transferDone.jsp</result>
|
||||
</action>
|
||||
|
||||
|
||||
|
||||
@@ -34,28 +34,28 @@
|
||||
|
||||
<package name="validation" extends="json-default" namespace="/validation">
|
||||
<action name="index">
|
||||
<result>/WEB-INF/validation/index.jsp</result>
|
||||
<result>index.jsp</result>
|
||||
</action>
|
||||
|
||||
<action name="quizBasic" class="org.apache.struts2.showcase.validation.QuizAction">
|
||||
<result name="input">quiz-basic.jsp</result>
|
||||
<result>quiz-success.jsp</result>
|
||||
<result name="input">/WEB-INF/validation/quiz-basic.jsp</result>
|
||||
<result>/WEB-INF/validation/quiz-success.jsp</result>
|
||||
</action>
|
||||
|
||||
<action name="quizClient" class="org.apache.struts2.showcase.validation.QuizAction">
|
||||
<result name="input">quiz-client.jsp</result>
|
||||
<result>quiz-success.jsp</result>
|
||||
<result name="input">/WEB-INF/validation/quiz-client.jsp</result>
|
||||
<result>/WEB-INF/validation/quiz-success.jsp</result>
|
||||
</action>
|
||||
|
||||
<action name="quizClientCss" class="org.apache.struts2.showcase.validation.QuizAction">
|
||||
<result name="input">quiz-client-css.jsp</result>
|
||||
<result>quiz-success.jsp</result>
|
||||
<result name="input">/WEB-INF/validation/quiz-client-css.jsp</result>
|
||||
<result>/WEB-INF/validation/quiz-success.jsp</result>
|
||||
</action>
|
||||
|
||||
<action name="quizAjax" class="org.apache.struts2.showcase.validation.QuizAction">
|
||||
<interceptor-ref name="jsonValidationWorkflowStack"/>
|
||||
<result name="input">quiz-ajax.jsp</result>
|
||||
<result>quiz-success.jsp</result>
|
||||
<result name="input">/WEB-INF/validation/quiz-ajax.jsp</result>
|
||||
<result>/WEB-INF/validation/quiz-success.jsp</result>
|
||||
</action>
|
||||
|
||||
<!-- =========================================== -->
|
||||
|
||||
@@ -0,0 +1,65 @@
|
||||
<!--
|
||||
/*
|
||||
* Licensed to the Apache Software Foundation (ASF) under one
|
||||
* or more contributor license agreements. See the NOTICE file
|
||||
* distributed with this work for additional information
|
||||
* regarding copyright ownership. The ASF licenses this file
|
||||
* to you under the Apache License, Version 2.0 (the
|
||||
* "License"); you may not use this file except in compliance
|
||||
* with the License. You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing,
|
||||
* software distributed under the License is distributed on an
|
||||
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||
* KIND, either express or implied. See the License for the
|
||||
* specific language governing permissions and limitations
|
||||
* under the License.
|
||||
*/
|
||||
-->
|
||||
<%@ page
|
||||
language="java"
|
||||
contentType="text/html; charset=UTF-8"
|
||||
pageEncoding="UTF-8"%>
|
||||
<%@ taglib prefix="s" uri="/struts-tags" %>
|
||||
<html>
|
||||
<head>
|
||||
<title>Struts2 Showcase - Fileupload sample - Multiple fileupload</title>
|
||||
</head>
|
||||
|
||||
<body>
|
||||
<div class="page-header">
|
||||
<h1>Fileupload sample - Multiple fileupload</h1>
|
||||
</div>
|
||||
|
||||
<div class="container-fluid">
|
||||
<s:iterator var="counter" begin="1" end="3">
|
||||
<!-- Mechanism for display to work with upload both as an array and list in a single JSP (a bit ugly).
|
||||
Note: Output "index" doesn't always match if the input is "sparse". -->
|
||||
<s:if test="%{#counter <= upload.length}">
|
||||
<s:set var="displayContent" value="true" />
|
||||
</s:if>
|
||||
<s:elseif test="%{#counter <= upload.size}">
|
||||
<s:set var="displayContent" value="true" />
|
||||
</s:elseif>
|
||||
<s:else>
|
||||
<s:set var="displayContent" value="false" />
|
||||
</s:else>
|
||||
<s:if test="%{#displayContent == true}">
|
||||
<div class="row">
|
||||
<div class="col-md-12">
|
||||
<b>File (<s:property value="#counter" />):</b>
|
||||
<ul>
|
||||
<li>ContentType: <s:property value="uploadContentType[#counter - 1]" /></li>
|
||||
<li>FileName: <s:property value="uploadFileName[#counter -1]" /></li>
|
||||
<li>File: <s:property value="upload[#counter - 1]" /></li>
|
||||
</ul>
|
||||
</div>
|
||||
</div>
|
||||
</s:if>
|
||||
</s:iterator>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
</html>
|
||||
@@ -39,7 +39,7 @@
|
||||
<div class="hero-unit">
|
||||
<h1>Welcome!</h1>
|
||||
<p>The Struts Showcase demonstrates a variety of use cases and tag usages. Essentially, the application exercises various framework features in isolation. The Showcase is not meant as a "best practices" example.</p>
|
||||
<p>For more "by example" solutions, see the <a class="btn btn-primary btn-large">Struts Cookbook »</a> pages.</p>
|
||||
<p>For more "by example" solutions, see the <a href="https://github.com/apache/struts-examples" class="btn btn-primary btn-large">Struts Examples »</a> pages.</p>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
|
||||
@@ -18,6 +18,7 @@
|
||||
* under the License.
|
||||
*/
|
||||
-->
|
||||
<%@page import="org.apache.struts2.showcase.hangman.HangmanConstants" %>
|
||||
<%@taglib prefix="s" uri="/struts-tags" %>
|
||||
<html>
|
||||
<head>
|
||||
@@ -635,5 +636,18 @@
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<br>
|
||||
<br>
|
||||
<p>
|
||||
A secondary test for this JSP visually verifies expression access to a public constant.
|
||||
A direct access to the same public constant via scriptlet provides secondary verification.
|
||||
</p>
|
||||
<br>
|
||||
<div>
|
||||
Test public static (constant) access (expression). Value: <s:property default="unavailable" value="@org.apache.struts2.showcase.hangman.HangmanConstants@HANGMAN_SESSION_KEY" />
|
||||
</div>
|
||||
<div>
|
||||
Test public static (constant) access (scriptlet). Value: <%=org.apache.struts2.showcase.hangman.HangmanConstants.HANGMAN_SESSION_KEY%>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -50,7 +50,7 @@
|
||||
|
||||
<@s.form action="transfer4">
|
||||
<@s.token/>
|
||||
<@s.textfield label="Amount" name="amount" required="true" value="400"/>
|
||||
<@s.textfield label="Amount" name="amount" required=true value="400"/>
|
||||
<@s.submit value="Transfer money" cssClass="btn btn-primary"/>
|
||||
</@s.form>
|
||||
</div>
|
||||
|
||||
+2
-2
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.5.16</version>
|
||||
<version>2.5.24</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-assembly</artifactId>
|
||||
@@ -111,7 +111,7 @@
|
||||
<id>make-assembly</id>
|
||||
<phase>package</phase>
|
||||
<goals>
|
||||
<goal>attached</goal>
|
||||
<goal>single</goal>
|
||||
</goals>
|
||||
</execution>
|
||||
</executions>
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
http://struts.apache.org/getting-started/
|
||||
http://struts.apache.org/security/
|
||||
http://struts.apache.org/core-developers/
|
||||
http://struts.apache.org/tag-developers/
|
||||
http://struts.apache.org/maven-archetypes/
|
||||
http://struts.apache.org/plugins/
|
||||
https://struts.apache.org/getting-started/
|
||||
https://struts.apache.org/security/
|
||||
https://struts.apache.org/core-developers/
|
||||
https://struts.apache.org/tag-developers/
|
||||
https://struts.apache.org/maven-archetypes/
|
||||
https://struts.apache.org/plugins/
|
||||
|
||||
+6
-3
@@ -30,7 +30,7 @@
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-bom</artifactId>
|
||||
<version>2.5.16</version>
|
||||
<version>2.5.24</version>
|
||||
<packaging>pom</packaging>
|
||||
|
||||
<name>Struts 2 Bill of Materials</name>
|
||||
@@ -45,7 +45,7 @@
|
||||
</licenses>
|
||||
|
||||
<properties>
|
||||
<struts-version.version>2.5.16</struts-version.version>
|
||||
<struts-version.version>2.5.24</struts-version.version>
|
||||
<maven.site.skip>true</maven.site.skip>
|
||||
<maven.site.deploy.skip>true</maven.site.deploy.skip>
|
||||
</properties>
|
||||
@@ -181,6 +181,9 @@
|
||||
</dependencyManagement>
|
||||
|
||||
<scm>
|
||||
<tag>STRUTS_2_5_16</tag>
|
||||
<tag>STRUTS_2_5_24</tag>
|
||||
<connection>scm:git:https://gitbox.apache.org/repos/asf/struts.git</connection>
|
||||
<developerConnection>scm:git:https://gitbox.apache.org/repos/asf/struts.git</developerConnection>
|
||||
<url>https://github.com/apache/struts/</url>
|
||||
</scm>
|
||||
</project>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-osgi-bundles</artifactId>
|
||||
<version>2.5.16</version>
|
||||
<version>2.5.24</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-osgi-admin-bundle</artifactId>
|
||||
|
||||
+21
-10
@@ -60,6 +60,9 @@ public class BundlesAction extends ActionSupport implements ServletContextAware
|
||||
}
|
||||
|
||||
public String start() throws BundleException {
|
||||
clearErrorsAndMessages();
|
||||
addActionMessage("Start - OSGi Host: " + osgiHost + ", ID: " + id);
|
||||
|
||||
Bundle bundle = osgiHost.getBundles().get(id);
|
||||
try {
|
||||
bundle.start();
|
||||
@@ -69,29 +72,35 @@ public class BundlesAction extends ActionSupport implements ServletContextAware
|
||||
//there no easy way/elegant way to know if the bundle was processed already
|
||||
Thread.sleep(1000);
|
||||
} catch (Exception e) {
|
||||
addActionError(e.toString());
|
||||
addActionError("Exception: " + e.toString() + " (" + e.getMessage() + ")");
|
||||
}
|
||||
|
||||
return view();
|
||||
}
|
||||
|
||||
public String stop() throws BundleException {
|
||||
clearErrorsAndMessages();
|
||||
addActionMessage("Stop - OSGi Host: " + osgiHost + ", ID: " + id);
|
||||
|
||||
Bundle bundle = osgiHost.getBundles().get(id);
|
||||
try {
|
||||
bundle.stop();
|
||||
} catch (Exception e) {
|
||||
addActionError(e.toString());
|
||||
addActionError("Exception: " + e.toString() + " (" + e.getMessage() + ")");
|
||||
}
|
||||
|
||||
return view();
|
||||
}
|
||||
|
||||
public String update() throws BundleException {
|
||||
clearErrorsAndMessages();
|
||||
addActionMessage("Update - OSGi Host: " + osgiHost + ", ID: " + id);
|
||||
|
||||
Bundle bundle = osgiHost.getBundles().get(id);
|
||||
try {
|
||||
bundle.update();
|
||||
} catch (Exception e) {
|
||||
addActionError(e.toString());
|
||||
addActionError("Exception: " + e.toString() + " (" + e.getMessage() + ")");
|
||||
}
|
||||
|
||||
return view();
|
||||
@@ -114,13 +123,14 @@ public class BundlesAction extends ActionSupport implements ServletContextAware
|
||||
}
|
||||
|
||||
public List<PackageConfig> getPackages() {
|
||||
List<PackageConfig> pkgs = new ArrayList<PackageConfig>();
|
||||
List<PackageConfig> pkgs = new ArrayList<>();
|
||||
Bundle bundle = getBundle();
|
||||
if (bundle.getState() == Bundle.ACTIVE) {
|
||||
for (String name : bundleAccessor.getPackagesByBundle(bundle)) {
|
||||
PackageConfig packageConfig = configuration.getPackageConfig(name);
|
||||
if (packageConfig != null)
|
||||
if (packageConfig != null) {
|
||||
pkgs.add(packageConfig);
|
||||
}
|
||||
}
|
||||
}
|
||||
return pkgs;
|
||||
@@ -133,13 +143,14 @@ public class BundlesAction extends ActionSupport implements ServletContextAware
|
||||
public Collection<Bundle> getBundles() {
|
||||
List<Bundle> bundles = new ArrayList(osgiHost.getBundles().values());
|
||||
Collections.sort(bundles, new Comparator<Bundle>() {
|
||||
@Override
|
||||
public int compare(Bundle bundle1, Bundle bundle2) {
|
||||
boolean bundle1StrutsEnabled = isStrutsEnabled(bundle1);
|
||||
boolean bundle2StrutsEnabled = isStrutsEnabled(bundle2);
|
||||
|
||||
if ((bundle1StrutsEnabled && bundle2StrutsEnabled) || (!bundle1StrutsEnabled && !bundle2StrutsEnabled))
|
||||
if ((bundle1StrutsEnabled && bundle2StrutsEnabled) || (!bundle1StrutsEnabled && !bundle2StrutsEnabled)) {
|
||||
return bundle1.getSymbolicName().compareTo(bundle2.getSymbolicName());
|
||||
else {
|
||||
} else {
|
||||
return bundle1StrutsEnabled ? -1 : 1;
|
||||
}
|
||||
}
|
||||
@@ -172,7 +183,7 @@ public class BundlesAction extends ActionSupport implements ServletContextAware
|
||||
try {
|
||||
state = bundle.getState();
|
||||
} catch (Exception e) {
|
||||
addActionError("Unable to determine bundle state: " + e.getMessage());
|
||||
addActionError("Unable to determine bundle state. Exception: " + e.toString() + " (" + e.getMessage() + ")");
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -181,8 +192,7 @@ public class BundlesAction extends ActionSupport implements ServletContextAware
|
||||
} else if ("stop".equals(val)) {
|
||||
return state == Bundle.ACTIVE;
|
||||
} else if ("update".equals(val)) {
|
||||
return state == Bundle.ACTIVE || state == Bundle.INSTALLED
|
||||
|| state == Bundle.RESOLVED;
|
||||
return state == Bundle.ACTIVE || state == Bundle.INSTALLED || state == Bundle.RESOLVED;
|
||||
}
|
||||
throw new IllegalArgumentException("Invalid state");
|
||||
}
|
||||
@@ -197,6 +207,7 @@ public class BundlesAction extends ActionSupport implements ServletContextAware
|
||||
this.bundleAccessor = bundleAccessor;
|
||||
}
|
||||
|
||||
@Override
|
||||
public void setServletContext(ServletContext servletContext) {
|
||||
osgiHost = (OsgiHost) servletContext.getAttribute(StrutsOsgiListener.OSGI_HOST);
|
||||
}
|
||||
|
||||
+62
-10
@@ -24,20 +24,29 @@ package org.apache.struts2.osgi.admin.actions;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.PrintStream;
|
||||
|
||||
import org.apache.struts2.osgi.DefaultBundleAccessor;
|
||||
import org.apache.felix.shell.ShellService;
|
||||
import org.apache.struts2.osgi.DefaultBundleAccessor;
|
||||
import org.apache.struts2.osgi.interceptor.BundleContextAware;
|
||||
import org.osgi.framework.Bundle;
|
||||
import org.osgi.framework.BundleContext;
|
||||
import org.osgi.framework.ServiceReference;
|
||||
|
||||
import com.opensymphony.xwork2.Action;
|
||||
import com.opensymphony.xwork2.ActionSupport;
|
||||
|
||||
/**
|
||||
* This action executes commands on the Felix Shell
|
||||
* This action executes commands on the Felix Shell.
|
||||
*
|
||||
* The action is BundleContextAware so that if the OSGi interceptor is used the BundleContext
|
||||
* can be provided for configurations where the DefaultBundleAccessor is insufficient.
|
||||
*
|
||||
*/
|
||||
public class ShellAction extends ActionSupport {
|
||||
public class ShellAction extends ActionSupport implements BundleContextAware {
|
||||
private String command;
|
||||
private String output;
|
||||
private BundleContext bundleContext;
|
||||
|
||||
@Override
|
||||
public String execute() {
|
||||
// get service
|
||||
ByteArrayOutputStream outByteStream = new ByteArrayOutputStream();
|
||||
@@ -52,7 +61,9 @@ public class ShellAction extends ActionSupport {
|
||||
outString = outByteStream.toString().trim();
|
||||
errString = errByteStream.toString().trim();
|
||||
} catch (Exception e) {
|
||||
errString = e.getMessage();
|
||||
outString = outByteStream.toString().trim();
|
||||
errString = "Exception: " + e.toString() + " (" + e.getMessage() + "). Output:" + outString +
|
||||
". Error: " + errByteStream.toString().trim(); // Full details for troubleshooting.
|
||||
} finally {
|
||||
outStream.close();
|
||||
errStream.close();
|
||||
@@ -75,17 +86,58 @@ public class ShellAction extends ActionSupport {
|
||||
}
|
||||
|
||||
public void executeCommand(String commandLine, PrintStream out, PrintStream err) throws Exception {
|
||||
ShellService shellService = getShellService();
|
||||
if (shellService != null)
|
||||
ShellService shellService = getShellService(out);
|
||||
if (shellService != null) {
|
||||
out.println("Attempting to execute command: " + commandLine);
|
||||
shellService.executeCommand(commandLine, out, err);
|
||||
}
|
||||
else
|
||||
err.println("Apache Felix Shell service is not installed");
|
||||
}
|
||||
|
||||
private ShellService getShellService() {
|
||||
private ShellService getShellService(PrintStream out) {
|
||||
//bundle can be de-activated, so keeping a reference aorund is not a good idea
|
||||
DefaultBundleAccessor bundleAcessor = DefaultBundleAccessor.getInstance();
|
||||
ServiceReference ref = bundleAcessor.getServiceReference(ShellService.class.getName());
|
||||
return (ShellService) bundleAcessor.getService(ref);
|
||||
final DefaultBundleAccessor bundleAccessor = DefaultBundleAccessor.getInstance();
|
||||
ServiceReference ref = (bundleAccessor != null ? bundleAccessor.getServiceReference(ShellService.class.getName()) : null);
|
||||
//out.println("DefaultBundleAccessor: " + bundleAcessor + ", ServiceReference [" + ShellService.class.getName() + "]: " + ref); // No logger, for debugging only.
|
||||
|
||||
if (ref == null && this.bundleContext != null) {
|
||||
// Depending on OSGi and Felix bundle configurations, the DefaultBundleAccessor may not be able to locate the ShellService.
|
||||
// In such cases, use the bundleContext (if available) to locate the ShellService in a "brute-force" manner.
|
||||
final Bundle[] bundles = this.bundleContext.getBundles();
|
||||
if (bundles != null && bundles.length > 0) {
|
||||
for (Bundle currentBundle : bundles) {
|
||||
if (currentBundle != null) {
|
||||
//out.println("Bundle [" + index + "], SymbolicName: " + currentBundle.getSymbolicName() + ", Location: " + currentBundle.getLocation() + ", BundleID: " + currentBundle.getBundleId()); // No logger, for debugging only.
|
||||
if (currentBundle.getSymbolicName().startsWith("org.apache.felix.shell")) {
|
||||
BundleContext currentBundleContext = currentBundle.getBundleContext();
|
||||
Object directShellServiceByClass = (currentBundleContext != null ? currentBundleContext.getServiceReference(org.apache.felix.shell.ShellService.class) : null);
|
||||
Object directShellServiceByName = (currentBundleContext != null ? currentBundleContext.getServiceReference("org.apache.felix.shell.ShellService") : null);
|
||||
//out.println(" ShellService reference (via bundle's context) by class: " + directShellServiceByClass); // No logger, for debugging only.
|
||||
//out.println(" ShellService reference (via bundle's context) by name: " + directShellServiceByName); // No logger, for debugging only.
|
||||
if (ref == null) {
|
||||
ref = (directShellServiceByClass != null ? (ServiceReference) directShellServiceByClass : (ServiceReference) directShellServiceByName);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
//out.println("Bundle [" + index + "] is null"); // No logger, for debugging only.
|
||||
}
|
||||
}
|
||||
} else {
|
||||
//out.println("OSGi Interceptor-provided BundleContext bundle array is null or empty"); // No logger, for debugging only.
|
||||
}
|
||||
}
|
||||
|
||||
if (ref == null) {
|
||||
out.println("ShellService reference cannot be found (null), service lookup will fail.");
|
||||
}
|
||||
|
||||
return (ShellService) (bundleAccessor != null ? bundleAccessor.getService(ref) : null);
|
||||
}
|
||||
|
||||
@Override
|
||||
public void setBundleContext(BundleContext bundleContext) {
|
||||
//System.out.println("ShellAction - setBundleContext called. BundleContext: " + bundleContext); // No logger, for debugging only.
|
||||
this.bundleContext = bundleContext;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,9 +1,13 @@
|
||||
Copyright (c) 2009 Paul Bakaus, http://jqueryui.com/
|
||||
Copyright jQuery Foundation and other contributors, https://jquery.org/
|
||||
|
||||
This software consists of voluntary contributions made by many
|
||||
individuals (AUTHORS.txt, http://jqueryui.com/about) For exact
|
||||
contribution history, see the revision history and logs, available
|
||||
at http://jquery-ui.googlecode.com/svn/
|
||||
individuals. For exact contribution history, see the revision history
|
||||
available at https://github.com/jquery/jquery-ui
|
||||
|
||||
The following license applies to all parts of this software except as
|
||||
documented below:
|
||||
|
||||
====
|
||||
|
||||
Permission is hereby granted, free of charge, to any person obtaining
|
||||
a copy of this software and associated documentation files (the
|
||||
@@ -23,3 +27,17 @@ NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
|
||||
LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
|
||||
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
|
||||
WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
||||
|
||||
====
|
||||
|
||||
Copyright and related rights for sample code are waived via CC0. Sample
|
||||
code is defined as all source code contained within the demos directory.
|
||||
|
||||
CC0: http://creativecommons.org/publicdomain/zero/1.0/
|
||||
|
||||
====
|
||||
|
||||
All files located in the node_modules and external directories are
|
||||
externally maintained libraries used by this software which have their
|
||||
own licenses; we recommend you read them, as their terms may differ from
|
||||
the terms above.
|
||||
|
||||
@@ -2,7 +2,8 @@ Apache Struts
|
||||
Copyright 2000-2011 The Apache Software Foundation
|
||||
|
||||
This product includes software developed by
|
||||
The Apache Software Foundation (http://www.apache.org/).
|
||||
The Apache Software Foundation (https://www.apache.org/).
|
||||
|
||||
The binary distributions includes the following third party software:
|
||||
JQuery (http://jquery.com/).
|
||||
jQuery (https://jquery.com/).
|
||||
jQuery UI (https://jqueryui.com/).
|
||||
|
||||
@@ -24,11 +24,11 @@
|
||||
|
||||
<link rel="stylesheet" type="text/css" href="<@s.url value="/static/css/shell.css" />" />
|
||||
<link rel="stylesheet" type="text/css" href="<@s.url value="/static/css/main.css" />" />
|
||||
<link rel="stylesheet" type="text/css" href="<@s.url value="/static/css/redmond/jquery-ui-1.7.1.custom.css" />" />
|
||||
<link rel="stylesheet" type="text/css" href="<@s.url value="/static/css/redmond/jquery-ui-1.12.1.redmond.css" />" />
|
||||
|
||||
<script src="<@s.url value="/static/js/shell.js" />"></script>
|
||||
<script src="<@s.url value="/static/js/jquery-1.3.2.min.js" />"></script>
|
||||
<script src="<@s.url value="/static/js/jquery-ui-1.7.1.custom.min.js" />"></script>
|
||||
<script src="<@s.url value="/static/js/jquery-1.12.4.min.js" />"></script>
|
||||
<script src="<@s.url value="/static/js/jquery-ui-1.12.1.min.js" />"></script>
|
||||
</head>
|
||||
<body>
|
||||
<div class="menu">
|
||||
|
||||
@@ -23,10 +23,10 @@
|
||||
<title>${bundle.symbolicName!}</title>
|
||||
|
||||
<link rel="stylesheet" type="text/css" href="<@s.url value="/static/css/main.css" />" />
|
||||
<link rel="stylesheet" type="text/css" href="<@s.url value="/static/css/redmond/jquery-ui-1.7.1.custom.css" />" />
|
||||
<link rel="stylesheet" type="text/css" href="<@s.url value="/static/css/redmond/jquery-ui-1.12.1.redmond.css" />" />
|
||||
|
||||
<script src="<@s.url value="/static/js/jquery-1.3.2.min.js" />"></script>
|
||||
<script src="<@s.url value="/static/js/jquery-ui-1.7.1.custom.min.js" />"></script>
|
||||
<script src="<@s.url value="/static/js/jquery-1.12.4.min.js" />"></script>
|
||||
<script src="<@s.url value="/static/js/jquery-ui-1.12.1.min.js" />"></script>
|
||||
|
||||
<script type="text/javascript">
|
||||
$(function() {
|
||||
@@ -163,5 +163,8 @@
|
||||
</table>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<@s.actionmessage />
|
||||
|
||||
</body>
|
||||
</html>
|
||||
@@ -23,10 +23,10 @@
|
||||
<title>OSGi Bundles</title>
|
||||
|
||||
<link rel="stylesheet" type="text/css" href="<@s.url value="/static/css/main.css" />" />
|
||||
<link rel="stylesheet" type="text/css" href="<@s.url value="/static/css/redmond/jquery-ui-1.7.1.custom.css" />" />
|
||||
<link rel="stylesheet" type="text/css" href="<@s.url value="/static/css/redmond/jquery-ui-1.12.1.redmond.css" />" />
|
||||
|
||||
<script src="<@s.url value="/static/js/jquery-1.3.2.min.js" />"></script>
|
||||
<script src="<@s.url value="/static/js/jquery-ui-1.7.1.custom.min.js" />"></script>
|
||||
<script src="<@s.url value="/static/js/jquery-1.12.4.min.js" />"></script>
|
||||
<script src="<@s.url value="/static/js/jquery-ui-1.12.1.min.js" />"></script>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
@@ -44,6 +44,9 @@
|
||||
</a>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<@s.actionerror />
|
||||
|
||||
<table class="properties" style="clear:both; width:700px">
|
||||
<thead>
|
||||
<tr>
|
||||
@@ -87,5 +90,8 @@
|
||||
</#list>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
<@s.actionmessage />
|
||||
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+1311
File diff suppressed because it is too large
Load Diff
-404
@@ -1,404 +0,0 @@
|
||||
/*
|
||||
* jQuery UI CSS Framework
|
||||
* Copyright (c) 2009 AUTHORS.txt (http://jqueryui.com/about)
|
||||
* Dual licensed under the MIT (MIT-LICENSE.txt) and GPL (GPL-LICENSE.txt) licenses.
|
||||
*/
|
||||
|
||||
/* Layout helpers
|
||||
----------------------------------*/
|
||||
.ui-helper-hidden { display: none; }
|
||||
.ui-helper-hidden-accessible { position: absolute; left: -99999999px; }
|
||||
.ui-helper-reset { margin: 0; padding: 0; border: 0; outline: 0; line-height: 1.3; text-decoration: none; font-size: 100%; list-style: none; }
|
||||
.ui-helper-clearfix:after { content: "."; display: block; height: 0; clear: both; visibility: hidden; }
|
||||
.ui-helper-clearfix { display: inline-block; }
|
||||
/* required comment for clearfix to work in Opera \*/
|
||||
* html .ui-helper-clearfix { height:1%; }
|
||||
.ui-helper-clearfix { display:block; }
|
||||
/* end clearfix */
|
||||
.ui-helper-zfix { width: 100%; height: 100%; top: 0; left: 0; position: absolute; opacity: 0; filter:Alpha(Opacity=0); }
|
||||
|
||||
|
||||
/* Interaction Cues
|
||||
----------------------------------*/
|
||||
.ui-state-disabled { cursor: default !important; }
|
||||
|
||||
|
||||
/* Icons
|
||||
----------------------------------*/
|
||||
|
||||
/* states and images */
|
||||
.ui-icon { display: block; text-indent: -99999px; overflow: hidden; background-repeat: no-repeat; }
|
||||
|
||||
|
||||
/* Misc visuals
|
||||
----------------------------------*/
|
||||
|
||||
/* Overlays */
|
||||
.ui-widget-overlay { position: absolute; top: 0; left: 0; width: 100%; height: 100%; }
|
||||
|
||||
/*
|
||||
* jQuery UI CSS Framework
|
||||
* Copyright (c) 2009 AUTHORS.txt (http://jqueryui.com/about)
|
||||
* Dual licensed under the MIT (MIT-LICENSE.txt) and GPL (GPL-LICENSE.txt) licenses.
|
||||
* To view and modify this theme, visit http://jqueryui.com/themeroller/?ffDefault=Lucida%20Grande,%20Lucida%20Sans,%20Arial,%20sans-serif&fwDefault=bold&fsDefault=1.1em&cornerRadius=5px&bgColorHeader=5c9ccc&bgTextureHeader=12_gloss_wave.png&bgImgOpacityHeader=55&borderColorHeader=4297d7&fcHeader=ffffff&iconColorHeader=d8e7f3&bgColorContent=fcfdfd&bgTextureContent=06_inset_hard.png&bgImgOpacityContent=100&borderColorContent=a6c9e2&fcContent=222222&iconColorContent=469bdd&bgColorDefault=dfeffc&bgTextureDefault=02_glass.png&bgImgOpacityDefault=85&borderColorDefault=c5dbec&fcDefault=2e6e9e&iconColorDefault=6da8d5&bgColorHover=d0e5f5&bgTextureHover=02_glass.png&bgImgOpacityHover=75&borderColorHover=79b7e7&fcHover=1d5987&iconColorHover=217bc0&bgColorActive=f5f8f9&bgTextureActive=06_inset_hard.png&bgImgOpacityActive=100&borderColorActive=79b7e7&fcActive=e17009&iconColorActive=f9bd01&bgColorHighlight=fbec88&bgTextureHighlight=01_flat.png&bgImgOpacityHighlight=55&borderColorHighlight=fad42e&fcHighlight=363636&iconColorHighlight=2e83ff&bgColorError=fef1ec&bgTextureError=02_glass.png&bgImgOpacityError=95&borderColorError=cd0a0a&fcError=cd0a0a&iconColorError=cd0a0a&bgColorOverlay=aaaaaa&bgTextureOverlay=01_flat.png&bgImgOpacityOverlay=0&opacityOverlay=30&bgColorShadow=aaaaaa&bgTextureShadow=01_flat.png&bgImgOpacityShadow=0&opacityShadow=30&thicknessShadow=8px&offsetTopShadow=-8px&offsetLeftShadow=-8px&cornerRadiusShadow=8px
|
||||
*/
|
||||
|
||||
|
||||
/* Component containers
|
||||
----------------------------------*/
|
||||
.ui-widget { font-family: Lucida Grande, Lucida Sans, Arial, sans-serif; font-size: 1.1em; }
|
||||
.ui-widget input, .ui-widget select, .ui-widget textarea, .ui-widget button { font-family: Lucida Grande, Lucida Sans, Arial, sans-serif; font-size: 1em; }
|
||||
.ui-widget-content { border: 1px solid #a6c9e2; background: #fcfdfd url(images/ui-bg_inset-hard_100_fcfdfd_1x100.png) 50% bottom repeat-x; color: #222222; }
|
||||
.ui-widget-content a { color: #222222; }
|
||||
.ui-widget-header { border: 1px solid #4297d7; background: #5c9ccc url(images/ui-bg_gloss-wave_55_5c9ccc_500x100.png) 50% 50% repeat-x; color: #ffffff; font-weight: bold; }
|
||||
.ui-widget-header a { color: #ffffff; }
|
||||
|
||||
/* Interaction states
|
||||
----------------------------------*/
|
||||
.ui-state-default, .ui-widget-content .ui-state-default { border: 1px solid #c5dbec; background: #dfeffc url(images/ui-bg_glass_85_dfeffc_1x400.png) 50% 50% repeat-x; font-weight: bold; color: #2e6e9e; outline: none; }
|
||||
.ui-state-default a, .ui-state-default a:link, .ui-state-default a:visited { color: #2e6e9e; text-decoration: none; outline: none; }
|
||||
.ui-state-hover, .ui-widget-content .ui-state-hover, .ui-state-focus, .ui-widget-content .ui-state-focus { border: 1px solid #79b7e7; background: #d0e5f5 url(images/ui-bg_glass_75_d0e5f5_1x400.png) 50% 50% repeat-x; font-weight: bold; color: #1d5987; outline: none; }
|
||||
.ui-state-hover a, .ui-state-hover a:hover { color: #1d5987; text-decoration: none; outline: none; }
|
||||
.ui-state-active, .ui-widget-content .ui-state-active { border: 1px solid #79b7e7; background: #f5f8f9 url(images/ui-bg_inset-hard_100_f5f8f9_1x100.png) 50% 50% repeat-x; font-weight: bold; color: #e17009; outline: none; }
|
||||
.ui-state-active a, .ui-state-active a:link, .ui-state-active a:visited { color: #e17009; outline: none; text-decoration: none; }
|
||||
|
||||
/* Interaction Cues
|
||||
----------------------------------*/
|
||||
.ui-state-highlight, .ui-widget-content .ui-state-highlight {border: 1px solid #fad42e; background: #fbec88 url(images/ui-bg_flat_55_fbec88_40x100.png) 50% 50% repeat-x; color: #363636; }
|
||||
.ui-state-highlight a, .ui-widget-content .ui-state-highlight a { color: #363636; }
|
||||
.ui-state-error, .ui-widget-content .ui-state-error {border: 1px solid #cd0a0a; background: #fef1ec url(images/ui-bg_glass_95_fef1ec_1x400.png) 50% 50% repeat-x; color: #cd0a0a; }
|
||||
.ui-state-error a, .ui-widget-content .ui-state-error a { color: #cd0a0a; }
|
||||
.ui-state-error-text, .ui-widget-content .ui-state-error-text { color: #cd0a0a; }
|
||||
.ui-state-disabled, .ui-widget-content .ui-state-disabled { opacity: .35; filter:Alpha(Opacity=35); background-image: none; }
|
||||
.ui-priority-primary, .ui-widget-content .ui-priority-primary { font-weight: bold; }
|
||||
.ui-priority-secondary, .ui-widget-content .ui-priority-secondary { opacity: .7; filter:Alpha(Opacity=70); font-weight: normal; }
|
||||
|
||||
/* Icons
|
||||
----------------------------------*/
|
||||
|
||||
/* states and images */
|
||||
.ui-icon { width: 16px; height: 16px; background-image: url(images/ui-icons_469bdd_256x240.png); }
|
||||
.ui-widget-content .ui-icon {background-image: url(images/ui-icons_469bdd_256x240.png); }
|
||||
.ui-widget-header .ui-icon {background-image: url(images/ui-icons_d8e7f3_256x240.png); }
|
||||
.ui-state-default .ui-icon { background-image: url(images/ui-icons_6da8d5_256x240.png); }
|
||||
.ui-state-hover .ui-icon, .ui-state-focus .ui-icon {background-image: url(images/ui-icons_217bc0_256x240.png); }
|
||||
.ui-state-active .ui-icon {background-image: url(images/ui-icons_f9bd01_256x240.png); }
|
||||
.ui-state-highlight .ui-icon {background-image: url(images/ui-icons_2e83ff_256x240.png); }
|
||||
.ui-state-error .ui-icon, .ui-state-error-text .ui-icon {background-image: url(images/ui-icons_cd0a0a_256x240.png); }
|
||||
|
||||
/* positioning */
|
||||
.ui-icon-carat-1-n { background-position: 0 0; }
|
||||
.ui-icon-carat-1-ne { background-position: -16px 0; }
|
||||
.ui-icon-carat-1-e { background-position: -32px 0; }
|
||||
.ui-icon-carat-1-se { background-position: -48px 0; }
|
||||
.ui-icon-carat-1-s { background-position: -64px 0; }
|
||||
.ui-icon-carat-1-sw { background-position: -80px 0; }
|
||||
.ui-icon-carat-1-w { background-position: -96px 0; }
|
||||
.ui-icon-carat-1-nw { background-position: -112px 0; }
|
||||
.ui-icon-carat-2-n-s { background-position: -128px 0; }
|
||||
.ui-icon-carat-2-e-w { background-position: -144px 0; }
|
||||
.ui-icon-triangle-1-n { background-position: 0 -16px; }
|
||||
.ui-icon-triangle-1-ne { background-position: -16px -16px; }
|
||||
.ui-icon-triangle-1-e { background-position: -32px -16px; }
|
||||
.ui-icon-triangle-1-se { background-position: -48px -16px; }
|
||||
.ui-icon-triangle-1-s { background-position: -64px -16px; }
|
||||
.ui-icon-triangle-1-sw { background-position: -80px -16px; }
|
||||
.ui-icon-triangle-1-w { background-position: -96px -16px; }
|
||||
.ui-icon-triangle-1-nw { background-position: -112px -16px; }
|
||||
.ui-icon-triangle-2-n-s { background-position: -128px -16px; }
|
||||
.ui-icon-triangle-2-e-w { background-position: -144px -16px; }
|
||||
.ui-icon-arrow-1-n { background-position: 0 -32px; }
|
||||
.ui-icon-arrow-1-ne { background-position: -16px -32px; }
|
||||
.ui-icon-arrow-1-e { background-position: -32px -32px; }
|
||||
.ui-icon-arrow-1-se { background-position: -48px -32px; }
|
||||
.ui-icon-arrow-1-s { background-position: -64px -32px; }
|
||||
.ui-icon-arrow-1-sw { background-position: -80px -32px; }
|
||||
.ui-icon-arrow-1-w { background-position: -96px -32px; }
|
||||
.ui-icon-arrow-1-nw { background-position: -112px -32px; }
|
||||
.ui-icon-arrow-2-n-s { background-position: -128px -32px; }
|
||||
.ui-icon-arrow-2-ne-sw { background-position: -144px -32px; }
|
||||
.ui-icon-arrow-2-e-w { background-position: -160px -32px; }
|
||||
.ui-icon-arrow-2-se-nw { background-position: -176px -32px; }
|
||||
.ui-icon-arrowstop-1-n { background-position: -192px -32px; }
|
||||
.ui-icon-arrowstop-1-e { background-position: -208px -32px; }
|
||||
.ui-icon-arrowstop-1-s { background-position: -224px -32px; }
|
||||
.ui-icon-arrowstop-1-w { background-position: -240px -32px; }
|
||||
.ui-icon-arrowthick-1-n { background-position: 0 -48px; }
|
||||
.ui-icon-arrowthick-1-ne { background-position: -16px -48px; }
|
||||
.ui-icon-arrowthick-1-e { background-position: -32px -48px; }
|
||||
.ui-icon-arrowthick-1-se { background-position: -48px -48px; }
|
||||
.ui-icon-arrowthick-1-s { background-position: -64px -48px; }
|
||||
.ui-icon-arrowthick-1-sw { background-position: -80px -48px; }
|
||||
.ui-icon-arrowthick-1-w { background-position: -96px -48px; }
|
||||
.ui-icon-arrowthick-1-nw { background-position: -112px -48px; }
|
||||
.ui-icon-arrowthick-2-n-s { background-position: -128px -48px; }
|
||||
.ui-icon-arrowthick-2-ne-sw { background-position: -144px -48px; }
|
||||
.ui-icon-arrowthick-2-e-w { background-position: -160px -48px; }
|
||||
.ui-icon-arrowthick-2-se-nw { background-position: -176px -48px; }
|
||||
.ui-icon-arrowthickstop-1-n { background-position: -192px -48px; }
|
||||
.ui-icon-arrowthickstop-1-e { background-position: -208px -48px; }
|
||||
.ui-icon-arrowthickstop-1-s { background-position: -224px -48px; }
|
||||
.ui-icon-arrowthickstop-1-w { background-position: -240px -48px; }
|
||||
.ui-icon-arrowreturnthick-1-w { background-position: 0 -64px; }
|
||||
.ui-icon-arrowreturnthick-1-n { background-position: -16px -64px; }
|
||||
.ui-icon-arrowreturnthick-1-e { background-position: -32px -64px; }
|
||||
.ui-icon-arrowreturnthick-1-s { background-position: -48px -64px; }
|
||||
.ui-icon-arrowreturn-1-w { background-position: -64px -64px; }
|
||||
.ui-icon-arrowreturn-1-n { background-position: -80px -64px; }
|
||||
.ui-icon-arrowreturn-1-e { background-position: -96px -64px; }
|
||||
.ui-icon-arrowreturn-1-s { background-position: -112px -64px; }
|
||||
.ui-icon-arrowrefresh-1-w { background-position: -128px -64px; }
|
||||
.ui-icon-arrowrefresh-1-n { background-position: -144px -64px; }
|
||||
.ui-icon-arrowrefresh-1-e { background-position: -160px -64px; }
|
||||
.ui-icon-arrowrefresh-1-s { background-position: -176px -64px; }
|
||||
.ui-icon-arrow-4 { background-position: 0 -80px; }
|
||||
.ui-icon-arrow-4-diag { background-position: -16px -80px; }
|
||||
.ui-icon-extlink { background-position: -32px -80px; }
|
||||
.ui-icon-newwin { background-position: -48px -80px; }
|
||||
.ui-icon-refresh { background-position: -64px -80px; }
|
||||
.ui-icon-shuffle { background-position: -80px -80px; }
|
||||
.ui-icon-transfer-e-w { background-position: -96px -80px; }
|
||||
.ui-icon-transferthick-e-w { background-position: -112px -80px; }
|
||||
.ui-icon-folder-collapsed { background-position: 0 -96px; }
|
||||
.ui-icon-folder-open { background-position: -16px -96px; }
|
||||
.ui-icon-document { background-position: -32px -96px; }
|
||||
.ui-icon-document-b { background-position: -48px -96px; }
|
||||
.ui-icon-note { background-position: -64px -96px; }
|
||||
.ui-icon-mail-closed { background-position: -80px -96px; }
|
||||
.ui-icon-mail-open { background-position: -96px -96px; }
|
||||
.ui-icon-suitcase { background-position: -112px -96px; }
|
||||
.ui-icon-comment { background-position: -128px -96px; }
|
||||
.ui-icon-person { background-position: -144px -96px; }
|
||||
.ui-icon-print { background-position: -160px -96px; }
|
||||
.ui-icon-trash { background-position: -176px -96px; }
|
||||
.ui-icon-locked { background-position: -192px -96px; }
|
||||
.ui-icon-unlocked { background-position: -208px -96px; }
|
||||
.ui-icon-bookmark { background-position: -224px -96px; }
|
||||
.ui-icon-tag { background-position: -240px -96px; }
|
||||
.ui-icon-home { background-position: 0 -112px; }
|
||||
.ui-icon-flag { background-position: -16px -112px; }
|
||||
.ui-icon-calendar { background-position: -32px -112px; }
|
||||
.ui-icon-cart { background-position: -48px -112px; }
|
||||
.ui-icon-pencil { background-position: -64px -112px; }
|
||||
.ui-icon-clock { background-position: -80px -112px; }
|
||||
.ui-icon-disk { background-position: -96px -112px; }
|
||||
.ui-icon-calculator { background-position: -112px -112px; }
|
||||
.ui-icon-zoomin { background-position: -128px -112px; }
|
||||
.ui-icon-zoomout { background-position: -144px -112px; }
|
||||
.ui-icon-search { background-position: -160px -112px; }
|
||||
.ui-icon-wrench { background-position: -176px -112px; }
|
||||
.ui-icon-gear { background-position: -192px -112px; }
|
||||
.ui-icon-heart { background-position: -208px -112px; }
|
||||
.ui-icon-star { background-position: -224px -112px; }
|
||||
.ui-icon-link { background-position: -240px -112px; }
|
||||
.ui-icon-cancel { background-position: 0 -128px; }
|
||||
.ui-icon-plus { background-position: -16px -128px; }
|
||||
.ui-icon-plusthick { background-position: -32px -128px; }
|
||||
.ui-icon-minus { background-position: -48px -128px; }
|
||||
.ui-icon-minusthick { background-position: -64px -128px; }
|
||||
.ui-icon-close { background-position: -80px -128px; }
|
||||
.ui-icon-closethick { background-position: -96px -128px; }
|
||||
.ui-icon-key { background-position: -112px -128px; }
|
||||
.ui-icon-lightbulb { background-position: -128px -128px; }
|
||||
.ui-icon-scissors { background-position: -144px -128px; }
|
||||
.ui-icon-clipboard { background-position: -160px -128px; }
|
||||
.ui-icon-copy { background-position: -176px -128px; }
|
||||
.ui-icon-contact { background-position: -192px -128px; }
|
||||
.ui-icon-image { background-position: -208px -128px; }
|
||||
.ui-icon-video { background-position: -224px -128px; }
|
||||
.ui-icon-script { background-position: -240px -128px; }
|
||||
.ui-icon-alert { background-position: 0 -144px; }
|
||||
.ui-icon-info { background-position: -16px -144px; }
|
||||
.ui-icon-notice { background-position: -32px -144px; }
|
||||
.ui-icon-help { background-position: -48px -144px; }
|
||||
.ui-icon-check { background-position: -64px -144px; }
|
||||
.ui-icon-bullet { background-position: -80px -144px; }
|
||||
.ui-icon-radio-off { background-position: -96px -144px; }
|
||||
.ui-icon-radio-on { background-position: -112px -144px; }
|
||||
.ui-icon-pin-w { background-position: -128px -144px; }
|
||||
.ui-icon-pin-s { background-position: -144px -144px; }
|
||||
.ui-icon-play { background-position: 0 -160px; }
|
||||
.ui-icon-pause { background-position: -16px -160px; }
|
||||
.ui-icon-seek-next { background-position: -32px -160px; }
|
||||
.ui-icon-seek-prev { background-position: -48px -160px; }
|
||||
.ui-icon-seek-end { background-position: -64px -160px; }
|
||||
.ui-icon-seek-first { background-position: -80px -160px; }
|
||||
.ui-icon-stop { background-position: -96px -160px; }
|
||||
.ui-icon-eject { background-position: -112px -160px; }
|
||||
.ui-icon-volume-off { background-position: -128px -160px; }
|
||||
.ui-icon-volume-on { background-position: -144px -160px; }
|
||||
.ui-icon-power { background-position: 0 -176px; }
|
||||
.ui-icon-signal-diag { background-position: -16px -176px; }
|
||||
.ui-icon-signal { background-position: -32px -176px; }
|
||||
.ui-icon-battery-0 { background-position: -48px -176px; }
|
||||
.ui-icon-battery-1 { background-position: -64px -176px; }
|
||||
.ui-icon-battery-2 { background-position: -80px -176px; }
|
||||
.ui-icon-battery-3 { background-position: -96px -176px; }
|
||||
.ui-icon-circle-plus { background-position: 0 -192px; }
|
||||
.ui-icon-circle-minus { background-position: -16px -192px; }
|
||||
.ui-icon-circle-close { background-position: -32px -192px; }
|
||||
.ui-icon-circle-triangle-e { background-position: -48px -192px; }
|
||||
.ui-icon-circle-triangle-s { background-position: -64px -192px; }
|
||||
.ui-icon-circle-triangle-w { background-position: -80px -192px; }
|
||||
.ui-icon-circle-triangle-n { background-position: -96px -192px; }
|
||||
.ui-icon-circle-arrow-e { background-position: -112px -192px; }
|
||||
.ui-icon-circle-arrow-s { background-position: -128px -192px; }
|
||||
.ui-icon-circle-arrow-w { background-position: -144px -192px; }
|
||||
.ui-icon-circle-arrow-n { background-position: -160px -192px; }
|
||||
.ui-icon-circle-zoomin { background-position: -176px -192px; }
|
||||
.ui-icon-circle-zoomout { background-position: -192px -192px; }
|
||||
.ui-icon-circle-check { background-position: -208px -192px; }
|
||||
.ui-icon-circlesmall-plus { background-position: 0 -208px; }
|
||||
.ui-icon-circlesmall-minus { background-position: -16px -208px; }
|
||||
.ui-icon-circlesmall-close { background-position: -32px -208px; }
|
||||
.ui-icon-squaresmall-plus { background-position: -48px -208px; }
|
||||
.ui-icon-squaresmall-minus { background-position: -64px -208px; }
|
||||
.ui-icon-squaresmall-close { background-position: -80px -208px; }
|
||||
.ui-icon-grip-dotted-vertical { background-position: 0 -224px; }
|
||||
.ui-icon-grip-dotted-horizontal { background-position: -16px -224px; }
|
||||
.ui-icon-grip-solid-vertical { background-position: -32px -224px; }
|
||||
.ui-icon-grip-solid-horizontal { background-position: -48px -224px; }
|
||||
.ui-icon-gripsmall-diagonal-se { background-position: -64px -224px; }
|
||||
.ui-icon-grip-diagonal-se { background-position: -80px -224px; }
|
||||
|
||||
|
||||
/* Misc visuals
|
||||
----------------------------------*/
|
||||
|
||||
/* Corner radius */
|
||||
.ui-corner-tl { -moz-border-radius-topleft: 5px; -webkit-border-top-left-radius: 5px; }
|
||||
.ui-corner-tr { -moz-border-radius-topright: 5px; -webkit-border-top-right-radius: 5px; }
|
||||
.ui-corner-bl { -moz-border-radius-bottomleft: 5px; -webkit-border-bottom-left-radius: 5px; }
|
||||
.ui-corner-br { -moz-border-radius-bottomright: 5px; -webkit-border-bottom-right-radius: 5px; }
|
||||
.ui-corner-top { -moz-border-radius-topleft: 5px; -webkit-border-top-left-radius: 5px; -moz-border-radius-topright: 5px; -webkit-border-top-right-radius: 5px; }
|
||||
.ui-corner-bottom { -moz-border-radius-bottomleft: 5px; -webkit-border-bottom-left-radius: 5px; -moz-border-radius-bottomright: 5px; -webkit-border-bottom-right-radius: 5px; }
|
||||
.ui-corner-right { -moz-border-radius-topright: 5px; -webkit-border-top-right-radius: 5px; -moz-border-radius-bottomright: 5px; -webkit-border-bottom-right-radius: 5px; }
|
||||
.ui-corner-left { -moz-border-radius-topleft: 5px; -webkit-border-top-left-radius: 5px; -moz-border-radius-bottomleft: 5px; -webkit-border-bottom-left-radius: 5px; }
|
||||
.ui-corner-all { -moz-border-radius: 5px; -webkit-border-radius: 5px; }
|
||||
|
||||
/* Overlays */
|
||||
.ui-widget-overlay { background: #aaaaaa url(images/ui-bg_flat_0_aaaaaa_40x100.png) 50% 50% repeat-x; opacity: .30;filter:Alpha(Opacity=30); }
|
||||
.ui-widget-shadow { margin: -8px 0 0 -8px; padding: 8px; background: #aaaaaa url(images/ui-bg_flat_0_aaaaaa_40x100.png) 50% 50% repeat-x; opacity: .30;filter:Alpha(Opacity=30); -moz-border-radius: 8px; -webkit-border-radius: 8px; }/* Accordion
|
||||
----------------------------------*/
|
||||
.ui-accordion .ui-accordion-header { cursor: pointer; position: relative; margin-top: 1px; zoom: 1; }
|
||||
.ui-accordion .ui-accordion-li-fix { display: inline; }
|
||||
.ui-accordion .ui-accordion-header-active { border-bottom: 0 !important; }
|
||||
.ui-accordion .ui-accordion-header a { display: block; font-size: 1em; padding: .5em .5em .5em 2.2em; }
|
||||
.ui-accordion .ui-accordion-header .ui-icon { position: absolute; left: .5em; top: 50%; margin-top: -8px; }
|
||||
.ui-accordion .ui-accordion-content { padding: 1em 2.2em; border-top: 0; margin-top: -2px; position: relative; top: 1px; margin-bottom: 2px; overflow: auto; display: none; }
|
||||
.ui-accordion .ui-accordion-content-active { display: block; }/* Datepicker
|
||||
----------------------------------*/
|
||||
.ui-datepicker { width: 17em; padding: .2em .2em 0; }
|
||||
.ui-datepicker .ui-datepicker-header { position:relative; padding:.2em 0; }
|
||||
.ui-datepicker .ui-datepicker-prev, .ui-datepicker .ui-datepicker-next { position:absolute; top: 2px; width: 1.8em; height: 1.8em; }
|
||||
.ui-datepicker .ui-datepicker-prev-hover, .ui-datepicker .ui-datepicker-next-hover { top: 1px; }
|
||||
.ui-datepicker .ui-datepicker-prev { left:2px; }
|
||||
.ui-datepicker .ui-datepicker-next { right:2px; }
|
||||
.ui-datepicker .ui-datepicker-prev-hover { left:1px; }
|
||||
.ui-datepicker .ui-datepicker-next-hover { right:1px; }
|
||||
.ui-datepicker .ui-datepicker-prev span, .ui-datepicker .ui-datepicker-next span { display: block; position: absolute; left: 50%; margin-left: -8px; top: 50%; margin-top: -8px; }
|
||||
.ui-datepicker .ui-datepicker-title { margin: 0 2.3em; line-height: 1.8em; text-align: center; }
|
||||
.ui-datepicker .ui-datepicker-title select { float:left; font-size:1em; margin:1px 0; }
|
||||
.ui-datepicker select.ui-datepicker-month-year {width: 100%;}
|
||||
.ui-datepicker select.ui-datepicker-month,
|
||||
.ui-datepicker select.ui-datepicker-year { width: 49%;}
|
||||
.ui-datepicker .ui-datepicker-title select.ui-datepicker-year { float: right; }
|
||||
.ui-datepicker table {width: 100%; font-size: .9em; border-collapse: collapse; margin:0 0 .4em; }
|
||||
.ui-datepicker th { padding: .7em .3em; text-align: center; font-weight: bold; border: 0; }
|
||||
.ui-datepicker td { border: 0; padding: 1px; }
|
||||
.ui-datepicker td span, .ui-datepicker td a { display: block; padding: .2em; text-align: right; text-decoration: none; }
|
||||
.ui-datepicker .ui-datepicker-buttonpane { background-image: none; margin: .7em 0 0 0; padding:0 .2em; border-left: 0; border-right: 0; border-bottom: 0; }
|
||||
.ui-datepicker .ui-datepicker-buttonpane button { float: right; margin: .5em .2em .4em; cursor: pointer; padding: .2em .6em .3em .6em; width:auto; overflow:visible; }
|
||||
.ui-datepicker .ui-datepicker-buttonpane button.ui-datepicker-current { float:left; }
|
||||
|
||||
/* with multiple calendars */
|
||||
.ui-datepicker.ui-datepicker-multi { width:auto; }
|
||||
.ui-datepicker-multi .ui-datepicker-group { float:left; }
|
||||
.ui-datepicker-multi .ui-datepicker-group table { width:95%; margin:0 auto .4em; }
|
||||
.ui-datepicker-multi-2 .ui-datepicker-group { width:50%; }
|
||||
.ui-datepicker-multi-3 .ui-datepicker-group { width:33.3%; }
|
||||
.ui-datepicker-multi-4 .ui-datepicker-group { width:25%; }
|
||||
.ui-datepicker-multi .ui-datepicker-group-last .ui-datepicker-header { border-left-width:0; }
|
||||
.ui-datepicker-multi .ui-datepicker-group-middle .ui-datepicker-header { border-left-width:0; }
|
||||
.ui-datepicker-multi .ui-datepicker-buttonpane { clear:left; }
|
||||
.ui-datepicker-row-break { clear:both; width:100%; }
|
||||
|
||||
/* RTL support */
|
||||
.ui-datepicker-rtl { direction: rtl; }
|
||||
.ui-datepicker-rtl .ui-datepicker-prev { right: 2px; left: auto; }
|
||||
.ui-datepicker-rtl .ui-datepicker-next { left: 2px; right: auto; }
|
||||
.ui-datepicker-rtl .ui-datepicker-prev:hover { right: 1px; left: auto; }
|
||||
.ui-datepicker-rtl .ui-datepicker-next:hover { left: 1px; right: auto; }
|
||||
.ui-datepicker-rtl .ui-datepicker-buttonpane { clear:right; }
|
||||
.ui-datepicker-rtl .ui-datepicker-buttonpane button { float: left; }
|
||||
.ui-datepicker-rtl .ui-datepicker-buttonpane button.ui-datepicker-current { float:right; }
|
||||
.ui-datepicker-rtl .ui-datepicker-group { float:right; }
|
||||
.ui-datepicker-rtl .ui-datepicker-group-last .ui-datepicker-header { border-right-width:0; border-left-width:1px; }
|
||||
.ui-datepicker-rtl .ui-datepicker-group-middle .ui-datepicker-header { border-right-width:0; border-left-width:1px; }
|
||||
|
||||
/* IE6 IFRAME FIX (taken from datepicker 1.5.3 */
|
||||
.ui-datepicker-cover {
|
||||
display: none; /*sorry for IE5*/
|
||||
display/**/: block; /*sorry for IE5*/
|
||||
position: absolute; /*must have*/
|
||||
z-index: -1; /*must have*/
|
||||
filter: mask(); /*must have*/
|
||||
top: -4px; /*must have*/
|
||||
left: -4px; /*must have*/
|
||||
width: 200px; /*must have*/
|
||||
height: 200px; /*must have*/
|
||||
}/* Dialog
|
||||
----------------------------------*/
|
||||
.ui-dialog { position: relative; padding: .2em; width: 300px; }
|
||||
.ui-dialog .ui-dialog-titlebar { padding: .5em .3em .3em 1em; position: relative; }
|
||||
.ui-dialog .ui-dialog-title { float: left; margin: .1em 0 .2em; }
|
||||
.ui-dialog .ui-dialog-titlebar-close { position: absolute; right: .3em; top: 50%; width: 19px; margin: -10px 0 0 0; padding: 1px; height: 18px; }
|
||||
.ui-dialog .ui-dialog-titlebar-close span { display: block; margin: 1px; }
|
||||
.ui-dialog .ui-dialog-titlebar-close:hover, .ui-dialog .ui-dialog-titlebar-close:focus { padding: 0; }
|
||||
.ui-dialog .ui-dialog-content { border: 0; padding: .5em 1em; background: none; overflow: auto; zoom: 1; }
|
||||
.ui-dialog .ui-dialog-buttonpane { text-align: left; border-width: 1px 0 0 0; background-image: none; margin: .5em 0 0 0; padding: .3em 1em .5em .4em; }
|
||||
.ui-dialog .ui-dialog-buttonpane button { float: right; margin: .5em .4em .5em 0; cursor: pointer; padding: .2em .6em .3em .6em; line-height: 1.4em; width:auto; overflow:visible; }
|
||||
.ui-dialog .ui-resizable-se { width: 14px; height: 14px; right: 3px; bottom: 3px; }
|
||||
.ui-draggable .ui-dialog-titlebar { cursor: move; }
|
||||
/* Progressbar
|
||||
----------------------------------*/
|
||||
.ui-progressbar { height:2em; text-align: left; }
|
||||
.ui-progressbar .ui-progressbar-value {margin: -1px; height:100%; }/* Resizable
|
||||
----------------------------------*/
|
||||
.ui-resizable { position: relative;}
|
||||
.ui-resizable-handle { position: absolute;font-size: 0.1px;z-index: 99999; display: block;}
|
||||
.ui-resizable-disabled .ui-resizable-handle, .ui-resizable-autohide .ui-resizable-handle { display: none; }
|
||||
.ui-resizable-n { cursor: n-resize; height: 7px; width: 100%; top: -5px; left: 0px; }
|
||||
.ui-resizable-s { cursor: s-resize; height: 7px; width: 100%; bottom: -5px; left: 0px; }
|
||||
.ui-resizable-e { cursor: e-resize; width: 7px; right: -5px; top: 0px; height: 100%; }
|
||||
.ui-resizable-w { cursor: w-resize; width: 7px; left: -5px; top: 0px; height: 100%; }
|
||||
.ui-resizable-se { cursor: se-resize; width: 12px; height: 12px; right: 1px; bottom: 1px; }
|
||||
.ui-resizable-sw { cursor: sw-resize; width: 9px; height: 9px; left: -5px; bottom: -5px; }
|
||||
.ui-resizable-nw { cursor: nw-resize; width: 9px; height: 9px; left: -5px; top: -5px; }
|
||||
.ui-resizable-ne { cursor: ne-resize; width: 9px; height: 9px; right: -5px; top: -5px;}/* Slider
|
||||
----------------------------------*/
|
||||
.ui-slider { position: relative; text-align: left; }
|
||||
.ui-slider .ui-slider-handle { position: absolute; z-index: 2; width: 1.2em; height: 1.2em; cursor: default; }
|
||||
.ui-slider .ui-slider-range { position: absolute; z-index: 1; font-size: .7em; display: block; border: 0; }
|
||||
|
||||
.ui-slider-horizontal { height: .8em; }
|
||||
.ui-slider-horizontal .ui-slider-handle { top: -.3em; margin-left: -.6em; }
|
||||
.ui-slider-horizontal .ui-slider-range { top: 0; height: 100%; }
|
||||
.ui-slider-horizontal .ui-slider-range-min { left: 0; }
|
||||
.ui-slider-horizontal .ui-slider-range-max { right: 0; }
|
||||
|
||||
.ui-slider-vertical { width: .8em; height: 100px; }
|
||||
.ui-slider-vertical .ui-slider-handle { left: -.3em; margin-left: 0; margin-bottom: -.6em; }
|
||||
.ui-slider-vertical .ui-slider-range { left: 0; width: 100%; }
|
||||
.ui-slider-vertical .ui-slider-range-min { bottom: 0; }
|
||||
.ui-slider-vertical .ui-slider-range-max { top: 0; }/* Tabs
|
||||
----------------------------------*/
|
||||
.ui-tabs { padding: .2em; zoom: 1; }
|
||||
.ui-tabs .ui-tabs-nav { list-style: none; position: relative; padding: .2em .2em 0; }
|
||||
.ui-tabs .ui-tabs-nav li { position: relative; float: left; border-bottom-width: 0 !important; margin: 0 .2em -1px 0; padding: 0; }
|
||||
.ui-tabs .ui-tabs-nav li a { float: left; text-decoration: none; padding: .5em 1em; }
|
||||
.ui-tabs .ui-tabs-nav li.ui-tabs-selected { padding-bottom: 1px; border-bottom-width: 0; }
|
||||
.ui-tabs .ui-tabs-nav li.ui-tabs-selected a, .ui-tabs .ui-tabs-nav li.ui-state-disabled a, .ui-tabs .ui-tabs-nav li.ui-state-processing a { cursor: text; }
|
||||
.ui-tabs .ui-tabs-nav li a, .ui-tabs.ui-tabs-collapsible .ui-tabs-nav li.ui-tabs-selected a { cursor: pointer; } /* first selector in group seems obsolete, but required to overcome bug in Opera applying cursor: text overall if defined elsewhere... */
|
||||
.ui-tabs .ui-tabs-panel { padding: 1em 1.4em; display: block; border-width: 0; background: none; }
|
||||
.ui-tabs .ui-tabs-hide { display: none !important; }
|
||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -21,28 +21,29 @@
|
||||
-->
|
||||
|
||||
<!DOCTYPE struts PUBLIC
|
||||
"-//Apache Software Foundation//DTD Struts Configuration 2.0//EN"
|
||||
"http://struts.apache.org/dtds/struts-2.0.dtd">
|
||||
"-//Apache Software Foundation//DTD Struts Configuration 2.5//EN"
|
||||
"http://struts.apache.org/dtds/struts-2.5.dtd">
|
||||
|
||||
<struts>
|
||||
<package name="bundle-admin" namespace="/osgi/admin" extends="struts-default">
|
||||
<constant name="struts.enable.DynamicMethodInvocation" value="false" />
|
||||
<package name="bundle-admin" namespace="/osgi/admin" extends="osgi-default" strict-method-invocation="true">
|
||||
<default-action-ref name="bundles" />
|
||||
|
||||
<action name="bundle_*!*" class="org.apache.struts2.osgi.admin.actions.BundlesAction" method="{2}">
|
||||
<param name="id">{1}</param>
|
||||
<result type="freemarker">viewBundle.ftl</result>
|
||||
<allowed-methods>index,view,start,stop,update</allowed-methods>
|
||||
</action>
|
||||
|
||||
<action name="bundles" class="org.apache.struts2.osgi.admin.actions.BundlesAction" method="index">
|
||||
<result type="freemarker">viewBundles.ftl</result>
|
||||
</action>
|
||||
|
||||
|
||||
<action name="execCommand" class="org.apache.struts2.osgi.admin.actions.ShellAction">
|
||||
<result type="freemarker">commandResult.ftl</result>
|
||||
</action>
|
||||
|
||||
<action name="shell">
|
||||
<action name="shell" class="org.apache.struts2.osgi.admin.actions.ShellAction">
|
||||
<result type="freemarker">shell.ftl</result>
|
||||
</action>
|
||||
</package>
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-osgi-bundles</artifactId>
|
||||
<version>2.5.16</version>
|
||||
<version>2.5.24</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-osgi-demo-bundle</artifactId>
|
||||
|
||||
+1
-1
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.5.16</version>
|
||||
<version>2.5.24</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-osgi-bundles</artifactId>
|
||||
|
||||
+3
-2
@@ -24,7 +24,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.5.16</version>
|
||||
<version>2.5.24</version>
|
||||
</parent>
|
||||
<artifactId>struts2-core</artifactId>
|
||||
<packaging>jar</packaging>
|
||||
@@ -190,7 +190,8 @@
|
||||
<dependency>
|
||||
<groupId>com.sun</groupId>
|
||||
<artifactId>tools</artifactId>
|
||||
<version>1.5.0</version>
|
||||
<version>1.7.0</version>
|
||||
<!-- Match version of minimum compatible version -->
|
||||
<scope>system</scope>
|
||||
<systemPath>${java.home}/../lib/tools.jar</systemPath>
|
||||
</dependency>
|
||||
|
||||
@@ -201,13 +201,10 @@ public class ActionChainResult implements Result {
|
||||
* @param invocation the DefaultActionInvocation calling the action call stack
|
||||
*/
|
||||
public void execute(ActionInvocation invocation) throws Exception {
|
||||
// if the finalNamespace wasn't explicitly defined, assume the current one
|
||||
if (this.namespace == null) {
|
||||
this.namespace = invocation.getProxy().getNamespace();
|
||||
}
|
||||
|
||||
ValueStack stack = ActionContext.getContext().getValueStack();
|
||||
String finalNamespace = TextParseUtil.translateVariables(namespace, stack);
|
||||
String finalNamespace = this.namespace != null
|
||||
? TextParseUtil.translateVariables(namespace, stack)
|
||||
: invocation.getProxy().getNamespace();
|
||||
String finalActionName = TextParseUtil.translateVariables(actionName, stack);
|
||||
String finalMethodName = this.methodName != null
|
||||
? TextParseUtil.translateVariables(this.methodName, stack)
|
||||
|
||||
@@ -27,6 +27,7 @@ import com.opensymphony.xwork2.test.StubConfigurationProvider;
|
||||
import com.opensymphony.xwork2.util.XWorkTestCaseHelper;
|
||||
import com.opensymphony.xwork2.util.location.LocatableProperties;
|
||||
import junit.framework.TestCase;
|
||||
import org.apache.commons.lang3.ClassUtils;
|
||||
|
||||
/**
|
||||
* Base JUnit TestCase to extend for XWork specific JUnit tests. Uses
|
||||
@@ -78,16 +79,20 @@ public abstract class XWorkTestCase extends TestCase {
|
||||
@Override
|
||||
public void register(ContainerBuilder builder,
|
||||
LocatableProperties props) throws ConfigurationException {
|
||||
builder.factory(type, name, new Factory() {
|
||||
public Object create(Context context) throws Exception {
|
||||
return impl;
|
||||
}
|
||||
if (impl instanceof String || ClassUtils.isPrimitiveOrWrapper(impl.getClass())) {
|
||||
props.setProperty(name, "" + impl);
|
||||
} else {
|
||||
builder.factory(type, name, new Factory() {
|
||||
public Object create(Context context) throws Exception {
|
||||
return impl;
|
||||
}
|
||||
|
||||
@Override
|
||||
public Class type() {
|
||||
return impl.getClass();
|
||||
}
|
||||
}, Scope.SINGLETON);
|
||||
@Override
|
||||
public Class type() {
|
||||
return impl.getClass();
|
||||
}
|
||||
}, Scope.SINGLETON);
|
||||
}
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
@@ -36,10 +36,8 @@ import java.util.*;
|
||||
* @since 2.1
|
||||
*/
|
||||
public abstract class AbstractMatcher<E> implements Serializable {
|
||||
/**
|
||||
* <p> The logging instance </p>
|
||||
*/
|
||||
private static final Logger log = LogManager.getLogger(AbstractMatcher.class);
|
||||
|
||||
private static final Logger LOG = LogManager.getLogger(AbstractMatcher.class);
|
||||
|
||||
/**
|
||||
* <p> Handles all wildcard pattern matching. </p>
|
||||
@@ -50,10 +48,34 @@ public abstract class AbstractMatcher<E> implements Serializable {
|
||||
* <p> The compiled patterns and their associated target objects </p>
|
||||
*/
|
||||
List<Mapping<E>> compiledPatterns = new ArrayList<>();
|
||||
;
|
||||
|
||||
/**
|
||||
* This flag controls if passed named params should be appended
|
||||
* to the map in {@link #replaceParameters(Map, Map)}
|
||||
* and will be accessible in {@link com.opensymphony.xwork2.config.entities.ResultConfig}.
|
||||
* If set to false, the named parameters won't be appended.
|
||||
*
|
||||
* This behaviour is controlled by {@link org.apache.struts2.StrutsConstants#STRUTS_MATCHER_APPEND_NAMED_PARAMETERS}
|
||||
*
|
||||
* @since 2.5.23
|
||||
* See WW-5065
|
||||
*/
|
||||
private final boolean appendNamedParameters;
|
||||
|
||||
public AbstractMatcher(PatternMatcher<?> helper) {
|
||||
public AbstractMatcher(PatternMatcher<?> helper, boolean appendNamedParameters) {
|
||||
this.wildcard = (PatternMatcher<Object>) helper;
|
||||
this.appendNamedParameters = appendNamedParameters;
|
||||
}
|
||||
|
||||
/**
|
||||
* Creates a matcher with {@link #appendNamedParameters} set to true to keep backward compatibility
|
||||
*
|
||||
* @param helper an instance of {@link PatternMatcher}
|
||||
* @deprecated use @{link {@link AbstractMatcher(PatternMatcher, boolean)} instead
|
||||
*/
|
||||
@Deprecated
|
||||
public AbstractMatcher(PatternMatcher<?> helper) {
|
||||
this(helper, true);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -84,17 +106,17 @@ public abstract class AbstractMatcher<E> implements Serializable {
|
||||
name = name.substring(1);
|
||||
}
|
||||
|
||||
log.debug("Compiling pattern '{}'", name);
|
||||
LOG.debug("Compiling pattern '{}'", name);
|
||||
|
||||
pattern = wildcard.compilePattern(name);
|
||||
compiledPatterns.add(new Mapping<E>(name, pattern, target));
|
||||
compiledPatterns.add(new Mapping<>(name, pattern, target));
|
||||
|
||||
if (looseMatch) {
|
||||
int lastStar = name.lastIndexOf('*');
|
||||
if (lastStar > 1 && lastStar == name.length() - 1) {
|
||||
if (name.charAt(lastStar - 1) != '*') {
|
||||
pattern = wildcard.compilePattern(name.substring(0, lastStar - 1));
|
||||
compiledPatterns.add(new Mapping<E>(name, pattern, target));
|
||||
compiledPatterns.add(new Mapping<>(name, pattern, target));
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -115,12 +137,12 @@ public abstract class AbstractMatcher<E> implements Serializable {
|
||||
E config = null;
|
||||
|
||||
if (compiledPatterns.size() > 0) {
|
||||
log.debug("Attempting to match '{}' to a wildcard pattern, {} available", potentialMatch, compiledPatterns.size());
|
||||
LOG.debug("Attempting to match '{}' to a wildcard pattern, {} available", potentialMatch, compiledPatterns.size());
|
||||
|
||||
Map<String,String> vars = new LinkedHashMap<String,String>();
|
||||
Map<String,String> vars = new LinkedHashMap<>();
|
||||
for (Mapping<E> m : compiledPatterns) {
|
||||
if (wildcard.match(vars, potentialMatch, m.getPattern())) {
|
||||
log.debug("Value matches pattern '{}'", m.getOriginalPattern());
|
||||
LOG.debug("Value matches pattern '{}'", m.getOriginalPattern());
|
||||
config = convert(potentialMatch, m.getTarget(), vars);
|
||||
break;
|
||||
}
|
||||
@@ -152,20 +174,23 @@ public abstract class AbstractMatcher<E> implements Serializable {
|
||||
*/
|
||||
protected Map<String,String> replaceParameters(Map<String, String> orig, Map<String,String> vars) {
|
||||
Map<String, String> map = new LinkedHashMap<>();
|
||||
|
||||
|
||||
//this will set the group index references, like {1}
|
||||
for (Map.Entry<String,String> entry : orig.entrySet()) {
|
||||
map.put(entry.getKey(), convertParam(entry.getValue(), vars));
|
||||
}
|
||||
|
||||
//the values map will contain entries like name->"Lex Luthor" and 1->"Lex Luthor"
|
||||
//now add the non-numeric values
|
||||
for (Map.Entry<String,String> entry: vars.entrySet()) {
|
||||
if (!NumberUtils.isCreatable(entry.getKey())) {
|
||||
map.put(entry.getKey(), entry.getValue());
|
||||
|
||||
if (appendNamedParameters) {
|
||||
LOG.debug("Appending named parameters to the result map");
|
||||
//the values map will contain entries like name->"Lex Luthor" and 1->"Lex Luthor"
|
||||
//now add the non-numeric values
|
||||
for (Map.Entry<String,String> entry: vars.entrySet()) {
|
||||
if (!NumberUtils.isCreatable(entry.getKey())) {
|
||||
map.put(entry.getKey(), entry.getValue());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
return map;
|
||||
}
|
||||
|
||||
@@ -192,7 +217,7 @@ public abstract class AbstractMatcher<E> implements Serializable {
|
||||
c = val.charAt(x);
|
||||
if (x < len - 2 &&
|
||||
c == '{' && '}' == val.charAt(x+2)) {
|
||||
varVal = (String)vars.get(String.valueOf(val.charAt(x + 1)));
|
||||
varVal = vars.get(String.valueOf(val.charAt(x + 1)));
|
||||
if (varVal != null) {
|
||||
ret.append(varVal);
|
||||
}
|
||||
@@ -213,18 +238,18 @@ public abstract class AbstractMatcher<E> implements Serializable {
|
||||
/**
|
||||
* <p> The original pattern. </p>
|
||||
*/
|
||||
private String original;
|
||||
private final String original;
|
||||
|
||||
|
||||
/**
|
||||
* <p> The compiled pattern. </p>
|
||||
*/
|
||||
private Object pattern;
|
||||
private final Object pattern;
|
||||
|
||||
/**
|
||||
* <p> The original object. </p>
|
||||
*/
|
||||
private E config;
|
||||
private final E config;
|
||||
|
||||
/**
|
||||
* <p> Contructs a read-only Mapping instance. </p>
|
||||
|
||||
@@ -58,7 +58,33 @@ public class ActionConfigMatcher extends AbstractMatcher<ActionConfig> implement
|
||||
public ActionConfigMatcher(PatternMatcher<?> patternMatcher,
|
||||
Map<String, ActionConfig> configs,
|
||||
boolean looseMatch) {
|
||||
super(patternMatcher);
|
||||
this(patternMatcher, configs, looseMatch, true);
|
||||
}
|
||||
|
||||
/**
|
||||
* <p> Finds and precompiles the wildcard patterns from the ActionConfig
|
||||
* "path" attributes. ActionConfig's will be evaluated in the order they
|
||||
* exist in the config file. Only paths that actually contain a
|
||||
* wildcard will be compiled. </p>
|
||||
*
|
||||
* <p>Patterns can optionally be matched "loosely". When
|
||||
* the end of the pattern matches \*[^*]\*$ (wildcard, no wildcard,
|
||||
* wildcard), if the pattern fails, it is also matched as if the
|
||||
* last two characters didn't exist. The goal is to support the
|
||||
* legacy "*!*" syntax, where the "!*" is optional.</p>
|
||||
*
|
||||
* @param patternMatcher pattern matcher
|
||||
* @param configs An array of ActionConfig's to process
|
||||
* @param looseMatch To loosely match wildcards or not
|
||||
* @param appendNamedParameters To append named parameters or not
|
||||
*
|
||||
* @since 2.5.23
|
||||
* See WW-5065
|
||||
*/
|
||||
public ActionConfigMatcher(PatternMatcher<?> patternMatcher,
|
||||
Map<String, ActionConfig> configs,
|
||||
boolean looseMatch, boolean appendNamedParameters) {
|
||||
super(patternMatcher, appendNamedParameters);
|
||||
for (Map.Entry<String, ActionConfig> entry : configs.entrySet()) {
|
||||
addPattern(entry.getKey(), entry.getValue(), looseMatch);
|
||||
}
|
||||
|
||||
@@ -289,6 +289,8 @@ public class DefaultConfiguration implements Configuration {
|
||||
builder.constant(XWorkConstants.RELOAD_XML_CONFIGURATION, "false");
|
||||
builder.constant(StrutsConstants.STRUTS_I18N_RELOAD, "false");
|
||||
|
||||
builder.constant(StrutsConstants.STRUTS_MATCHER_APPEND_NAMED_PARAMETERS, "true");
|
||||
|
||||
return builder.create(true);
|
||||
}
|
||||
|
||||
@@ -338,8 +340,12 @@ public class DefaultConfiguration implements Configuration {
|
||||
}
|
||||
|
||||
PatternMatcher<int[]> matcher = container.getInstance(PatternMatcher.class);
|
||||
boolean appendNamedParameters = Boolean.parseBoolean(
|
||||
container.getInstance(String.class, StrutsConstants.STRUTS_MATCHER_APPEND_NAMED_PARAMETERS)
|
||||
);
|
||||
|
||||
return new RuntimeConfigurationImpl(Collections.unmodifiableMap(namespaceActionConfigs),
|
||||
Collections.unmodifiableMap(namespaceConfigs), matcher);
|
||||
Collections.unmodifiableMap(namespaceConfigs), matcher, appendNamedParameters);
|
||||
}
|
||||
|
||||
private void setDefaultResults(Map<String, ResultConfig> results, PackageConfig packageContext) {
|
||||
@@ -417,15 +423,18 @@ public class DefaultConfiguration implements Configuration {
|
||||
|
||||
public RuntimeConfigurationImpl(Map<String, Map<String, ActionConfig>> namespaceActionConfigs,
|
||||
Map<String, String> namespaceConfigs,
|
||||
PatternMatcher<int[]> matcher) {
|
||||
PatternMatcher<int[]> matcher,
|
||||
boolean appendNamedParameters)
|
||||
{
|
||||
this.namespaceActionConfigs = namespaceActionConfigs;
|
||||
this.namespaceConfigs = namespaceConfigs;
|
||||
|
||||
this.namespaceActionConfigMatchers = new LinkedHashMap<>();
|
||||
this.namespaceMatcher = new NamespaceMatcher(matcher, namespaceActionConfigs.keySet());
|
||||
this.namespaceMatcher = new NamespaceMatcher(matcher, namespaceActionConfigs.keySet(), appendNamedParameters);
|
||||
|
||||
for (Map.Entry<String, Map<String, ActionConfig>> entry : namespaceActionConfigs.entrySet()) {
|
||||
namespaceActionConfigMatchers.put(entry.getKey(), new ActionConfigMatcher(matcher, entry.getValue(), true));
|
||||
ActionConfigMatcher configMatcher = new ActionConfigMatcher(matcher, entry.getValue(), true, appendNamedParameters);
|
||||
namespaceActionConfigMatchers.put(entry.getKey(), configMatcher);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -29,9 +29,23 @@ import java.util.Set;
|
||||
* @since 2.1
|
||||
*/
|
||||
public class NamespaceMatcher extends AbstractMatcher<NamespaceMatch> {
|
||||
public NamespaceMatcher(PatternMatcher<?> patternMatcher,
|
||||
Set<String> namespaces) {
|
||||
super(patternMatcher);
|
||||
|
||||
public NamespaceMatcher(PatternMatcher<?> patternMatcher, Set<String> namespaces) {
|
||||
this(patternMatcher, namespaces, true);
|
||||
}
|
||||
|
||||
/**
|
||||
* Matches namespace strings against a wildcard pattern matcher
|
||||
*
|
||||
* @param patternMatcher pattern matcher
|
||||
* @param namespaces A set of namespaces to process
|
||||
* @param appendNamedParameters To append named parameters or not
|
||||
*
|
||||
* @since 2.5.23
|
||||
* See WW-5065
|
||||
*/
|
||||
public NamespaceMatcher(PatternMatcher<?> patternMatcher, Set<String> namespaces, boolean appendNamedParameters) {
|
||||
super(patternMatcher, appendNamedParameters);
|
||||
for (String name : namespaces) {
|
||||
if (!patternMatcher.isLiteral(name)) {
|
||||
addPattern(name, new NamespaceMatch(name, null), false);
|
||||
|
||||
+3
@@ -108,6 +108,7 @@ import com.opensymphony.xwork2.validator.DefaultValidatorFactory;
|
||||
import com.opensymphony.xwork2.validator.DefaultValidatorFileParser;
|
||||
import com.opensymphony.xwork2.validator.ValidatorFactory;
|
||||
import com.opensymphony.xwork2.validator.ValidatorFileParser;
|
||||
import com.sun.org.apache.xpath.internal.operations.Bool;
|
||||
import ognl.MethodAccessor;
|
||||
import ognl.PropertyAccessor;
|
||||
import org.apache.struts2.StrutsConstants;
|
||||
@@ -226,6 +227,8 @@ public class XWorkConfigurationProvider implements ConfigurationProvider {
|
||||
props.setProperty(XWorkConstants.ENABLE_OGNL_EXPRESSION_CACHE, Boolean.TRUE.toString());
|
||||
props.setProperty(XWorkConstants.ENABLE_OGNL_EVAL_EXPRESSION, Boolean.FALSE.toString());
|
||||
props.setProperty(XWorkConstants.RELOAD_XML_CONFIGURATION, Boolean.FALSE.toString());
|
||||
props.setProperty(StrutsConstants.STRUTS_ALLOW_STATIC_METHOD_ACCESS, Boolean.FALSE.toString());
|
||||
props.setProperty(StrutsConstants.STRUTS_MATCHER_APPEND_NAMED_PARAMETERS, Boolean.TRUE.toString());
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
+35
-14
@@ -93,12 +93,12 @@ public class XmlConfigurationProvider implements ConfigurationProvider {
|
||||
private String configFileName;
|
||||
private ObjectFactory objectFactory;
|
||||
|
||||
private Set<String> loadedFileUrls = new HashSet<>();
|
||||
private final Set<String> loadedFileUrls = new HashSet<>();
|
||||
private boolean errorIfMissing;
|
||||
private Map<String, String> dtdMappings;
|
||||
private Configuration configuration;
|
||||
private boolean throwExceptionOnDuplicateBeans = true;
|
||||
private Map<String, Element> declaredPackages = new HashMap<>();
|
||||
private final Map<String, Element> declaredPackages = new HashMap<>();
|
||||
|
||||
private FileManager fileManager;
|
||||
private ValueSubstitutor valueSubstitutor;
|
||||
@@ -874,15 +874,24 @@ public class XmlConfigurationProvider implements ConfigurationProvider {
|
||||
if (allowedMethodsEls.getLength() > 0) {
|
||||
// user defined 'allowed-methods' so used them whatever Strict DMI was enabled or not
|
||||
allowedMethods = new HashSet<>(packageContext.getGlobalAllowedMethods());
|
||||
|
||||
if (allowedMethodsEls.getLength() > 0) {
|
||||
Node n = allowedMethodsEls.item(0).getFirstChild();
|
||||
if (n != null) {
|
||||
String s = n.getNodeValue().trim();
|
||||
if (s.length() > 0) {
|
||||
allowedMethods.addAll(TextParseUtil.commaDelimitedStringToSet(s));
|
||||
// Fix for WW-5029 (concatenate all possible text node children)
|
||||
final Node allowedMethodsNode = allowedMethodsEls.item(0);
|
||||
if (allowedMethodsNode != null) {
|
||||
final NodeList allowedMethodsChildren = allowedMethodsNode.getChildNodes();
|
||||
final StringBuilder allowedMethodsSB = new StringBuilder();
|
||||
for (int i = 0; i < allowedMethodsChildren.getLength(); i++) {
|
||||
Node allowedMethodsChildNode = allowedMethodsChildren.item(i);
|
||||
if (allowedMethodsChildNode != null && allowedMethodsChildNode.getNodeType() == Node.TEXT_NODE) {
|
||||
String childNodeValue = allowedMethodsChildNode.getNodeValue();
|
||||
childNodeValue = (childNodeValue != null ? childNodeValue.trim() : "");
|
||||
if (childNodeValue.length() > 0) {
|
||||
allowedMethodsSB.append(childNodeValue);
|
||||
}
|
||||
}
|
||||
}
|
||||
if (allowedMethodsSB.length() > 0) {
|
||||
allowedMethods.addAll(TextParseUtil.commaDelimitedStringToSet(allowedMethodsSB.toString()));
|
||||
}
|
||||
}
|
||||
} else if (packageContext.isStrictMethodInvocation()) {
|
||||
// user enabled Strict DMI but didn't defined action specific 'allowed-methods' so we use 'global-allowed-methods' only
|
||||
@@ -937,11 +946,23 @@ public class XmlConfigurationProvider implements ConfigurationProvider {
|
||||
|
||||
if (globalAllowedMethodsElms.getLength() > 0) {
|
||||
Set<String> globalAllowedMethods = new HashSet<>();
|
||||
Node n = globalAllowedMethodsElms.item(0).getFirstChild();
|
||||
if (n != null) {
|
||||
String s = n.getNodeValue().trim();
|
||||
if (s.length() > 0) {
|
||||
globalAllowedMethods = TextParseUtil.commaDelimitedStringToSet(s);
|
||||
// Fix for WW-5029 (concatenate all possible text node children)
|
||||
Node globaAllowedMethodsNode = globalAllowedMethodsElms.item(0);
|
||||
if (globaAllowedMethodsNode != null) {
|
||||
NodeList globaAllowedMethodsChildren = globaAllowedMethodsNode.getChildNodes();
|
||||
final StringBuilder globalAllowedMethodsSB = new StringBuilder();
|
||||
for (int i = 0; i < globaAllowedMethodsChildren.getLength(); i++) {
|
||||
Node globalAllowedMethodsChildNode = globaAllowedMethodsChildren.item(i);
|
||||
if (globalAllowedMethodsChildNode != null && globalAllowedMethodsChildNode.getNodeType() == Node.TEXT_NODE) {
|
||||
String childNodeValue = globalAllowedMethodsChildNode.getNodeValue();
|
||||
childNodeValue = (childNodeValue != null ? childNodeValue.trim() : "");
|
||||
if (childNodeValue.length() > 0) {
|
||||
globalAllowedMethodsSB.append(childNodeValue);
|
||||
}
|
||||
}
|
||||
}
|
||||
if (globalAllowedMethodsSB.length() > 0) {
|
||||
globalAllowedMethods.addAll(TextParseUtil.commaDelimitedStringToSet(globalAllowedMethodsSB.toString()));
|
||||
}
|
||||
}
|
||||
packageContext.addGlobalAllowedMethods(globalAllowedMethods);
|
||||
|
||||
@@ -21,7 +21,6 @@ package com.opensymphony.xwork2.conversion.impl;
|
||||
import com.opensymphony.xwork2.conversion.ObjectTypeDeterminer;
|
||||
import com.opensymphony.xwork2.conversion.TypeConverter;
|
||||
import com.opensymphony.xwork2.inject.Inject;
|
||||
import com.opensymphony.xwork2.util.XWorkList;
|
||||
|
||||
import java.lang.reflect.Member;
|
||||
import java.util.Collection;
|
||||
|
||||
+1
-2
@@ -16,13 +16,12 @@
|
||||
* specific language governing permissions and limitations
|
||||
* under the License.
|
||||
*/
|
||||
package com.opensymphony.xwork2.util;
|
||||
package com.opensymphony.xwork2.conversion.impl;
|
||||
|
||||
import com.opensymphony.xwork2.ActionContext;
|
||||
import com.opensymphony.xwork2.ObjectFactory;
|
||||
import com.opensymphony.xwork2.XWorkException;
|
||||
import com.opensymphony.xwork2.conversion.TypeConverter;
|
||||
import com.opensymphony.xwork2.conversion.impl.XWorkConverter;
|
||||
import org.apache.logging.log4j.LogManager;
|
||||
import org.apache.logging.log4j.Logger;
|
||||
|
||||
@@ -164,7 +164,8 @@ class ContainerImpl implements Container {
|
||||
public FieldInjector(ContainerImpl container, Field field, String name)
|
||||
throws MissingDependencyException {
|
||||
this.field = field;
|
||||
if (!field.isAccessible()) {
|
||||
if ((!Modifier.isPublic(field.getModifiers()) || !Modifier.isPublic(field.getDeclaringClass().getModifiers()))
|
||||
&& !field.isAccessible()) {
|
||||
SecurityManager sm = System.getSecurityManager();
|
||||
try {
|
||||
if (sm != null) {
|
||||
@@ -256,7 +257,8 @@ class ContainerImpl implements Container {
|
||||
|
||||
public MethodInjector(ContainerImpl container, Method method, String name) throws MissingDependencyException {
|
||||
this.method = method;
|
||||
if (!method.isAccessible()) {
|
||||
if ((!Modifier.isPublic(method.getModifiers()) || !Modifier.isPublic(method.getDeclaringClass().getModifiers()))
|
||||
&& !method.isAccessible()) {
|
||||
SecurityManager sm = System.getSecurityManager();
|
||||
try {
|
||||
if (sm != null) {
|
||||
@@ -306,7 +308,8 @@ class ContainerImpl implements Container {
|
||||
this.implementation = implementation;
|
||||
|
||||
constructor = findConstructorIn(implementation);
|
||||
if (!constructor.isAccessible()) {
|
||||
if ((!Modifier.isPublic(constructor.getModifiers()) || !Modifier.isPublic(constructor.getDeclaringClass().getModifiers()))
|
||||
&& !constructor.isAccessible()) {
|
||||
SecurityManager sm = System.getSecurityManager();
|
||||
try {
|
||||
if (sm != null) {
|
||||
|
||||
@@ -25,13 +25,16 @@ import com.opensymphony.xwork2.XWorkConstants;
|
||||
import com.opensymphony.xwork2.inject.Inject;
|
||||
import com.opensymphony.xwork2.security.AcceptedPatternsChecker;
|
||||
import com.opensymphony.xwork2.security.ExcludedPatternsChecker;
|
||||
import com.opensymphony.xwork2.util.*;
|
||||
import com.opensymphony.xwork2.util.ClearableValueStack;
|
||||
import com.opensymphony.xwork2.util.MemberAccessValueStack;
|
||||
import com.opensymphony.xwork2.util.ValueStack;
|
||||
import com.opensymphony.xwork2.util.ValueStackFactory;
|
||||
import com.opensymphony.xwork2.util.reflection.ReflectionContextState;
|
||||
import org.apache.commons.lang3.BooleanUtils;
|
||||
import org.apache.logging.log4j.LogManager;
|
||||
import org.apache.logging.log4j.Logger;
|
||||
import org.apache.struts2.dispatcher.Parameter;
|
||||
import org.apache.struts2.dispatcher.HttpParameters;
|
||||
import org.apache.struts2.dispatcher.Parameter;
|
||||
|
||||
import java.util.Collection;
|
||||
import java.util.Comparator;
|
||||
@@ -100,8 +103,8 @@ public class ParametersInterceptor extends MethodFilterInterceptor {
|
||||
*/
|
||||
static final Comparator<String> rbCollator = new Comparator<String>() {
|
||||
public int compare(String s1, String s2) {
|
||||
int l1 = countOGNLCharacters(s1),
|
||||
l2 = countOGNLCharacters(s2);
|
||||
int l1 = countOGNLCharacters(s1);
|
||||
int l2 = countOGNLCharacters(s2);
|
||||
return l1 < l2 ? -1 : (l2 < l1 ? 1 : s1.compareTo(s2));
|
||||
}
|
||||
|
||||
@@ -185,7 +188,7 @@ public class ParametersInterceptor extends MethodFilterInterceptor {
|
||||
if (clearableStack) {
|
||||
//if the stack's context can be cleared, do that to prevent OGNL
|
||||
//from having access to objects in the stack, see XW-641
|
||||
((ClearableValueStack)newStack).clearContextValues();
|
||||
((ClearableValueStack) newStack).clearContextValues();
|
||||
Map<String, Object> context = newStack.getContext();
|
||||
ReflectionContextState.setCreatingNullObjects(context, true);
|
||||
ReflectionContextState.setDenyMethodExecution(context, true);
|
||||
@@ -228,7 +231,7 @@ public class ParametersInterceptor extends MethodFilterInterceptor {
|
||||
TextProvider tp = (TextProvider) action;
|
||||
developerNotification = tp.getText("devmode.notification",
|
||||
"Developer Notification:\n{0}",
|
||||
new String[]{ developerNotification }
|
||||
new String[]{developerNotification}
|
||||
);
|
||||
}
|
||||
|
||||
@@ -245,7 +248,7 @@ public class ParametersInterceptor extends MethodFilterInterceptor {
|
||||
/**
|
||||
* Checks if name of parameter can be accepted or thrown away
|
||||
*
|
||||
* @param name parameter name
|
||||
* @param name parameter name
|
||||
* @param action current action
|
||||
* @return true if parameter is accepted
|
||||
*/
|
||||
@@ -289,27 +292,45 @@ public class ParametersInterceptor extends MethodFilterInterceptor {
|
||||
return accepted;
|
||||
}
|
||||
|
||||
protected boolean isWithinLengthLimit( String name ) {
|
||||
protected boolean isWithinLengthLimit(String name) {
|
||||
boolean matchLength = name.length() <= paramNameMaxLength;
|
||||
if (!matchLength) {
|
||||
LOG.debug("Parameter [{}] is too long, allowed length is [{}]", name, String.valueOf(paramNameMaxLength));
|
||||
if (devMode) { // warn only when in devMode
|
||||
LOG.warn("Parameter [{}] is too long, allowed length is [{}]. Use Interceptor Parameter Overriding " +
|
||||
"to override the limit, see more at\n" +
|
||||
"https://struts.apache.org/core-developers/interceptors.html#interceptor-parameter-overriding",
|
||||
name, paramNameMaxLength);
|
||||
} else {
|
||||
LOG.warn("Parameter [{}] is too long, allowed length is [{}]", name, paramNameMaxLength);
|
||||
}
|
||||
}
|
||||
return matchLength;
|
||||
}
|
||||
}
|
||||
|
||||
protected boolean isAccepted(String paramName) {
|
||||
AcceptedPatternsChecker.IsAccepted result = acceptedPatterns.isAccepted(paramName);
|
||||
if (result.isAccepted()) {
|
||||
return true;
|
||||
} else if (devMode) { // warn only when in devMode
|
||||
LOG.warn("Parameter [{}] didn't match accepted pattern [{}]! See Accepted / Excluded patterns at\n" +
|
||||
"https://struts.apache.org/security/#accepted--excluded-patterns",
|
||||
paramName, result.getAcceptedPattern());
|
||||
} else {
|
||||
LOG.debug("Parameter [{}] didn't match accepted pattern [{}]!", paramName, result.getAcceptedPattern());
|
||||
}
|
||||
LOG.debug("Parameter [{}] didn't match accepted pattern [{}]!", paramName, result.getAcceptedPattern());
|
||||
return false;
|
||||
}
|
||||
|
||||
protected boolean isExcluded(String paramName) {
|
||||
ExcludedPatternsChecker.IsExcluded result = excludedPatterns.isExcluded(paramName);
|
||||
if (result.isExcluded()) {
|
||||
LOG.debug("Parameter [{}] matches excluded pattern [{}]!", paramName, result.getExcludedPattern());
|
||||
if (devMode) { // warn only when in devMode
|
||||
LOG.warn("Parameter [{}] matches excluded pattern [{}]! See Accepted / Excluded patterns at\n" +
|
||||
"https://struts.apache.org/security/#accepted--excluded-patterns",
|
||||
paramName, result.getExcludedPattern());
|
||||
} else {
|
||||
LOG.debug("Parameter [{}] matches excluded pattern [{}]!", paramName, result.getExcludedPattern());
|
||||
}
|
||||
return true;
|
||||
}
|
||||
return false;
|
||||
|
||||
@@ -23,7 +23,7 @@ package com.opensymphony.xwork2.ognl;
|
||||
*/
|
||||
public class ErrorMessageBuilder {
|
||||
|
||||
private StringBuilder message = new StringBuilder();
|
||||
private final StringBuilder message = new StringBuilder();
|
||||
|
||||
public static ErrorMessageBuilder create() {
|
||||
return new ErrorMessageBuilder();
|
||||
|
||||
@@ -24,7 +24,7 @@ import java.util.Map;
|
||||
|
||||
public class OgnlNullHandlerWrapper implements ognl.NullHandler {
|
||||
|
||||
private NullHandler wrapped;
|
||||
private final NullHandler wrapped;
|
||||
|
||||
public OgnlNullHandlerWrapper(NullHandler target) {
|
||||
this.wrapped = target;
|
||||
|
||||
@@ -28,7 +28,7 @@ import java.util.Map;
|
||||
*/
|
||||
public class OgnlTypeConverterWrapper implements ognl.TypeConverter {
|
||||
|
||||
private TypeConverter typeConverter;
|
||||
private final TypeConverter typeConverter;
|
||||
|
||||
public OgnlTypeConverterWrapper(TypeConverter converter) {
|
||||
if (converter == null) {
|
||||
|
||||
@@ -54,48 +54,64 @@ public class OgnlUtil {
|
||||
|
||||
private static final Logger LOG = LogManager.getLogger(OgnlUtil.class);
|
||||
|
||||
private ConcurrentMap<String, Object> expressions = new ConcurrentHashMap<>();
|
||||
private final ConcurrentMap<String, Object> expressions = new ConcurrentHashMap<>();
|
||||
private final ConcurrentMap<Class, BeanInfo> beanInfoCache = new ConcurrentHashMap<>();
|
||||
private TypeConverter defaultConverter;
|
||||
|
||||
private boolean devMode = false;
|
||||
private boolean devMode;
|
||||
private boolean enableExpressionCache = true;
|
||||
private boolean enableEvalExpression;
|
||||
|
||||
private Set<Class<?>> excludedClasses = Collections.emptySet();
|
||||
private Set<Pattern> excludedPackageNamePatterns = Collections.emptySet();
|
||||
private Set<String> excludedPackageNames = Collections.emptySet();
|
||||
private Set<Class<?>> excludedClasses;
|
||||
private Set<Pattern> excludedPackageNamePatterns;
|
||||
private Set<String> excludedPackageNames;
|
||||
|
||||
private Container container;
|
||||
private boolean allowStaticMethodAccess;
|
||||
private boolean disallowProxyMemberAccess;
|
||||
|
||||
public OgnlUtil() {
|
||||
excludedClasses = new HashSet<>();
|
||||
excludedPackageNamePatterns = new HashSet<>();
|
||||
excludedPackageNames = new HashSet<>();
|
||||
excludedClasses = Collections.unmodifiableSet(excludedClasses);
|
||||
excludedPackageNamePatterns = Collections.unmodifiableSet(excludedPackageNamePatterns);
|
||||
excludedPackageNames = Collections.unmodifiableSet(excludedPackageNames);
|
||||
}
|
||||
|
||||
@Inject
|
||||
public void setXWorkConverter(XWorkConverter conv) {
|
||||
protected void setXWorkConverter(XWorkConverter conv) {
|
||||
this.defaultConverter = new OgnlTypeConverterWrapper(conv);
|
||||
}
|
||||
|
||||
@Inject(XWorkConstants.DEV_MODE)
|
||||
public void setDevMode(String mode) {
|
||||
protected void setDevMode(String mode) {
|
||||
this.devMode = BooleanUtils.toBoolean(mode);
|
||||
}
|
||||
|
||||
@Inject(XWorkConstants.ENABLE_OGNL_EXPRESSION_CACHE)
|
||||
public void setEnableExpressionCache(String cache) {
|
||||
protected void setEnableExpressionCache(String cache) {
|
||||
enableExpressionCache = BooleanUtils.toBoolean(cache);
|
||||
}
|
||||
|
||||
@Inject(value = XWorkConstants.ENABLE_OGNL_EVAL_EXPRESSION, required = false)
|
||||
public void setEnableEvalExpression(String evalExpression) {
|
||||
enableEvalExpression = "true".equals(evalExpression);
|
||||
if(enableEvalExpression){
|
||||
protected void setEnableEvalExpression(String evalExpression) {
|
||||
this.enableEvalExpression = BooleanUtils.toBoolean(evalExpression);
|
||||
if (this.enableEvalExpression) {
|
||||
LOG.warn("Enabling OGNL expression evaluation may introduce security risks " +
|
||||
"(see http://struts.apache.org/release/2.3.x/docs/s2-013.html for further details)");
|
||||
}
|
||||
}
|
||||
|
||||
@Inject(value = XWorkConstants.OGNL_EXCLUDED_CLASSES, required = false)
|
||||
public void setExcludedClasses(String commaDelimitedClasses) {
|
||||
protected void setExcludedClasses(String commaDelimitedClasses) {
|
||||
Set<Class<?>> excludedClasses = new HashSet<>();
|
||||
excludedClasses.addAll(this.excludedClasses);
|
||||
excludedClasses.addAll(parseExcludedClasses(commaDelimitedClasses));
|
||||
this.excludedClasses = Collections.unmodifiableSet(excludedClasses);
|
||||
}
|
||||
|
||||
private Set<Class<?>> parseExcludedClasses(String commaDelimitedClasses) {
|
||||
Set<String> classNames = TextParseUtil.commaDelimitedStringToSet(commaDelimitedClasses);
|
||||
Set<Class<?>> classes = new HashSet<>();
|
||||
|
||||
@@ -107,11 +123,18 @@ public class OgnlUtil {
|
||||
}
|
||||
}
|
||||
|
||||
excludedClasses = Collections.unmodifiableSet(classes);
|
||||
return classes;
|
||||
}
|
||||
|
||||
@Inject(value = XWorkConstants.OGNL_EXCLUDED_PACKAGE_NAME_PATTERNS, required = false)
|
||||
public void setExcludedPackageNamePatterns(String commaDelimitedPackagePatterns) {
|
||||
protected void setExcludedPackageNamePatterns(String commaDelimitedPackagePatterns) {
|
||||
Set<Pattern> excludedPackageNamePatterns = new HashSet<>();
|
||||
excludedPackageNamePatterns.addAll(this.excludedPackageNamePatterns);
|
||||
excludedPackageNamePatterns.addAll(parseExcludedPackageNamePatterns(commaDelimitedPackagePatterns));
|
||||
this.excludedPackageNamePatterns = Collections.unmodifiableSet(excludedPackageNamePatterns);
|
||||
}
|
||||
|
||||
private Set<Pattern> parseExcludedPackageNamePatterns(String commaDelimitedPackagePatterns) {
|
||||
Set<String> packagePatterns = TextParseUtil.commaDelimitedStringToSet(commaDelimitedPackagePatterns);
|
||||
Set<Pattern> packageNamePatterns = new HashSet<>();
|
||||
|
||||
@@ -119,12 +142,19 @@ public class OgnlUtil {
|
||||
packageNamePatterns.add(Pattern.compile(pattern));
|
||||
}
|
||||
|
||||
excludedPackageNamePatterns = Collections.unmodifiableSet(packageNamePatterns);
|
||||
return packageNamePatterns;
|
||||
}
|
||||
|
||||
@Inject(value = XWorkConstants.OGNL_EXCLUDED_PACKAGE_NAMES, required = false)
|
||||
public void setExcludedPackageNames(String commaDelimitedPackageNames) {
|
||||
excludedPackageNames = Collections.unmodifiableSet(TextParseUtil.commaDelimitedStringToSet(commaDelimitedPackageNames));
|
||||
protected void setExcludedPackageNames(String commaDelimitedPackageNames) {
|
||||
Set<String> excludedPackageNames = new HashSet<>();
|
||||
excludedPackageNames.addAll(this.excludedPackageNames);
|
||||
excludedPackageNames.addAll(parseExcludedPackageNames(commaDelimitedPackageNames));
|
||||
this.excludedPackageNames = Collections.unmodifiableSet(excludedPackageNames);
|
||||
}
|
||||
|
||||
private Set<String> parseExcludedPackageNames(String commaDelimitedPackageNames) {
|
||||
return TextParseUtil.commaDelimitedStringToSet(commaDelimitedPackageNames);
|
||||
}
|
||||
|
||||
public Set<Class<?>> getExcludedClasses() {
|
||||
@@ -140,24 +170,112 @@ public class OgnlUtil {
|
||||
}
|
||||
|
||||
@Inject
|
||||
public void setContainer(Container container) {
|
||||
protected void setContainer(Container container) {
|
||||
this.container = container;
|
||||
}
|
||||
|
||||
@Inject(value = XWorkConstants.ALLOW_STATIC_METHOD_ACCESS, required = false)
|
||||
public void setAllowStaticMethodAccess(String allowStaticMethodAccess) {
|
||||
this.allowStaticMethodAccess = Boolean.parseBoolean(allowStaticMethodAccess);
|
||||
protected void setAllowStaticMethodAccess(String allowStaticMethodAccess) {
|
||||
this.allowStaticMethodAccess = BooleanUtils.toBoolean(allowStaticMethodAccess);
|
||||
}
|
||||
|
||||
@Inject(value = StrutsConstants.STRUTS_DISALLOW_PROXY_MEMBER_ACCESS, required = false)
|
||||
public void setDisallowProxyMemberAccess(String disallowProxyMemberAccess) {
|
||||
protected void setDisallowProxyMemberAccess(String disallowProxyMemberAccess) {
|
||||
this.disallowProxyMemberAccess = Boolean.parseBoolean(disallowProxyMemberAccess);
|
||||
}
|
||||
|
||||
/**
|
||||
* @param maxLength Injects the Struts OGNL maximum expression length.
|
||||
*/
|
||||
@Inject(value = StrutsConstants.STRUTS_OGNL_EXPRESSION_MAX_LENGTH, required = false)
|
||||
protected void applyExpressionMaxLength(String maxLength) {
|
||||
try {
|
||||
if (maxLength == null || maxLength.isEmpty()) {
|
||||
// user is going to disable this functionality
|
||||
Ognl.applyExpressionMaxLength(null);
|
||||
} else {
|
||||
Ognl.applyExpressionMaxLength(Integer.parseInt(maxLength));
|
||||
}
|
||||
} catch (Exception ex) {
|
||||
LOG.error("Unable to set OGNL Expression Max Length {}.", maxLength); // Help configuration debugging.
|
||||
throw ex;
|
||||
}
|
||||
}
|
||||
|
||||
public boolean isDisallowProxyMemberAccess() {
|
||||
return disallowProxyMemberAccess;
|
||||
}
|
||||
|
||||
/**
|
||||
* Convenience mechanism to clear the OGNL Runtime Cache via OgnlUtil. May be utilized
|
||||
* by applications that generate many unique OGNL expressions over time.
|
||||
*
|
||||
* Note: This call affects the global OGNL cache, see ({@link ognl.OgnlRuntime#clearCache()} for details.
|
||||
*
|
||||
* Warning: Frequent calling if this method may negatively impact performance, but may be required
|
||||
* to avoid memory exhaustion (resource leak) with too many OGNL expressions being cached.
|
||||
*
|
||||
* @since 2.5.21
|
||||
*/
|
||||
public static void clearRuntimeCache() {
|
||||
OgnlRuntime.clearCache();
|
||||
}
|
||||
|
||||
/**
|
||||
* Provide a mechanism to clear the OGNL expression cache. May be utilized by applications
|
||||
* that generate many unique OGNL expressions over time.
|
||||
*
|
||||
* Note: This call affects the current OgnlUtil instance. For Struts this is often a Singleton
|
||||
* instance so it can be "effectively global".
|
||||
*
|
||||
* Warning: Frequent calling if this method may negatively impact performance, but may be required
|
||||
* to avoid memory exhaustion (resource leak) with too many OGNL expressions being cached.
|
||||
*
|
||||
* @since 2.5.21
|
||||
*/
|
||||
public void clearExpressionCache() {
|
||||
expressions.clear();
|
||||
}
|
||||
|
||||
/**
|
||||
* Check the size of the expression cache (current number of elements).
|
||||
*
|
||||
* @return current number of elements in the expression cache.
|
||||
*
|
||||
* @since 2.5.21
|
||||
*/
|
||||
public int expressionCacheSize() {
|
||||
return expressions.size();
|
||||
}
|
||||
|
||||
/**
|
||||
* Provide a mechanism to clear the BeanInfo cache. May be utilized by applications
|
||||
* that request BeanInfo and/or PropertyDescriptors for many unique classes or objects over time
|
||||
* (especially dynamic objects).
|
||||
*
|
||||
* Note: This call affects the current OgnlUtil instance. For Struts this is often a Singleton
|
||||
* instance so it can be "effectively global".
|
||||
*
|
||||
* Warning: Frequent calling if this method may negatively impact performance, but may be required
|
||||
* to avoid memory exhaustion (resource leak) with too many BeanInfo elements being cached.
|
||||
*
|
||||
* @since 2.5.21
|
||||
*/
|
||||
public void clearBeanInfoCache() {
|
||||
beanInfoCache.clear();
|
||||
}
|
||||
|
||||
/**
|
||||
* Check the size of the BeanInfo cache (current number of elements).
|
||||
*
|
||||
* @return current number of elements in the BeanInfo cache.
|
||||
*
|
||||
* @since 2.5.21
|
||||
*/
|
||||
public int beanInfoCacheSize() {
|
||||
return beanInfoCache.size();
|
||||
}
|
||||
|
||||
/**
|
||||
* Sets the object's properties using the default type converter, defaulting to not throw
|
||||
* exceptions for problems setting the properties.
|
||||
@@ -404,7 +522,7 @@ public class OgnlUtil {
|
||||
|
||||
final T exec = task.execute(tree);
|
||||
// if cache is enabled and it's a valid expression, puts it in
|
||||
if(enableExpressionCache) {
|
||||
if (enableExpressionCache) {
|
||||
expressions.putIfAbsent(expression, tree);
|
||||
}
|
||||
return exec;
|
||||
@@ -425,7 +543,7 @@ public class OgnlUtil {
|
||||
|
||||
final T exec = task.execute(tree);
|
||||
// if cache is enabled and it's a valid expression, puts it in
|
||||
if(enableExpressionCache) {
|
||||
if (enableExpressionCache) {
|
||||
expressions.putIfAbsent(expression, tree);
|
||||
}
|
||||
return exec;
|
||||
@@ -641,8 +759,7 @@ public class OgnlUtil {
|
||||
*/
|
||||
public BeanInfo getBeanInfo(Class clazz) throws IntrospectionException {
|
||||
synchronized (beanInfoCache) {
|
||||
BeanInfo beanInfo;
|
||||
beanInfo = beanInfoCache.get(clazz);
|
||||
BeanInfo beanInfo = beanInfoCache.get(clazz);
|
||||
if (beanInfo == null) {
|
||||
beanInfo = Introspector.getBeanInfo(clazz, Object.class);
|
||||
beanInfoCache.putIfAbsent(clazz, beanInfo);
|
||||
@@ -656,6 +773,9 @@ public class OgnlUtil {
|
||||
setValue(name, context, o, value);
|
||||
} catch (OgnlException e) {
|
||||
Throwable reason = e.getReason();
|
||||
if (reason instanceof SecurityException) {
|
||||
LOG.warn("Could not evaluate this expression due to security constraints: [{}]", name, e);
|
||||
}
|
||||
String msg = "Caught OgnlException while setting property '" + name + "' on type '" + o.getClass().getName() + "'.";
|
||||
Throwable exception = (reason == null) ? e : reason;
|
||||
|
||||
|
||||
@@ -82,7 +82,7 @@ public class OgnlValueStack implements Serializable, ValueStack, ClearableValueS
|
||||
}
|
||||
|
||||
@Inject
|
||||
public void setOgnlUtil(OgnlUtil ognlUtil) {
|
||||
protected void setOgnlUtil(OgnlUtil ognlUtil) {
|
||||
this.ognlUtil = ognlUtil;
|
||||
securityMemberAccess.setExcludedClasses(ognlUtil.getExcludedClasses());
|
||||
securityMemberAccess.setExcludedPackageNamePatterns(ognlUtil.getExcludedPackageNamePatterns());
|
||||
@@ -102,12 +102,12 @@ public class OgnlValueStack implements Serializable, ValueStack, ClearableValueS
|
||||
}
|
||||
|
||||
@Inject(XWorkConstants.DEV_MODE)
|
||||
public void setDevMode(String mode) {
|
||||
protected void setDevMode(String mode) {
|
||||
this.devMode = BooleanUtils.toBoolean(mode);
|
||||
}
|
||||
|
||||
@Inject(value = "logMissingProperties", required = false)
|
||||
public void setLogMissingProperties(String logMissingProperties) {
|
||||
protected void setLogMissingProperties(String logMissingProperties) {
|
||||
this.logMissingProperties = BooleanUtils.toBoolean(logMissingProperties);
|
||||
}
|
||||
|
||||
@@ -157,8 +157,6 @@ public class OgnlValueStack implements Serializable, ValueStack, ClearableValueS
|
||||
setValue(expr, value, devMode);
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
/**
|
||||
* @see com.opensymphony.xwork2.util.ValueStack#setValue(java.lang.String, java.lang.Object)
|
||||
*/
|
||||
@@ -184,7 +182,7 @@ public class OgnlValueStack implements Serializable, ValueStack, ClearableValueS
|
||||
|
||||
private void trySetValue(String expr, Object value, boolean throwExceptionOnFailure, Map<String, Object> context) throws OgnlException {
|
||||
context.put(XWorkConverter.CONVERSION_PROPERTY_FULLNAME, expr);
|
||||
context.put(REPORT_ERRORS_ON_NO_PROP, (throwExceptionOnFailure) ? Boolean.TRUE : Boolean.FALSE);
|
||||
context.put(REPORT_ERRORS_ON_NO_PROP, throwExceptionOnFailure || logMissingProperties ? Boolean.TRUE : Boolean.FALSE);
|
||||
ognlUtil.setValue(expr, context, root, value);
|
||||
}
|
||||
|
||||
@@ -206,6 +204,9 @@ public class OgnlValueStack implements Serializable, ValueStack, ClearableValueS
|
||||
}
|
||||
|
||||
protected void handleOgnlException(String expr, Object value, boolean throwExceptionOnFailure, OgnlException e) {
|
||||
if (e != null && e.getReason() instanceof SecurityException) {
|
||||
LOG.error("Could not evaluate this expression due to security constraints: [{}]", expr, e);
|
||||
}
|
||||
boolean shouldLog = shouldLogMissingPropertyWarning(e);
|
||||
String msg = null;
|
||||
if (throwExceptionOnFailure || shouldLog) {
|
||||
@@ -248,7 +249,7 @@ public class OgnlValueStack implements Serializable, ValueStack, ClearableValueS
|
||||
}
|
||||
|
||||
protected void setupExceptionOnFailure(boolean throwExceptionOnFailure) {
|
||||
if (throwExceptionOnFailure) {
|
||||
if (throwExceptionOnFailure || logMissingProperties) {
|
||||
context.put(THROW_EXCEPTION_ON_FAILURE, true);
|
||||
}
|
||||
}
|
||||
@@ -328,7 +329,12 @@ public class OgnlValueStack implements Serializable, ValueStack, ClearableValueS
|
||||
}
|
||||
|
||||
protected Object handleOgnlException(String expr, boolean throwExceptionOnFailure, OgnlException e) {
|
||||
Object ret = findInContext(expr);
|
||||
Object ret = null;
|
||||
if (e != null && e.getReason() instanceof SecurityException) {
|
||||
LOG.error("Could not evaluate this expression due to security constraints: [{}]", expr, e);
|
||||
} else {
|
||||
ret = findInContext(expr);
|
||||
}
|
||||
if (ret == null) {
|
||||
if (shouldLogMissingPropertyWarning(e)) {
|
||||
LOG.warn("Could not find property [{}]!", expr, e);
|
||||
@@ -341,8 +347,9 @@ public class OgnlValueStack implements Serializable, ValueStack, ClearableValueS
|
||||
}
|
||||
|
||||
protected boolean shouldLogMissingPropertyWarning(OgnlException e) {
|
||||
return (e instanceof NoSuchPropertyException || e instanceof MethodFailedException)
|
||||
&& devMode && logMissingProperties;
|
||||
return (e instanceof NoSuchPropertyException ||
|
||||
(e instanceof MethodFailedException && e.getReason() instanceof NoSuchMethodException))
|
||||
&& logMissingProperties;
|
||||
}
|
||||
|
||||
private Object tryFindValue(String expr, Class asType) throws OgnlException {
|
||||
@@ -379,7 +386,7 @@ public class OgnlValueStack implements Serializable, ValueStack, ClearableValueS
|
||||
* @param e The thrown exception.
|
||||
*/
|
||||
private void logLookupFailure(String expr, Exception e) {
|
||||
if (devMode && LOG.isWarnEnabled()) {
|
||||
if (devMode) {
|
||||
LOG.warn("Caught an exception while evaluating expression '{}' against value stack", expr, e);
|
||||
LOG.warn("NOTE: Previous warning message was issued due to devMode set to true.");
|
||||
} else {
|
||||
@@ -475,7 +482,7 @@ public class OgnlValueStack implements Serializable, ValueStack, ClearableValueS
|
||||
}
|
||||
|
||||
@Inject
|
||||
public void setXWorkConverter(final XWorkConverter converter) {
|
||||
protected void setXWorkConverter(final XWorkConverter converter) {
|
||||
this.converter = converter;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -19,6 +19,7 @@
|
||||
package com.opensymphony.xwork2.ognl;
|
||||
|
||||
import com.opensymphony.xwork2.ActionContext;
|
||||
import com.opensymphony.xwork2.XWorkConstants;
|
||||
import com.opensymphony.xwork2.TextProvider;
|
||||
import com.opensymphony.xwork2.conversion.NullHandler;
|
||||
import com.opensymphony.xwork2.conversion.impl.XWorkConverter;
|
||||
@@ -32,6 +33,8 @@ import ognl.MethodAccessor;
|
||||
import ognl.OgnlRuntime;
|
||||
import ognl.PropertyAccessor;
|
||||
import org.apache.commons.lang3.BooleanUtils;
|
||||
import org.apache.logging.log4j.LogManager;
|
||||
import org.apache.logging.log4j.Logger;
|
||||
|
||||
import java.util.Map;
|
||||
import java.util.Set;
|
||||
@@ -41,24 +44,26 @@ import java.util.Set;
|
||||
*/
|
||||
public class OgnlValueStackFactory implements ValueStackFactory {
|
||||
|
||||
private static final Logger LOG = LogManager.getLogger(OgnlValueStackFactory.class);
|
||||
|
||||
protected XWorkConverter xworkConverter;
|
||||
protected CompoundRootAccessor compoundRootAccessor;
|
||||
protected TextProvider textProvider;
|
||||
protected Container container;
|
||||
protected boolean allowStaticMethodAccess;
|
||||
private boolean allowStaticMethodAccess;
|
||||
|
||||
@Inject
|
||||
public void setXWorkConverter(XWorkConverter converter) {
|
||||
protected void setXWorkConverter(XWorkConverter converter) {
|
||||
this.xworkConverter = converter;
|
||||
}
|
||||
|
||||
@Inject("system")
|
||||
public void setTextProvider(TextProvider textProvider) {
|
||||
protected void setTextProvider(TextProvider textProvider) {
|
||||
this.textProvider = textProvider;
|
||||
}
|
||||
|
||||
@Inject(value="allowStaticMethodAccess", required=false)
|
||||
public void setAllowStaticMethodAccess(String allowStaticMethodAccess) {
|
||||
@Inject(value = XWorkConstants.ALLOW_STATIC_METHOD_ACCESS, required = false)
|
||||
protected void setAllowStaticMethodAccess(String allowStaticMethodAccess) {
|
||||
this.allowStaticMethodAccess = BooleanUtils.toBoolean(allowStaticMethodAccess);
|
||||
}
|
||||
|
||||
@@ -77,7 +82,7 @@ public class OgnlValueStackFactory implements ValueStackFactory {
|
||||
}
|
||||
|
||||
@Inject
|
||||
public void setContainer(Container container) throws ClassNotFoundException {
|
||||
protected void setContainer(Container container) throws ClassNotFoundException {
|
||||
Set<String> names = container.getInstanceNames(PropertyAccessor.class);
|
||||
for (String name : names) {
|
||||
Class cls = Class.forName(name);
|
||||
|
||||
@@ -46,9 +46,16 @@ public class SecurityMemberAccess extends DefaultMemberAccess {
|
||||
private Set<String> excludedPackageNames = Collections.emptySet();
|
||||
private boolean disallowProxyMemberAccess;
|
||||
|
||||
public SecurityMemberAccess(boolean method) {
|
||||
/**
|
||||
* SecurityMemberAccess
|
||||
* - access decisions based on whether member is static (or not)
|
||||
* - block or allow access to properties (configurable-after-construction)
|
||||
*
|
||||
* @param allowStaticMethodAccess
|
||||
*/
|
||||
public SecurityMemberAccess(boolean allowStaticMethodAccess) {
|
||||
super(false);
|
||||
allowStaticMethodAccess = method;
|
||||
this.allowStaticMethodAccess = allowStaticMethodAccess;
|
||||
}
|
||||
|
||||
public boolean getAllowStaticMethodAccess() {
|
||||
@@ -59,28 +66,30 @@ public class SecurityMemberAccess extends DefaultMemberAccess {
|
||||
public boolean isAccessible(Map context, Object target, Member member, String propertyName) {
|
||||
LOG.debug("Checking access for [target: {}, member: {}, property: {}]", target, member, propertyName);
|
||||
|
||||
final Class memberClass = member.getDeclaringClass();
|
||||
Class targetClass = (target != null ? target.getClass() : memberClass); // Note: target,propertyName may be null (static field checks OGNL 3.1.19+)
|
||||
|
||||
if (checkEnumAccess(target, member)) {
|
||||
LOG.trace("Allowing access to enum: {}", target);
|
||||
LOG.trace("Allowing access to enum: target class [{}] of target [{}], member [{}]", targetClass, target, member);
|
||||
return true;
|
||||
}
|
||||
|
||||
Class targetClass = target.getClass();
|
||||
Class memberClass = member.getDeclaringClass();
|
||||
|
||||
if (Modifier.isStatic(member.getModifiers()) && allowStaticMethodAccess) {
|
||||
LOG.debug("Support for accessing static methods [target: {}, member: {}, property: {}] is deprecated!", target, member, propertyName);
|
||||
if (!isClassExcluded(member.getDeclaringClass())) {
|
||||
targetClass = member.getDeclaringClass();
|
||||
LOG.debug("Support for accessing static methods [target: {}, targetClass: {}, member: {}, property: {}] is deprecated!",
|
||||
target, targetClass, member, propertyName);
|
||||
if (!isClassExcluded(memberClass)) {
|
||||
targetClass = memberClass;
|
||||
}
|
||||
}
|
||||
|
||||
if (isPackageExcluded(targetClass.getPackage(), memberClass.getPackage())) {
|
||||
LOG.warn("Package of target [{}] or package of member [{}] are excluded!", target, member);
|
||||
LOG.warn("Package [{}] of target class [{}] of target [{}] or package [{}] of member [{}] are excluded!", targetClass.getPackage(), targetClass,
|
||||
target, memberClass.getPackage(), member);
|
||||
return false;
|
||||
}
|
||||
|
||||
if (isClassExcluded(targetClass)) {
|
||||
LOG.warn("Target class [{}] is excluded!", target);
|
||||
LOG.warn("Target class [{}] of target [{}] is excluded!", targetClass, target);
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -90,7 +99,7 @@ public class SecurityMemberAccess extends DefaultMemberAccess {
|
||||
}
|
||||
|
||||
if (disallowProxyMemberAccess && ProxyUtil.isProxyMember(member, target)) {
|
||||
LOG.warn("Access to proxy [{}] is blocked!", member);
|
||||
LOG.warn("Access to proxy is blocked! Target class [{}] of target [{}], member [{}]", targetClass, target, member);
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -133,8 +142,8 @@ public class SecurityMemberAccess extends DefaultMemberAccess {
|
||||
LOG.warn("The use of the default (unnamed) package is discouraged!");
|
||||
}
|
||||
|
||||
final String targetPackageName = targetPackage == null ? "" : targetPackage.getName();
|
||||
final String memberPackageName = memberPackage == null ? "" : memberPackage.getName();
|
||||
String targetPackageName = targetPackage == null ? "" : targetPackage.getName();
|
||||
String memberPackageName = memberPackage == null ? "" : memberPackage.getName();
|
||||
|
||||
for (Pattern pattern : excludedPackageNamePatterns) {
|
||||
if (pattern.matcher(targetPackageName).matches() || pattern.matcher(memberPackageName).matches()) {
|
||||
@@ -142,9 +151,11 @@ public class SecurityMemberAccess extends DefaultMemberAccess {
|
||||
}
|
||||
}
|
||||
|
||||
targetPackageName = targetPackageName + ".";
|
||||
memberPackageName = memberPackageName + ".";
|
||||
|
||||
for (String packageName: excludedPackageNames) {
|
||||
if (targetPackageName.startsWith(packageName) || targetPackageName.equals(packageName)
|
||||
|| memberPackageName.startsWith(packageName) || memberPackageName.equals(packageName)) {
|
||||
if (targetPackageName.startsWith(packageName) || memberPackageName.startsWith(packageName)) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -28,7 +28,7 @@ import java.util.Map;
|
||||
*/
|
||||
public class XWorkTypeConverterWrapper implements TypeConverter {
|
||||
|
||||
private ognl.TypeConverter typeConverter;
|
||||
private final ognl.TypeConverter typeConverter;
|
||||
|
||||
public XWorkTypeConverterWrapper(ognl.TypeConverter conv) {
|
||||
this.typeConverter = conv;
|
||||
|
||||
+18
-14
@@ -63,10 +63,10 @@ public class CompoundRootAccessor implements PropertyAccessor, MethodAccessor, C
|
||||
private final static Logger LOG = LogManager.getLogger(CompoundRootAccessor.class);
|
||||
private final static Class[] EMPTY_CLASS_ARRAY = new Class[0];
|
||||
private static Map<MethodCall, Boolean> invalidMethods = new ConcurrentHashMap<>();
|
||||
private boolean devMode = false;
|
||||
private boolean devMode;
|
||||
|
||||
@Inject(XWorkConstants.DEV_MODE)
|
||||
public void setDevMode(String mode) {
|
||||
protected void setDevMode(String mode) {
|
||||
this.devMode = BooleanUtils.toBoolean(mode);
|
||||
}
|
||||
|
||||
@@ -217,13 +217,14 @@ public class CompoundRootAccessor implements PropertyAccessor, MethodAccessor, C
|
||||
return null;
|
||||
}
|
||||
|
||||
Throwable reason = null;
|
||||
Class[] argTypes = getArgTypes(objects);
|
||||
for (Object o : root) {
|
||||
if (o == null) {
|
||||
continue;
|
||||
}
|
||||
|
||||
Class clazz = o.getClass();
|
||||
Class[] argTypes = getArgTypes(objects);
|
||||
|
||||
MethodCall mc = null;
|
||||
|
||||
@@ -233,24 +234,27 @@ public class CompoundRootAccessor implements PropertyAccessor, MethodAccessor, C
|
||||
|
||||
if ((argTypes == null) || !invalidMethods.containsKey(mc)) {
|
||||
try {
|
||||
Object value = OgnlRuntime.callMethod((OgnlContext) context, o, name, objects);
|
||||
|
||||
if (value != null) {
|
||||
return value;
|
||||
}
|
||||
return OgnlRuntime.callMethod((OgnlContext) context, o, name, objects);
|
||||
} catch (OgnlException e) {
|
||||
// try the next one
|
||||
Throwable reason = e.getReason();
|
||||
reason = e.getReason();
|
||||
|
||||
if (!context.containsKey(OgnlValueStack.THROW_EXCEPTION_ON_FAILURE) && (mc != null) && (reason != null) && (reason.getClass() == NoSuchMethodException.class)) {
|
||||
invalidMethods.put(mc, Boolean.TRUE);
|
||||
} else if (reason != null) {
|
||||
throw new MethodFailedException(o, name, e.getReason());
|
||||
if (reason != null && !(reason instanceof NoSuchMethodException)) {
|
||||
// method has found but thrown an exception
|
||||
break;
|
||||
}
|
||||
|
||||
if ((mc != null) && (reason != null)) {
|
||||
invalidMethods.put(mc, Boolean.TRUE);
|
||||
}
|
||||
// continue and try the next one
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if (context.containsKey(OgnlValueStack.THROW_EXCEPTION_ON_FAILURE)) {
|
||||
throw new MethodFailedException(target, name, reason);
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
|
||||
+1
-1
@@ -48,7 +48,7 @@ public class XWorkCollectionPropertyAccessor extends SetPropertyAccessor {
|
||||
//use a basic object Ognl property accessor here
|
||||
//to access properties of the objects in the Set
|
||||
//so that nothing is put in the context to screw things up
|
||||
private ObjectPropertyAccessor _accessor = new ObjectPropertyAccessor();
|
||||
private final ObjectPropertyAccessor _accessor = new ObjectPropertyAccessor();
|
||||
|
||||
private XWorkConverter xworkConverter;
|
||||
private ObjectFactory objectFactory;
|
||||
|
||||
+1
-1
@@ -30,7 +30,7 @@ import java.util.Map;
|
||||
*/
|
||||
public class XWorkEnumerationAccessor extends EnumerationPropertyAccessor {
|
||||
|
||||
ObjectPropertyAccessor opa = new ObjectPropertyAccessor();
|
||||
private final ObjectPropertyAccessor opa = new ObjectPropertyAccessor();
|
||||
|
||||
@Override
|
||||
public void setProperty(Map context, Object target, Object name, Object value) throws OgnlException {
|
||||
|
||||
+1
-1
@@ -30,7 +30,7 @@ import java.util.Map;
|
||||
*/
|
||||
public class XWorkIteratorPropertyAccessor extends IteratorPropertyAccessor {
|
||||
|
||||
ObjectPropertyAccessor opa = new ObjectPropertyAccessor();
|
||||
private final ObjectPropertyAccessor opa = new ObjectPropertyAccessor();
|
||||
|
||||
@Override
|
||||
public void setProperty(Map context, Object target, Object name, Object value) throws OgnlException {
|
||||
|
||||
+53
-11
@@ -21,10 +21,13 @@ package com.opensymphony.xwork2.security;
|
||||
import com.opensymphony.xwork2.XWorkConstants;
|
||||
import com.opensymphony.xwork2.inject.Inject;
|
||||
import com.opensymphony.xwork2.util.TextParseUtil;
|
||||
import org.apache.commons.lang3.BooleanUtils;
|
||||
import org.apache.logging.log4j.LogManager;
|
||||
import org.apache.logging.log4j.Logger;
|
||||
import org.apache.struts2.StrutsConstants;
|
||||
|
||||
import java.util.Arrays;
|
||||
import java.util.Collections;
|
||||
import java.util.HashSet;
|
||||
import java.util.Set;
|
||||
import java.util.regex.Pattern;
|
||||
@@ -34,7 +37,11 @@ public class DefaultAcceptedPatternsChecker implements AcceptedPatternsChecker {
|
||||
private static final Logger LOG = LogManager.getLogger(DefaultAcceptedPatternsChecker.class);
|
||||
|
||||
public static final String[] ACCEPTED_PATTERNS = {
|
||||
"\\w+((\\.\\w+)|(\\[\\d+\\])|(\\(\\d+\\))|(\\['(\\w|[\\u4e00-\\u9fa5])+'\\])|(\\('(\\w|[\\u4e00-\\u9fa5])+'\\)))*"
|
||||
"\\w+((\\.\\w+)|(\\[\\d+])|(\\(\\d+\\))|(\\['(\\w|[\\u4e00-\\u9fa5])+'])|(\\('(\\w|[\\u4e00-\\u9fa5])+'\\)))*"
|
||||
};
|
||||
|
||||
public static final String[] DMI_AWARE_ACCEPTED_PATTERNS = {
|
||||
"\\w+([:]?\\w+)?((\\.\\w+)|(\\[\\d+])|(\\(\\d+\\))|(\\['(\\w|[\\u4e00-\\u9fa5])+'])|(\\('(\\w|[\\u4e00-\\u9fa5])+'\\)))*([!]?\\w+)?"
|
||||
};
|
||||
|
||||
private Set<Pattern> acceptedPatterns;
|
||||
@@ -43,40 +50,74 @@ public class DefaultAcceptedPatternsChecker implements AcceptedPatternsChecker {
|
||||
setAcceptedPatterns(ACCEPTED_PATTERNS);
|
||||
}
|
||||
|
||||
public DefaultAcceptedPatternsChecker(
|
||||
@Inject(value = StrutsConstants.STRUTS_ENABLE_DYNAMIC_METHOD_INVOCATION, required = false) String dmiValue
|
||||
) {
|
||||
if (BooleanUtils.toBoolean(dmiValue)) {
|
||||
LOG.debug("DMI is enabled, adding DMI related accepted patterns");
|
||||
setAcceptedPatterns(DMI_AWARE_ACCEPTED_PATTERNS);
|
||||
} else {
|
||||
setAcceptedPatterns(ACCEPTED_PATTERNS);
|
||||
}
|
||||
}
|
||||
|
||||
@Inject(value = XWorkConstants.OVERRIDE_ACCEPTED_PATTERNS, required = false)
|
||||
public void setOverrideAcceptedPatterns(String acceptablePatterns) {
|
||||
protected void setOverrideAcceptedPatterns(String acceptablePatterns) {
|
||||
LOG.warn("Overriding accepted patterns [{}] with [{}], be aware that this affects all instances and safety of your application!",
|
||||
XWorkConstants.OVERRIDE_ACCEPTED_PATTERNS, acceptablePatterns);
|
||||
acceptedPatterns, acceptablePatterns);
|
||||
acceptedPatterns = new HashSet<>();
|
||||
for (String pattern : TextParseUtil.commaDelimitedStringToSet(acceptablePatterns)) {
|
||||
acceptedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
try {
|
||||
for (String pattern : TextParseUtil.commaDelimitedStringToSet(acceptablePatterns)) {
|
||||
acceptedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
}
|
||||
} finally {
|
||||
acceptedPatterns = Collections.unmodifiableSet(acceptedPatterns);
|
||||
}
|
||||
}
|
||||
|
||||
@Inject(value = XWorkConstants.ADDITIONAL_ACCEPTED_PATTERNS, required = false)
|
||||
public void setAdditionalAcceptedPatterns(String acceptablePatterns) {
|
||||
protected void setAdditionalAcceptedPatterns(String acceptablePatterns) {
|
||||
LOG.warn("Adding additional global patterns [{}] to accepted patterns!", acceptablePatterns);
|
||||
for (String pattern : TextParseUtil.commaDelimitedStringToSet(acceptablePatterns)) {
|
||||
acceptedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
acceptedPatterns = new HashSet<>(acceptedPatterns); // Make mutable before adding
|
||||
try {
|
||||
for (String pattern : TextParseUtil.commaDelimitedStringToSet(acceptablePatterns)) {
|
||||
acceptedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
}
|
||||
} finally {
|
||||
acceptedPatterns = Collections.unmodifiableSet(acceptedPatterns);
|
||||
}
|
||||
}
|
||||
|
||||
@Override
|
||||
public void setAcceptedPatterns(String commaDelimitedPatterns) {
|
||||
setAcceptedPatterns(TextParseUtil.commaDelimitedStringToSet(commaDelimitedPatterns));
|
||||
}
|
||||
|
||||
@Override
|
||||
public void setAcceptedPatterns(String[] additionalPatterns) {
|
||||
setAcceptedPatterns(new HashSet<>(Arrays.asList(additionalPatterns)));
|
||||
}
|
||||
|
||||
@Override
|
||||
public void setAcceptedPatterns(Set<String> patterns) {
|
||||
LOG.trace("Sets accepted patterns [{}]", patterns);
|
||||
if (acceptedPatterns == null) {
|
||||
// Limit unwanted log entries (for 1st call, acceptedPatterns null)
|
||||
LOG.debug("Sets accepted patterns to [{}], note this impacts the safety of your application!", patterns);
|
||||
} else {
|
||||
LOG.warn("Replacing accepted patterns [{}] with [{}], be aware that this affects all instances and safety of your application!",
|
||||
acceptedPatterns, patterns);
|
||||
}
|
||||
acceptedPatterns = new HashSet<>(patterns.size());
|
||||
for (String pattern : patterns) {
|
||||
acceptedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
try {
|
||||
for (String pattern : patterns) {
|
||||
acceptedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
}
|
||||
} finally {
|
||||
acceptedPatterns = Collections.unmodifiableSet(acceptedPatterns);
|
||||
}
|
||||
}
|
||||
|
||||
@Override
|
||||
public IsAccepted isAccepted(String value) {
|
||||
for (Pattern acceptedPattern : acceptedPatterns) {
|
||||
if (acceptedPattern.matcher(value).matches()) {
|
||||
@@ -87,6 +128,7 @@ public class DefaultAcceptedPatternsChecker implements AcceptedPatternsChecker {
|
||||
return IsAccepted.no(acceptedPatterns.toString());
|
||||
}
|
||||
|
||||
@Override
|
||||
public Set<Pattern> getAcceptedPatterns() {
|
||||
return acceptedPatterns;
|
||||
}
|
||||
|
||||
+42
-12
@@ -27,6 +27,7 @@ import org.apache.logging.log4j.Logger;
|
||||
import org.apache.struts2.StrutsConstants;
|
||||
|
||||
import java.util.Arrays;
|
||||
import java.util.Collections;
|
||||
import java.util.HashSet;
|
||||
import java.util.Set;
|
||||
import java.util.regex.Pattern;
|
||||
@@ -47,47 +48,75 @@ public class DefaultExcludedPatternsChecker implements ExcludedPatternsChecker {
|
||||
}
|
||||
|
||||
@Inject(value = XWorkConstants.OVERRIDE_EXCLUDED_PATTERNS, required = false)
|
||||
public void setOverrideExcludePatterns(String excludePatterns) {
|
||||
LOG.warn("Overriding excluded patterns [{}] with [{}], be aware that this affects all instances and safety of your application!",
|
||||
XWorkConstants.OVERRIDE_EXCLUDED_PATTERNS, excludePatterns);
|
||||
excludedPatterns = new HashSet<Pattern>();
|
||||
for (String pattern : TextParseUtil.commaDelimitedStringToSet(excludePatterns)) {
|
||||
excludedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
protected void setOverrideExcludePatterns(String excludePatterns) {
|
||||
if (excludedPatterns != null && excludedPatterns.size() > 0) {
|
||||
LOG.warn("Overriding excluded patterns [{}] with [{}], be aware that this affects all instances and safety of your application!",
|
||||
excludedPatterns, excludePatterns);
|
||||
} else {
|
||||
// Limit unwanted log entries (when excludedPatterns null/empty - usually 1st call)
|
||||
LOG.debug("Overriding excluded patterns with [{}]", excludePatterns);
|
||||
}
|
||||
excludedPatterns = new HashSet<>();
|
||||
try {
|
||||
for (String pattern : TextParseUtil.commaDelimitedStringToSet(excludePatterns)) {
|
||||
excludedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
}
|
||||
} finally {
|
||||
excludedPatterns = Collections.unmodifiableSet(excludedPatterns);
|
||||
}
|
||||
}
|
||||
|
||||
@Inject(value = XWorkConstants.ADDITIONAL_EXCLUDED_PATTERNS, required = false)
|
||||
public void setAdditionalExcludePatterns(String excludePatterns) {
|
||||
LOG.debug("Adding additional global patterns [{}] to excluded patterns!", excludePatterns);
|
||||
for (String pattern : TextParseUtil.commaDelimitedStringToSet(excludePatterns)) {
|
||||
excludedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
excludedPatterns = new HashSet<>(excludedPatterns); // Make mutable before adding
|
||||
try {
|
||||
for (String pattern : TextParseUtil.commaDelimitedStringToSet(excludePatterns)) {
|
||||
excludedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
}
|
||||
} finally {
|
||||
excludedPatterns = Collections.unmodifiableSet(excludedPatterns);
|
||||
}
|
||||
}
|
||||
|
||||
@Inject(StrutsConstants.STRUTS_ENABLE_DYNAMIC_METHOD_INVOCATION)
|
||||
public void setDynamicMethodInvocation(String dmiValue) {
|
||||
protected void setDynamicMethodInvocation(String dmiValue) {
|
||||
if (!BooleanUtils.toBoolean(dmiValue)) {
|
||||
LOG.debug("DMI is disabled, adding DMI related excluded patterns");
|
||||
setAdditionalExcludePatterns("^(action|method):.*");
|
||||
}
|
||||
}
|
||||
|
||||
@Override
|
||||
public void setExcludedPatterns(String commaDelimitedPatterns) {
|
||||
setExcludedPatterns(TextParseUtil.commaDelimitedStringToSet(commaDelimitedPatterns));
|
||||
}
|
||||
|
||||
@Override
|
||||
public void setExcludedPatterns(String[] patterns) {
|
||||
setExcludedPatterns(new HashSet<>(Arrays.asList(patterns)));
|
||||
}
|
||||
|
||||
@Override
|
||||
public void setExcludedPatterns(Set<String> patterns) {
|
||||
LOG.trace("Sets excluded patterns [{}]", patterns);
|
||||
if (excludedPatterns != null && excludedPatterns.size() > 0) {
|
||||
LOG.warn("Replacing excluded patterns [{}] with [{}], be aware that this affects all instances and safety of your application!",
|
||||
excludedPatterns, patterns);
|
||||
} else {
|
||||
// Limit unwanted log entries (when excludedPatterns null/empty - usually 1st call)
|
||||
LOG.debug("Sets excluded patterns to [{}]", patterns);
|
||||
}
|
||||
excludedPatterns = new HashSet<>(patterns.size());
|
||||
for (String pattern : patterns) {
|
||||
excludedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
try {
|
||||
for (String pattern : patterns) {
|
||||
excludedPatterns.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
}
|
||||
} finally {
|
||||
excludedPatterns = Collections.unmodifiableSet(excludedPatterns);
|
||||
}
|
||||
}
|
||||
|
||||
@Override
|
||||
public IsExcluded isExcluded(String value) {
|
||||
for (Pattern excludedPattern : excludedPatterns) {
|
||||
if (excludedPattern.matcher(value).matches()) {
|
||||
@@ -98,6 +127,7 @@ public class DefaultExcludedPatternsChecker implements ExcludedPatternsChecker {
|
||||
return IsExcluded.no(excludedPatterns);
|
||||
}
|
||||
|
||||
@Override
|
||||
public Set<Pattern> getExcludedPatterns() {
|
||||
return excludedPatterns;
|
||||
}
|
||||
|
||||
@@ -53,7 +53,7 @@ abstract class AbstractLocalizedTextProvider implements LocalizedTextProvider {
|
||||
public static final String STRUTS_MESSAGES_BUNDLE = "org/apache/struts2/struts-messages";
|
||||
|
||||
private static final String TOMCAT_RESOURCE_ENTRIES_FIELD = "resourceEntries";
|
||||
private final String RELOADED = "com.opensymphony.xwork2.util.LocalizedTextProvider.reloaded";
|
||||
private static final String RELOADED = "com.opensymphony.xwork2.util.LocalizedTextProvider.reloaded";
|
||||
|
||||
protected final ConcurrentMap<String, ResourceBundle> bundlesMap = new ConcurrentHashMap<>();
|
||||
protected boolean devMode = false;
|
||||
@@ -225,10 +225,45 @@ abstract class AbstractLocalizedTextProvider implements LocalizedTextProvider {
|
||||
}
|
||||
|
||||
/**
|
||||
* @param bundleName Removes the bundle from any cached "misses"
|
||||
* Clear a specific bundle from the <code>bundlesMap</code>
|
||||
*
|
||||
* Warning: This method <b>may be ineffective</b> due to the way the <code>bundlesMap</code>
|
||||
* is used in combination with locale. Descendants should use the method
|
||||
* {@link #clearBundle(java.lang.String, java.util.Locale)} instead.
|
||||
*
|
||||
* @param bundleName The bundle to remove from the bundle map
|
||||
*/
|
||||
public void clearBundle(final String bundleName) {
|
||||
bundlesMap.remove(getCurrentThreadContextClassLoader().hashCode() + bundleName);
|
||||
final ResourceBundle removedBundle = bundlesMap.remove(getCurrentThreadContextClassLoader().hashCode() + bundleName);
|
||||
LOG.debug("Clearing resource bundle [{}], result: [{}].", bundleName, Boolean.valueOf(removedBundle != null));
|
||||
}
|
||||
|
||||
/**
|
||||
* Clear a specific bundle + locale combination from the <code>bundlesMap</code>.
|
||||
* Intended for descendants to use clear a bundle + locale combination.
|
||||
*
|
||||
* @param bundleName The bundle (combined with locale) to remove from the bundle map
|
||||
* @param locale Provides the locale to combine with the bundle to get the key
|
||||
*/
|
||||
protected void clearBundle(final String bundleName, Locale locale) {
|
||||
final String key = createMissesKey(String.valueOf(getCurrentThreadContextClassLoader().hashCode()), bundleName, locale);
|
||||
final ResourceBundle removedBundle = bundlesMap.remove(key);
|
||||
LOG.debug("Clearing resource bundle [{}], locale [{}], result: [{}].", bundleName, locale, Boolean.valueOf(removedBundle != null));
|
||||
}
|
||||
|
||||
/**
|
||||
* Clears the <code>missingBundles</code> contents. This allows descendants to
|
||||
* clear the <b>"missing bundles cache"</b> when desired (or needed).
|
||||
*
|
||||
* Note: This method may be used when the <code>bundlesMap</code> state has changed
|
||||
* in such a way that bundles that were previously "missing" may now be available
|
||||
* (e.g. after calling {@link #addDefaultResourceBundle(java.lang.String)} when the
|
||||
* {@link AbstractLocalizedTextProvider} has already been used for failed bundle
|
||||
* lookups of a given key, or some transitory state made a bundle lookup fail.
|
||||
*/
|
||||
protected void clearMissingBundlesCache() {
|
||||
missingBundles.clear();
|
||||
LOG.debug("Cleared the missing bundles cache.");
|
||||
}
|
||||
|
||||
protected void reloadBundles() {
|
||||
|
||||
@@ -27,6 +27,7 @@ import java.net.URI;
|
||||
import java.net.URISyntaxException;
|
||||
import java.net.URL;
|
||||
import java.net.URLClassLoader;
|
||||
import java.util.Collections;
|
||||
import java.util.HashMap;
|
||||
import java.util.Vector;
|
||||
import java.util.zip.ZipEntry;
|
||||
@@ -77,11 +78,7 @@ public class ClassPathFinder {
|
||||
*/
|
||||
public Vector<String> findMatches() {
|
||||
Vector<String> matches = new Vector<>();
|
||||
URLClassLoader cl = getURLClassLoader();
|
||||
if (cl == null ) {
|
||||
throw new XWorkException("unable to attain an URLClassLoader") ;
|
||||
}
|
||||
URL[] parentUrls = cl.getURLs();
|
||||
URL[] parentUrls = getClassLoaderURLs();
|
||||
compiledPattern = patternMatcher.compilePattern(pattern);
|
||||
for (URL url : parentUrls) {
|
||||
if (!"file".equals(url.getProtocol())) {
|
||||
@@ -173,20 +170,24 @@ public class ClassPathFinder {
|
||||
this.patternMatcher = patternMatcher;
|
||||
}
|
||||
|
||||
private URLClassLoader getURLClassLoader() {
|
||||
URLClassLoader ucl = null;
|
||||
private URL[] getClassLoaderURLs() {
|
||||
URL[] urls;
|
||||
ClassLoader loader = Thread.currentThread().getContextClassLoader();
|
||||
|
||||
if(! (loader instanceof URLClassLoader)) {
|
||||
|
||||
if (!(loader instanceof URLClassLoader)) {
|
||||
loader = ClassPathFinder.class.getClassLoader();
|
||||
if (loader instanceof URLClassLoader) {
|
||||
ucl = (URLClassLoader) loader ;
|
||||
}
|
||||
|
||||
if (loader instanceof URLClassLoader) {
|
||||
urls = ((URLClassLoader) loader).getURLs();
|
||||
} else { //jdk9 or later
|
||||
try {
|
||||
urls = Collections.list(loader.getResources("")).toArray(new URL[0]);
|
||||
} catch (IOException e) {
|
||||
throw new XWorkException("unable to get ClassLoader URLs", e);
|
||||
}
|
||||
}
|
||||
else {
|
||||
ucl = (URLClassLoader) loader;
|
||||
}
|
||||
|
||||
return ucl ;
|
||||
|
||||
return urls;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -82,13 +82,14 @@ public class ProxyUtil {
|
||||
}
|
||||
|
||||
/**
|
||||
* Check whether the given member is a proxy member of a proxy object.
|
||||
* Check whether the given member is a proxy member of a proxy object or is a static proxy member.
|
||||
* @param member the member to check
|
||||
* @param object the object to check
|
||||
*/
|
||||
public static boolean isProxyMember(Member member, Object object) {
|
||||
if (!isProxy(object))
|
||||
if (!Modifier.isStatic(member.getModifiers()) && !isProxy(object)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
Boolean flag = isProxyMemberCache.get(member);
|
||||
if (flag != null) {
|
||||
|
||||
@@ -58,10 +58,25 @@ public class ResourceFinder {
|
||||
this(path, classLoaderInterface, null);
|
||||
}
|
||||
|
||||
/**
|
||||
* Create a ResourceFinder instance for looking up resources (via ClassLoader or via specific URLs
|
||||
* specifying resource locations).
|
||||
*
|
||||
* This class was functional in Struts 2.3.x, but broken for Struts 2.5.x (before 2.5.24), when dealing with
|
||||
* JAR resources in certain circumstances. The current logic permits the base path to be "" (empty string),
|
||||
* which is required to also match JAR entries rooted at "" and not just file entries rooted at "/".
|
||||
*
|
||||
* @param path Base path from which to look for resources (typically "xyz/abc/klm" form for file or
|
||||
* jar contents).
|
||||
* @param classLoaderInterface ClassLoader to perform the resource lookup. If null, a default Thread
|
||||
* ClassLoader will be used.
|
||||
* @param urls URLs (typically file: or jar:) within which to search for resources, instead of the
|
||||
* ClassLoader. If null, fallback to a ClassLoader instead.
|
||||
*/
|
||||
public ResourceFinder(String path, ClassLoaderInterface classLoaderInterface, URL... urls) {
|
||||
path = StringUtils.trimToEmpty(path);
|
||||
if (!StringUtils.endsWith(path, "/")) {
|
||||
path += "/";
|
||||
if (!path.isEmpty() && !StringUtils.endsWith(path, "/")) {
|
||||
path += "/"; // Only append terminator to nonempty paths, otherwise JAR entry lookups break.
|
||||
}
|
||||
this.path = path;
|
||||
|
||||
@@ -1015,15 +1030,26 @@ public class ResourceFinder {
|
||||
public Map<URL, Set<String>> findPackagesMap(String uri) throws IOException {
|
||||
String basePath = path + uri;
|
||||
|
||||
LOG.trace(" basePath(initial): " + basePath);
|
||||
|
||||
if (!basePath.endsWith("/")) {
|
||||
basePath += "/";
|
||||
}
|
||||
|
||||
LOG.trace(" basePath(final): " + basePath);
|
||||
|
||||
Enumeration<URL> urls = getResources(basePath);
|
||||
Map<URL, Set<String>> result = new HashMap<>();
|
||||
|
||||
if (! urls.hasMoreElements()) {
|
||||
LOG.debug(" urls enumeration for basePath is empty ?");
|
||||
}
|
||||
|
||||
while (urls.hasMoreElements()) {
|
||||
URL location = urls.nextElement();
|
||||
|
||||
LOG.debug(" url (location): " + location);
|
||||
|
||||
try {
|
||||
if ("jar".equals(location.getProtocol())) {
|
||||
Set<String> resources = new HashSet<>();
|
||||
@@ -1114,12 +1140,20 @@ public class ResourceFinder {
|
||||
jarfile = conn.getJarFile();
|
||||
|
||||
Enumeration<JarEntry> entries = jarfile.entries();
|
||||
|
||||
if (entries == null || ! entries.hasMoreElements()) {
|
||||
LOG.debug(" JAR entries null or empty");
|
||||
}
|
||||
LOG.debug(" Looking for entries matching basePath: " + basePath);
|
||||
|
||||
while (entries != null && entries.hasMoreElements()) {
|
||||
JarEntry entry = entries.nextElement();
|
||||
String name = entry.getName();
|
||||
|
||||
if (entry.isDirectory() && StringUtils.startsWith(name, basePath)) {
|
||||
resources.add(name);
|
||||
} else if (entry.isDirectory()) {
|
||||
LOG.trace(" entry: " + name + " , isDirectory: " + entry.isDirectory() + " but does not start with basepath");
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1156,13 +1190,22 @@ public class ResourceFinder {
|
||||
|
||||
private Enumeration<URL> getResources(String fulluri) throws IOException {
|
||||
if (urls == null) {
|
||||
LOG.debug(" urls (member) null, using classLoaderInterface to get resources");
|
||||
|
||||
return classLoaderInterface.getResources(fulluri);
|
||||
}
|
||||
|
||||
LOG.debug(" urls (member) non-null, using findResource to get resources");
|
||||
|
||||
Vector<URL> resources = new Vector<>();
|
||||
for (URL url : urls) {
|
||||
URL resource = findResource(fulluri, url);
|
||||
if (resource != null){
|
||||
|
||||
if (resource != null) {
|
||||
LOG.trace(" resource lookup non-null");
|
||||
resources.add(resource);
|
||||
} else {
|
||||
LOG.trace(" resource lookup is null");
|
||||
}
|
||||
}
|
||||
return resources.elements();
|
||||
|
||||
@@ -40,7 +40,8 @@ public class DefaultFileManager implements FileManager {
|
||||
private static final Pattern JAR_PATTERN = Pattern.compile("^(jar:|wsjar:|zip:|vfsfile:|code-source:)?(file:)?(.*?)(\\!/|\\.jar/)(.*)");
|
||||
private static final int JAR_FILE_PATH = 3;
|
||||
|
||||
protected static Map<String, Revision> files = Collections.synchronizedMap(new HashMap<String, Revision>());
|
||||
protected static final Map<String, Revision> files = Collections.synchronizedMap(new HashMap<String, Revision>());
|
||||
private static final List<URL> lazyMonitoredFilesCache = Collections.synchronizedList(new ArrayList<URL>());
|
||||
|
||||
protected boolean reloadingConfigs = false;
|
||||
|
||||
@@ -48,6 +49,16 @@ public class DefaultFileManager implements FileManager {
|
||||
}
|
||||
|
||||
public void setReloadingConfigs(boolean reloadingConfigs) {
|
||||
if (reloadingConfigs && !this.reloadingConfigs) {
|
||||
//starting monitoring cached not-monitored files (lazy monitoring on demand because of performance)
|
||||
this.reloadingConfigs = true;
|
||||
synchronized (lazyMonitoredFilesCache) {
|
||||
for (URL fileUrl : lazyMonitoredFilesCache) {
|
||||
monitorFile(fileUrl);
|
||||
}
|
||||
lazyMonitoredFilesCache.clear();
|
||||
}
|
||||
}
|
||||
this.reloadingConfigs = reloadingConfigs;
|
||||
}
|
||||
|
||||
@@ -88,6 +99,12 @@ public class DefaultFileManager implements FileManager {
|
||||
|
||||
public void monitorFile(URL fileUrl) {
|
||||
String fileName = fileUrl.toString();
|
||||
if (!reloadingConfigs) {
|
||||
//reserve file for monitoring on demand because of performance
|
||||
files.remove(fileName);
|
||||
lazyMonitoredFilesCache.add(fileUrl);
|
||||
return;
|
||||
}
|
||||
Revision revision;
|
||||
LOG.debug("Creating revision for URL: {}", fileName);
|
||||
if (isJarURL(fileUrl)) {
|
||||
|
||||
@@ -37,9 +37,7 @@ public class JarEntryRevision extends Revision {
|
||||
private long lastModified;
|
||||
|
||||
public static Revision build(URL fileUrl, FileManager fileManager) {
|
||||
StrutsJarURLConnection conn = null;
|
||||
try {
|
||||
conn = StrutsJarURLConnection.openConnection(fileUrl);
|
||||
try (StrutsJarURLConnection conn = StrutsJarURLConnection.openConnection(fileUrl)) {
|
||||
conn.setUseCaches(false);
|
||||
URL url = fileManager.normalizeToFileProtocol(fileUrl);
|
||||
if (url != null) {
|
||||
@@ -51,14 +49,6 @@ public class JarEntryRevision extends Revision {
|
||||
LOG.warn("Could not create JarEntryRevision for [{}]!", fileUrl, e);
|
||||
return null;
|
||||
}
|
||||
finally {
|
||||
if(null != conn) {
|
||||
try {
|
||||
conn.getInputStream().close();
|
||||
} catch (IOException ignored) {
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private JarEntryRevision(URL jarFileURL, long lastModified) {
|
||||
@@ -70,21 +60,12 @@ public class JarEntryRevision extends Revision {
|
||||
}
|
||||
|
||||
public boolean needsReloading() {
|
||||
StrutsJarURLConnection conn = null;
|
||||
long lastLastModified = lastModified;
|
||||
try {
|
||||
conn = StrutsJarURLConnection.openConnection(jarFileURL);
|
||||
try (StrutsJarURLConnection conn = StrutsJarURLConnection.openConnection(jarFileURL)) {
|
||||
conn.setUseCaches(false);
|
||||
lastLastModified = conn.getJarEntry().getTime();
|
||||
} catch (IOException ignored) {
|
||||
}
|
||||
finally {
|
||||
if(null != conn) {
|
||||
try {
|
||||
conn.getInputStream().close();
|
||||
} catch (IOException ignored) {
|
||||
}
|
||||
}
|
||||
} catch (Throwable e) {
|
||||
LOG.warn("Could not check if needsReloading for [{}]!", jarFileURL, e);
|
||||
}
|
||||
|
||||
return lastModified < lastLastModified;
|
||||
|
||||
@@ -44,7 +44,7 @@ import java.util.jar.JarFile;
|
||||
* While {@link JarURLConnection#parseSpecs(URL)} is private, then we had to extend {@link URLConnection} instead
|
||||
* @since 2.5.15
|
||||
*/
|
||||
class StrutsJarURLConnection extends URLConnection {
|
||||
class StrutsJarURLConnection extends URLConnection implements AutoCloseable {
|
||||
private static final String FILE_URL_PREFIX = "file:";
|
||||
|
||||
private JarURLConnection jarURLConnection;
|
||||
@@ -123,8 +123,8 @@ class StrutsJarURLConnection extends URLConnection {
|
||||
Path tmpFile = Files.createTempFile("jar_cache", null);
|
||||
try {
|
||||
Files.copy(in, tmpFile, StandardCopyOption.REPLACE_EXISTING);
|
||||
JarFile jarFile = new JarFile(tmpFile.toFile(), true, JarFile.OPEN_READ);
|
||||
tmpFile.toFile().deleteOnExit();
|
||||
JarFile jarFile = new JarFile(tmpFile.toFile(), true, JarFile.OPEN_READ
|
||||
| JarFile.OPEN_DELETE);
|
||||
return jarFile;
|
||||
} catch (Throwable thr) {
|
||||
try {
|
||||
@@ -171,6 +171,20 @@ class StrutsJarURLConnection extends URLConnection {
|
||||
}
|
||||
}
|
||||
|
||||
@Override
|
||||
public void close() throws Exception {
|
||||
try {
|
||||
getInputStream().close();
|
||||
} catch (IOException ignored) {
|
||||
}
|
||||
if (jarURLConnection == null) {
|
||||
try {
|
||||
jarFile.close();
|
||||
} catch (IOException ignored) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
static StrutsJarURLConnection openConnection(URL url) throws IOException {
|
||||
return new StrutsJarURLConnection(url);
|
||||
}
|
||||
|
||||
@@ -41,12 +41,15 @@ public final class StrutsConstants {
|
||||
/** The URL extension to use to determine if the request is meant for a Struts action */
|
||||
public static final String STRUTS_ACTION_EXTENSION = "struts.action.extension";
|
||||
|
||||
/** Comma separated list of patterns (java.util.regex.Pattern) to be excluded from Struts2-processing */
|
||||
public static final String STRUTS_ACTION_EXCLUDE_PATTERN = "struts.action.excludePattern";
|
||||
/** Comma separated list of patterns (java.util.regex.Pattern) to be excluded from Struts2-processing */
|
||||
public static final String STRUTS_ACTION_EXCLUDE_PATTERN = "struts.action.excludePattern";
|
||||
|
||||
/** Whether to use the alterative syntax for the tags or not */
|
||||
/** Whether to use the alternative syntax for the tags or not */
|
||||
public static final String STRUTS_TAG_ALTSYNTAX = "struts.tag.altSyntax";
|
||||
|
||||
/** Whether to use the response encoding (JSP page encoding) for s:include tag processing (false - use STRUTS_I18N_ENCODING - by default) */
|
||||
public static final String STRUTS_TAG_INCLUDETAG_USERESPONSEENCODING = "struts.tag.includetag.useResponseEncoding";
|
||||
|
||||
/** The HTTP port used by Struts URLs */
|
||||
public static final String STRUTS_URL_HTTP_PORT = "struts.url.http.port";
|
||||
|
||||
@@ -56,7 +59,7 @@ public final class StrutsConstants {
|
||||
/** The default includeParams method to generate Struts URLs */
|
||||
public static final String STRUTS_URL_INCLUDEPARAMS = "struts.url.includeParams";
|
||||
|
||||
public static final String STRUTS_URL_RENDERER = "struts.urlRenderer";
|
||||
public static final String STRUTS_URL_RENDERER = "struts.urlRenderer";
|
||||
|
||||
/** The com.opensymphony.xwork2.ObjectFactory implementation class */
|
||||
public static final String STRUTS_OBJECTFACTORY = "struts.objectFactory";
|
||||
@@ -91,7 +94,7 @@ public final class StrutsConstants {
|
||||
/** The org.apache.struts2.views.freemarker.FreemarkerManager implementation class */
|
||||
public static final String STRUTS_FREEMARKER_MANAGER_CLASSNAME = "struts.freemarker.manager.classname";
|
||||
|
||||
/** Update freemarker templates cache in seconds*/
|
||||
/** Update freemarker templates cache in seconds */
|
||||
public static final String STRUTS_FREEMARKER_TEMPLATES_CACHE_UPDATE_DELAY = "struts.freemarker.templatesCache.updateDelay";
|
||||
|
||||
/** Cache model instances at BeanWrapper level */
|
||||
@@ -220,12 +223,12 @@ public final class StrutsConstants {
|
||||
public static final String STRUTS_LOCALE_PROVIDER_FACTORY = "struts.localeProviderFactory";
|
||||
|
||||
/** The name of the parameter to create when mapping an id (used by some action mappers) */
|
||||
public static final String STRUTS_ID_PARAMETER_NAME = "struts.mapper.idParameterName";
|
||||
|
||||
/** The name of the parameter to determine whether static method access will be allowed in OGNL expressions or not */
|
||||
public static final String STRUTS_ALLOW_STATIC_METHOD_ACCESS = "struts.ognl.allowStaticMethodAccess";
|
||||
public static final String STRUTS_ID_PARAMETER_NAME = "struts.mapper.idParameterName";
|
||||
|
||||
/** The com.opensymphony.xwork2.validator.ActionValidatorManager implementation class */
|
||||
/** The name of the parameter to determine whether static method access will be allowed in OGNL expressions or not */
|
||||
public static final String STRUTS_ALLOW_STATIC_METHOD_ACCESS = "struts.ognl.allowStaticMethodAccess";
|
||||
|
||||
/** The com.opensymphony.xwork2.validator.ActionValidatorManager implementation class */
|
||||
public static final String STRUTS_ACTIONVALIDATORMANAGER = "struts.actionValidatorManager";
|
||||
|
||||
/** The {@link com.opensymphony.xwork2.util.ValueStackFactory} implementation class */
|
||||
@@ -236,7 +239,7 @@ public final class StrutsConstants {
|
||||
|
||||
/** The {@link com.opensymphony.xwork2.util.reflection.ReflectionContextFactory} implementation class */
|
||||
public static final String STRUTS_REFLECTIONCONTEXTFACTORY = "struts.reflectionContextFactory";
|
||||
|
||||
|
||||
/** The {@link com.opensymphony.xwork2.util.PatternMatcher} implementation class */
|
||||
public static final String STRUTS_PATTERNMATCHER = "struts.patternMatcher";
|
||||
|
||||
@@ -246,32 +249,35 @@ public final class StrutsConstants {
|
||||
/** The {@link com.opensymphony.xwork2.UnknownHandlerManager} implementation class */
|
||||
public static final String STRUTS_UNKNOWN_HANDLER_MANAGER = "struts.unknownHandlerManager";
|
||||
|
||||
/** Throw RuntimeException when a property is not found, or the evaluation of the espression fails*/
|
||||
/** Throw RuntimeException when a property is not found, or the evaluation of the expression fails */
|
||||
public static final String STRUTS_EL_THROW_EXCEPTION = "struts.el.throwExceptionOnFailure";
|
||||
|
||||
/** Logs properties that are not found (very verbose) **/
|
||||
/** Logs properties that are not found (very verbose) */
|
||||
public static final String STRUTS_LOG_MISSING_PROPERTIES = "struts.ognl.logMissingProperties";
|
||||
|
||||
/** Enables caching of parsed OGNL expressions **/
|
||||
/** Enables caching of parsed OGNL expressions */
|
||||
public static final String STRUTS_ENABLE_OGNL_EXPRESSION_CACHE = "struts.ognl.enableExpressionCache";
|
||||
|
||||
/** Enables evaluation of OGNL expressions **/
|
||||
/** Enables evaluation of OGNL expressions */
|
||||
public static final String STRUTS_ENABLE_OGNL_EVAL_EXPRESSION = "struts.ognl.enableOGNLEvalExpression";
|
||||
|
||||
/** Disables {@link org.apache.struts2.dispatcher.StrutsRequestWrapper} request attribute value stack lookup (JSTL accessibility) **/
|
||||
/** The maximum length of an expression (OGNL) */
|
||||
public static final String STRUTS_OGNL_EXPRESSION_MAX_LENGTH = "struts.ognl.expressionMaxLength";
|
||||
|
||||
/** Disables {@link org.apache.struts2.dispatcher.StrutsRequestWrapper} request attribute value stack lookup (JSTL accessibility) */
|
||||
public static final String STRUTS_DISABLE_REQUEST_ATTRIBUTE_VALUE_STACK_LOOKUP = "struts.disableRequestAttributeValueStackLookup";
|
||||
|
||||
/** The{@link org.apache.struts2.views.util.UrlHelper} implementation class **/
|
||||
/** The{@link org.apache.struts2.views.util.UrlHelper} implementation class */
|
||||
public static final String STRUTS_URL_HELPER = "struts.view.urlHelper";
|
||||
|
||||
/** {@link com.opensymphony.xwork2.conversion.impl.XWorkBasicConverter} **/
|
||||
/** {@link com.opensymphony.xwork2.conversion.impl.XWorkBasicConverter} */
|
||||
public static final String STRUTS_CONVERTER_COLLECTION = "struts.converter.collection";
|
||||
public static final String STRUTS_CONVERTER_ARRAY = "struts.converter.array";
|
||||
public static final String STRUTS_CONVERTER_DATE = "struts.converter.date";
|
||||
public static final String STRUTS_CONVERTER_NUMBER = "struts.converter.number";
|
||||
public static final String STRUTS_CONVERTER_STRING = "struts.converter.string";
|
||||
|
||||
/** Enable handling exceptions by Dispatcher - true by default **/
|
||||
/** Enable handling exceptions by Dispatcher - true by default */
|
||||
public static final String STRUTS_HANDLE_EXCEPTION = "struts.handle.exception";
|
||||
|
||||
public static final String STRUTS_CONVERTER_PROPERTIES_PROCESSOR = "struts.converter.properties.processor";
|
||||
@@ -282,37 +288,42 @@ public final class StrutsConstants {
|
||||
|
||||
public static final String STRUTS_EXPRESSION_PARSER = "struts.expression.parser";
|
||||
|
||||
/** actions names' whitelist **/
|
||||
/** Namespace names' whitelist */
|
||||
public static final String STRUTS_ALLOWED_NAMESPACE_NAMES = "struts.allowed.namespace.names";
|
||||
/** Default namespace name to use when namespace didn't match the whitelist */
|
||||
public static final String STRUTS_DEFAULT_NAMESPACE_NAME = "struts.default.namespace.name";
|
||||
|
||||
/** Action names' whitelist */
|
||||
public static final String STRUTS_ALLOWED_ACTION_NAMES = "struts.allowed.action.names";
|
||||
/** default action name to use when action didn't match the whitelist **/
|
||||
/** Default action name to use when action didn't match the whitelist */
|
||||
public static final String STRUTS_DEFAULT_ACTION_NAME = "struts.default.action.name";
|
||||
|
||||
/** methods names' whitelist **/
|
||||
/** Method names' whitelist */
|
||||
public static final String STRUTS_ALLOWED_METHOD_NAMES = "struts.allowed.method.names";
|
||||
/** default method name to use when method didn't match the whitelist **/
|
||||
/** Default method name to use when method didn't match the whitelist */
|
||||
public static final String STRUTS_DEFAULT_METHOD_NAME = "struts.default.method.name";
|
||||
|
||||
/** enables action: prefix **/
|
||||
/** Enables action: prefix */
|
||||
public static final String STRUTS_MAPPER_ACTION_PREFIX_ENABLED = "struts.mapper.action.prefix.enabled";
|
||||
|
||||
/** enables access to actions in other namespaces than current with action: prefix **/
|
||||
/** Enables access to actions in other namespaces than current with action: prefix */
|
||||
public static final String STRUTS_MAPPER_ACTION_PREFIX_CROSSNAMESPACES = "struts.mapper.action.prefix.crossNamespaces";
|
||||
|
||||
public static final String DEFAULT_TEMPLATE_TYPE_CONFIG_KEY = "struts.ui.templateSuffix";
|
||||
|
||||
/** Allows override default DispatcherErrorHandler **/
|
||||
/** Allows override default DispatcherErrorHandler */
|
||||
public static final String STRUTS_DISPATCHER_ERROR_HANDLER = "struts.dispatcher.errorHandler";
|
||||
|
||||
/** Comma delimited set of excluded classes and package names which cannot be accessed via expressions **/
|
||||
/** Comma delimited set of excluded classes and package names which cannot be accessed via expressions */
|
||||
public static final String STRUTS_EXCLUDED_CLASSES = "struts.excludedClasses";
|
||||
public static final String STRUTS_EXCLUDED_PACKAGE_NAME_PATTERNS = "struts.excludedPackageNamePatterns";
|
||||
public static final String STRUTS_EXCLUDED_PACKAGE_NAMES = "struts.excludedPackageNames";
|
||||
|
||||
/** Dedicated services to check if passed string is excluded/accepted **/
|
||||
/** Dedicated services to check if passed string is excluded/accepted */
|
||||
public static final String STRUTS_EXCLUDED_PATTERNS_CHECKER = "struts.excludedPatterns.checker";
|
||||
public static final String STRUTS_ACCEPTED_PATTERNS_CHECKER = "struts.acceptedPatterns.checker";
|
||||
|
||||
/** Constant is used to override framework's default excluded patterns **/
|
||||
/** Constant is used to override framework's default excluded patterns */
|
||||
public static final String STRUTS_OVERRIDE_EXCLUDED_PATTERNS = "struts.override.excludedPatterns";
|
||||
public static final String STRUTS_OVERRIDE_ACCEPTED_PATTERNS = "struts.override.acceptedPatterns";
|
||||
|
||||
@@ -330,4 +341,7 @@ public final class StrutsConstants {
|
||||
public static final String STRUTS_DISALLOW_PROXY_MEMBER_ACCESS = "struts.disallowProxyMemberAccess";
|
||||
|
||||
public static final String STRUTS_OGNL_AUTO_GROWTH_COLLECTION_LIMIT = "struts.ognl.autoGrowthCollectionLimit";
|
||||
|
||||
/** See {@link com.opensymphony.xwork2.config.impl.AbstractMatcher#appendNamedParameters */
|
||||
public static final String STRUTS_MATCHER_APPEND_NAMED_PARAMETERS = "struts.matcher.appendNamedParameters";
|
||||
}
|
||||
|
||||
@@ -20,6 +20,7 @@ package org.apache.struts2.components;
|
||||
|
||||
import com.opensymphony.xwork2.inject.Inject;
|
||||
import com.opensymphony.xwork2.util.ValueStack;
|
||||
|
||||
import org.apache.logging.log4j.LogManager;
|
||||
import org.apache.logging.log4j.Logger;
|
||||
import org.apache.struts2.RequestUtils;
|
||||
@@ -35,6 +36,7 @@ import javax.servlet.ServletRequest;
|
||||
import javax.servlet.http.HttpServletRequest;
|
||||
import javax.servlet.http.HttpServletResponse;
|
||||
import javax.servlet.http.HttpServletResponseWrapper;
|
||||
|
||||
import java.io.*;
|
||||
import java.net.URLEncoder;
|
||||
import java.util.*;
|
||||
@@ -90,17 +92,19 @@ public class Include extends Component {
|
||||
|
||||
private static final Logger LOG = LogManager.getLogger(Include.class);
|
||||
|
||||
private static String systemEncoding = System.getProperty("file.encoding");
|
||||
private static final String systemEncoding = System.getProperty("file.encoding");
|
||||
|
||||
protected String value;
|
||||
private HttpServletRequest req;
|
||||
private HttpServletResponse res;
|
||||
private static String defaultEncoding;
|
||||
private String defaultEncoding; // Made non-static (during WW-4971 fix)
|
||||
private boolean useResponseEncoding; // Added with WW-4971 fix (allows switch between usage of response or default encoding)
|
||||
|
||||
public Include(ValueStack stack, HttpServletRequest req, HttpServletResponse res) {
|
||||
super(stack);
|
||||
this.req = req;
|
||||
this.res = res;
|
||||
useResponseEncoding = false; // By default use defaultEncoding (vs. response/page encoding)
|
||||
}
|
||||
|
||||
@Inject(StrutsConstants.STRUTS_I18N_ENCODING)
|
||||
@@ -108,9 +112,25 @@ public class Include extends Component {
|
||||
defaultEncoding = encoding;
|
||||
}
|
||||
|
||||
@Inject(value = StrutsConstants.STRUTS_TAG_INCLUDETAG_USERESPONSEENCODING, required=false)
|
||||
public void setUseResponseEncoding(String useEncoding) {
|
||||
useResponseEncoding = Boolean.parseBoolean(useEncoding);
|
||||
}
|
||||
|
||||
public boolean end(Writer writer, String body) {
|
||||
String page = findString(value, "value", "You must specify the URL to include. Example: /foo.jsp");
|
||||
StringBuilder urlBuf = new StringBuilder();
|
||||
String encodingForInclude;
|
||||
|
||||
if (useResponseEncoding) {
|
||||
encodingForInclude = res.getCharacterEncoding(); // Use response (page) encoding
|
||||
if (encodingForInclude == null || encodingForInclude.length() == 0) {
|
||||
encodingForInclude = defaultEncoding; // Revert to defaultEncoding when response (page) encoding is invalid
|
||||
}
|
||||
}
|
||||
else {
|
||||
encodingForInclude = defaultEncoding; // Use default encoding (when useResponseEncoding is false)
|
||||
}
|
||||
|
||||
// Add URL
|
||||
urlBuf.append(page);
|
||||
@@ -147,7 +167,7 @@ public class Include extends Component {
|
||||
|
||||
// Include
|
||||
try {
|
||||
include(result, writer, req, res, defaultEncoding);
|
||||
include(result, writer, req, res, encodingForInclude);
|
||||
} catch (ServletException | IOException e) {
|
||||
LOG.warn("Exception thrown during include of {}", result, e);
|
||||
}
|
||||
@@ -209,7 +229,7 @@ public class Include extends Component {
|
||||
}
|
||||
|
||||
public void addParameter(String key, Object value) {
|
||||
// don't use the default implementation of addParameter,
|
||||
// Don't use the default implementation of addParameter,
|
||||
// instead, include tag requires that each parameter be a list of objects,
|
||||
// just like the HTTP servlet interfaces are (String[])
|
||||
if (value != null) {
|
||||
@@ -256,7 +276,7 @@ public class Include extends Component {
|
||||
// Use given encoding
|
||||
pageResponse.getContent().writeTo(writer, encoding);
|
||||
} else {
|
||||
//use the platform specific encoding
|
||||
// Use the platform specific encoding
|
||||
pageResponse.getContent().writeTo(writer, systemEncoding);
|
||||
}
|
||||
}
|
||||
@@ -349,9 +369,9 @@ public class Include extends Component {
|
||||
* @throws IOException
|
||||
*/
|
||||
public FastByteArrayOutputStream getContent() throws IOException {
|
||||
//if we are using a writer, we need to flush the
|
||||
//data to the underlying outputstream.
|
||||
//most containers do this - but it seems Jetty 4.0.5 doesn't
|
||||
// If we are using a writer, we need to flush the
|
||||
// data to the underlying outputstream.
|
||||
// Most containers do this - but it seems Jetty 4.0.5 doesn't
|
||||
if (pagePrintWriter != null) {
|
||||
pagePrintWriter.flush();
|
||||
}
|
||||
|
||||
@@ -140,4 +140,19 @@ public class OptGroup extends Component {
|
||||
public void setListValue(String listValue) {
|
||||
internalUiBean.setListValue(listValue);
|
||||
}
|
||||
|
||||
@StrutsTagAttribute(description = "Property of list objects to get css class from")
|
||||
public void setListCssClass(String listCssClass) {
|
||||
internalUiBean.setListCssClass(listCssClass);
|
||||
}
|
||||
|
||||
@StrutsTagAttribute(description = "Property of list objects to get css style from")
|
||||
public void setListCssStyle(String listCssStyle) {
|
||||
internalUiBean.setListCssStyle(listCssStyle);
|
||||
}
|
||||
|
||||
@StrutsTagAttribute(description = "Property of list objects to get title from")
|
||||
public void setListTitle(String listTitle) {
|
||||
internalUiBean.setListTitle(listTitle);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -31,8 +31,7 @@ import com.opensymphony.xwork2.util.ValueStack;
|
||||
* complex expression and then simply reference that variable each time rather than the complex expression. This is
|
||||
* useful in both cases: when the complex expression takes time (performance improvement) or is hard to read (code
|
||||
* readability improvement).</p>
|
||||
* <p>If the tag is used with body content, the evaluation of the value parameter is omitted. Instead, the String to
|
||||
* which the body evaluates is set as value for the scoped variable.</p>
|
||||
* <p>If the value parameter is omitted, the String to which the body evaluates is set as value for the scoped variable.</p>
|
||||
*
|
||||
* <p>The scopes available are as follows:</p>
|
||||
* <ul>
|
||||
@@ -83,6 +82,7 @@ import com.opensymphony.xwork2.util.ValueStack;
|
||||
public class Set extends ContextBean {
|
||||
protected String scope;
|
||||
protected String value;
|
||||
protected boolean trimBody = true;
|
||||
|
||||
public Set(ValueStack stack) {
|
||||
super(stack);
|
||||
@@ -93,10 +93,10 @@ public class Set extends ContextBean {
|
||||
|
||||
Object o;
|
||||
if (value == null) {
|
||||
if (body != null && !body.equals("")) {
|
||||
o = body;
|
||||
} else {
|
||||
if (body == null) {
|
||||
o = findValue("top");
|
||||
} else {
|
||||
o = body;
|
||||
}
|
||||
} else {
|
||||
o = findValue(value);
|
||||
@@ -136,6 +136,11 @@ public class Set extends ContextBean {
|
||||
this.value = value;
|
||||
}
|
||||
|
||||
@StrutsTagAttribute(description="Set to false to prevent the default whitespace-trim of this tag's body content", type="Boolean", defaultValue="true")
|
||||
public void setTrimBody(boolean trimBody) {
|
||||
this.trimBody = trimBody;
|
||||
}
|
||||
|
||||
@Override
|
||||
public boolean usesBody() {
|
||||
return true;
|
||||
|
||||
@@ -97,6 +97,10 @@ public class DefaultDispatcherErrorHandler implements DispatcherErrorHandler {
|
||||
response.sendError(code, e.getMessage());
|
||||
} catch (IOException e1) {
|
||||
// we're already sending an error, not much else we can do if more stuff breaks
|
||||
LOG.warn("Unable to send error response, code: {};", code, e1);
|
||||
} catch (IllegalStateException ise) {
|
||||
// Log illegalstate instead of passing unrecoverable exception to calling thread
|
||||
LOG.warn("Unable to send error response, code: {}; isCommited: {};", code, response.isCommitted(), ise);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -122,6 +126,10 @@ public class DefaultDispatcherErrorHandler implements DispatcherErrorHandler {
|
||||
response.sendError(code, "Unable to show problem report:\n" + exp + "\n\n" + LocationUtils.getLocation(exp));
|
||||
} catch (IOException ex) {
|
||||
// we're already sending an error, not much else we can do if more stuff breaks
|
||||
LOG.warn("Unable to send error response, code: {};", code, ex);
|
||||
} catch (IllegalStateException ise) {
|
||||
// Log illegalstate instead of passing unrecoverable exception to calling thread
|
||||
LOG.warn("Unable to send error response, code: {}; isCommited: {};", code, response.isCommitted(), ise);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -218,7 +218,15 @@ public class DefaultStaticContentLoader implements StaticContentLoader {
|
||||
}
|
||||
}
|
||||
|
||||
response.sendError(HttpServletResponse.SC_NOT_FOUND);
|
||||
try {
|
||||
response.sendError(HttpServletResponse.SC_NOT_FOUND);
|
||||
} catch (IOException e1) {
|
||||
// we're already sending an error, not much else we can do if more stuff breaks
|
||||
LOG.warn("Unable to send error response, code: {};", HttpServletResponse.SC_NOT_FOUND, e1);
|
||||
} catch (IllegalStateException ise) {
|
||||
// Log illegalstate instead of passing unrecoverable exception to calling thread
|
||||
LOG.warn("Unable to send error response, code: {}; isCommited: {};", HttpServletResponse.SC_NOT_FOUND, response.isCommitted(), ise);
|
||||
}
|
||||
}
|
||||
|
||||
protected void process(InputStream is, String path, HttpServletRequest request, HttpServletResponse response) throws IOException {
|
||||
|
||||
@@ -85,7 +85,7 @@ public class Dispatcher {
|
||||
*/
|
||||
public static final String REQUEST_POST_METHOD = "POST";
|
||||
|
||||
public static final String MULTIPART_FORM_DATA_REGEX = "^multipart/form-data(; boundary=[0-9a-zA-Z'()+_,\\-./:=?]{1,70})?(;charset=[a-zA-Z\\-0-9]{3,14})?";
|
||||
public static final String MULTIPART_FORM_DATA_REGEX = "^multipart/form-data(?:\\s*;\\s*boundary=[0-9a-zA-Z'()+_,\\-./:=?]{1,70})?(?:\\s*;\\s*charset=[a-zA-Z\\-0-9]{3,14})?";
|
||||
|
||||
/**
|
||||
* Provide a thread local instance.
|
||||
@@ -582,8 +582,10 @@ public class Dispatcher {
|
||||
logConfigurationException(request, e);
|
||||
sendError(request, response, HttpServletResponse.SC_NOT_FOUND, e);
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
if (handleException || devMode) {
|
||||
if (devMode) {
|
||||
LOG.debug("Dispatcher serviceAction failed", e);
|
||||
}
|
||||
sendError(request, response, HttpServletResponse.SC_INTERNAL_SERVER_ERROR, e);
|
||||
} else {
|
||||
throw new ServletException(e);
|
||||
@@ -694,12 +696,23 @@ public class Dispatcher {
|
||||
try {
|
||||
locale = LocaleUtils.toLocale(defaultLocale);
|
||||
} catch (IllegalArgumentException e) {
|
||||
LOG.warn(new ParameterizedMessage("Cannot convert 'struts.locale' = [{}] to proper locale, defaulting to request locale [{}]",
|
||||
defaultLocale, request.getLocale()), e);
|
||||
locale = request.getLocale();
|
||||
try {
|
||||
locale = request.getLocale();
|
||||
LOG.warn(new ParameterizedMessage("Cannot convert 'struts.locale' = [{}] to proper locale, defaulting to request locale [{}]",
|
||||
defaultLocale, locale), e);
|
||||
} catch (RuntimeException rex) {
|
||||
LOG.warn(new ParameterizedMessage("Cannot convert 'struts.locale' = [{}] to proper locale, and cannot get locale from HTTP Request, falling back to system default locale",
|
||||
defaultLocale), rex);
|
||||
locale = Locale.getDefault();
|
||||
}
|
||||
}
|
||||
} else {
|
||||
locale = request.getLocale();
|
||||
try {
|
||||
locale = request.getLocale();
|
||||
} catch (RuntimeException rex) {
|
||||
LOG.warn("Cannot get locale from HTTP Request, falling back to system default locale", rex);
|
||||
locale = Locale.getDefault();
|
||||
}
|
||||
}
|
||||
return locale;
|
||||
}
|
||||
|
||||
@@ -197,5 +197,28 @@ public class HttpParameters implements Map<String, Parameter>, Cloneable {
|
||||
|
||||
return new HttpParameters(parameters);
|
||||
}
|
||||
|
||||
/**
|
||||
* Alternate Builder method which avoids wrapping any parameters that are already
|
||||
* a {@link Parameter} element within another {@link Parameter} wrapper.
|
||||
*
|
||||
* @return
|
||||
*/
|
||||
public HttpParameters buildNoNestedWrapping() {
|
||||
Map<String, Parameter> parameters = (parent == null)
|
||||
? new HashMap<String, Parameter>()
|
||||
: new HashMap<>(parent.parameters);
|
||||
|
||||
for (Map.Entry<String, Object> entry : requestParameterMap.entrySet()) {
|
||||
String name = entry.getKey();
|
||||
Object value = entry.getValue();
|
||||
Parameter parameterValue = (value instanceof Parameter)
|
||||
? (Parameter) value
|
||||
: new Parameter.Request(name, value);
|
||||
parameters.put(name, parameterValue);
|
||||
}
|
||||
|
||||
return new HttpParameters(parameters);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -31,7 +31,6 @@ import org.apache.logging.log4j.Logger;
|
||||
import org.apache.struts2.RequestUtils;
|
||||
import org.apache.struts2.ServletActionContext;
|
||||
import org.apache.struts2.StrutsConstants;
|
||||
import org.apache.struts2.StrutsException;
|
||||
import org.apache.struts2.util.PrefixTrie;
|
||||
|
||||
import javax.servlet.http.HttpServletRequest;
|
||||
@@ -117,6 +116,10 @@ public class DefaultActionMapper implements ActionMapper {
|
||||
protected boolean allowSlashesInActionNames = false;
|
||||
protected boolean alwaysSelectFullNamespace = false;
|
||||
protected PrefixTrie prefixTrie = null;
|
||||
|
||||
protected Pattern allowedNamespaceNames = Pattern.compile("[a-zA-Z0-9._/\\-]*");
|
||||
protected String defaultNamespaceName = "/";
|
||||
|
||||
protected Pattern allowedActionNames = Pattern.compile("[a-zA-Z0-9._!/\\-]*");
|
||||
protected String defaultActionName = "index";
|
||||
|
||||
@@ -202,6 +205,16 @@ public class DefaultActionMapper implements ActionMapper {
|
||||
this.alwaysSelectFullNamespace = BooleanUtils.toBoolean(alwaysSelectFullNamespace);
|
||||
}
|
||||
|
||||
@Inject(value = StrutsConstants.STRUTS_ALLOWED_NAMESPACE_NAMES, required = false)
|
||||
public void setAllowedNamespaceNames(String allowedNamespaceNames) {
|
||||
this.allowedNamespaceNames = Pattern.compile(allowedNamespaceNames);
|
||||
}
|
||||
|
||||
@Inject(value = StrutsConstants.STRUTS_DEFAULT_NAMESPACE_NAME, required = false)
|
||||
public void setDefaultNamespaceName(String defaultNamespaceName) {
|
||||
this.defaultNamespaceName = defaultNamespaceName;
|
||||
}
|
||||
|
||||
@Inject(value = StrutsConstants.STRUTS_ALLOWED_ACTION_NAMES, required = false)
|
||||
public void setAllowedActionNames(String allowedActionNames) {
|
||||
this.allowedActionNames = Pattern.compile(allowedActionNames);
|
||||
@@ -389,10 +402,28 @@ public class DefaultActionMapper implements ActionMapper {
|
||||
}
|
||||
}
|
||||
|
||||
mapping.setNamespace(namespace);
|
||||
mapping.setNamespace(cleanupNamespaceName(namespace));
|
||||
mapping.setName(cleanupActionName(name));
|
||||
}
|
||||
|
||||
/**
|
||||
* Checks namespace name against allowed pattern if not matched returns default namespace
|
||||
*
|
||||
* @param rawNamespace name extracted from URI
|
||||
* @return safe namespace name
|
||||
*/
|
||||
protected String cleanupNamespaceName(final String rawNamespace) {
|
||||
if (allowedNamespaceNames.matcher(rawNamespace).matches()) {
|
||||
return rawNamespace;
|
||||
} else {
|
||||
LOG.warn(
|
||||
"{} did not match allowed namespace names {} - default namespace {} will be used!",
|
||||
rawNamespace, allowedNamespaceNames, defaultNamespaceName
|
||||
);
|
||||
return defaultNamespaceName;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Checks action name against allowed pattern if not matched returns default action name
|
||||
*
|
||||
|
||||
+8
-8
@@ -74,6 +74,8 @@ import java.util.Map;
|
||||
public class ActionMappingParametersInterceptor extends ParametersInterceptor {
|
||||
|
||||
/**
|
||||
* Get the parameter map from ActionMapping associated with the provided ActionContext.
|
||||
*
|
||||
* @param ac The action context
|
||||
* @return the parameters from the action mapping in the context. If none found, returns an empty map.
|
||||
*/
|
||||
@@ -81,27 +83,25 @@ public class ActionMappingParametersInterceptor extends ParametersInterceptor {
|
||||
protected HttpParameters retrieveParameters(ActionContext ac) {
|
||||
ActionMapping mapping = (ActionMapping) ac.get(ServletActionContext.ACTION_MAPPING);
|
||||
if (mapping != null) {
|
||||
return HttpParameters.create(mapping.getParams()).build();
|
||||
return HttpParameters.create(mapping.getParams()).buildNoNestedWrapping();
|
||||
} else {
|
||||
return HttpParameters.create().build();
|
||||
return HttpParameters.create().buildNoNestedWrapping();
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Adds the parameters into context's ParameterMap
|
||||
* Adds the parameters into the current ActionContext's parameter map.
|
||||
*
|
||||
* Note: The method should avoid re-wrapping values which are already of type Parameter.
|
||||
*
|
||||
* @param ac The action context
|
||||
* @param newParams The parameter map to apply
|
||||
* <p>
|
||||
* In this class this is a no-op, since the parameters were fetched from the same location.
|
||||
* In subclasses both retrieveParameters() and addParametersToContext() should be overridden.
|
||||
* </p>
|
||||
*/
|
||||
@Override
|
||||
protected void addParametersToContext(ActionContext ac, Map<String, ?> newParams) {
|
||||
HttpParameters previousParams = ac.getParameters();
|
||||
HttpParameters.Builder combinedParams = HttpParameters.create().withParent(previousParams).withExtraParams(newParams);
|
||||
|
||||
ac.setParameters(combinedParams.build());
|
||||
ac.setParameters(combinedParams.buildNoNestedWrapping());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -261,6 +261,7 @@ public class I18nInterceptor extends AbstractInterceptor {
|
||||
super(invocation);
|
||||
}
|
||||
|
||||
@Override
|
||||
public Locale find() {
|
||||
Locale requestOnlyLocale = super.find();
|
||||
|
||||
@@ -281,15 +282,13 @@ public class I18nInterceptor extends AbstractInterceptor {
|
||||
|
||||
@Override
|
||||
public Locale store(ActionInvocation invocation, Locale locale) {
|
||||
HttpSession session = ServletActionContext.getRequest().getSession(false);
|
||||
Map<String, Object> session = invocation.getInvocationContext().getSession();
|
||||
|
||||
if (session != null) {
|
||||
String sessionId = session.getId();
|
||||
String sessionId = ServletActionContext.getRequest().getSession().getId();
|
||||
synchronized (sessionId.intern()) {
|
||||
invocation.getInvocationContext().getSession().put(attributeName, locale);
|
||||
session.put(attributeName, locale);
|
||||
}
|
||||
} else {
|
||||
LOG.debug("session creation avoided as it doesn't exist already");
|
||||
}
|
||||
|
||||
return locale;
|
||||
|
||||
@@ -29,7 +29,7 @@ import java.util.Map;
|
||||
/**
|
||||
* Just as the CheckboxInterceptor checks that if only the hidden field is present, so too does this interceptor. If
|
||||
* the "__multiselect_" request parameter is present and its visible counterpart is not, set a new request parameter to an
|
||||
* empty Sting.
|
||||
* empty String.
|
||||
*/
|
||||
public class MultiselectInterceptor extends AbstractInterceptor {
|
||||
private static final long serialVersionUID = 1L;
|
||||
@@ -37,7 +37,7 @@ public class MultiselectInterceptor extends AbstractInterceptor {
|
||||
/**
|
||||
* Just as the CheckboxInterceptor checks that if only the hidden field is present, so too does this interceptor.
|
||||
* If the "__multiselect_" request parameter is present and its visible counterpart is not, set a new request parameter
|
||||
* to an empty Sting.
|
||||
* to an empty String.
|
||||
*
|
||||
* @param ai ActionInvocation
|
||||
* @return the result of the action
|
||||
|
||||
+28
-4
@@ -112,6 +112,20 @@ public class TokenSessionStoreInterceptor extends TokenInterceptor {
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Handles processing of invalid tokens. If a previously stored invocation is
|
||||
* available, the method will attempt to return and render its result. Otherwise
|
||||
* it will return INVALID_TOKEN_CODE.
|
||||
*
|
||||
* Note: Because a stored (previously completed) invocation's PageContext will be closed,
|
||||
* this method must replace the stored PageContext with the current invocation's one (or a null).
|
||||
* See {@link org.apache.struts2.util.InvocationSessionStore#loadInvocation(String key, String token)} for details.
|
||||
*
|
||||
* @param invocation
|
||||
*
|
||||
* @return
|
||||
* @throws Exception
|
||||
*/
|
||||
@Override
|
||||
protected String handleInvalidToken(ActionInvocation invocation) throws Exception {
|
||||
ActionContext ac = invocation.getInvocationContext();
|
||||
@@ -126,11 +140,11 @@ public class TokenSessionStoreInterceptor extends TokenInterceptor {
|
||||
params.remove(tokenName);
|
||||
params.remove(TokenHelper.TOKEN_NAME_FIELD);
|
||||
|
||||
String sessionTokenName = TokenHelper.buildTokenSessionAttributeName(tokenName);
|
||||
String sessionTokenName = TokenHelper.buildTokenSessionAttributeName(tokenName);
|
||||
ActionInvocation savedInvocation = InvocationSessionStore.loadInvocation(sessionTokenName, token);
|
||||
|
||||
if (savedInvocation != null) {
|
||||
// set the valuestack to the request scope
|
||||
// set the savedInvocation's valuestack to the request scope
|
||||
ValueStack stack = savedInvocation.getStack();
|
||||
request.setAttribute(ServletActionContext.STRUTS_VALUESTACK_KEY, stack);
|
||||
|
||||
@@ -153,13 +167,23 @@ public class TokenSessionStoreInterceptor extends TokenInterceptor {
|
||||
return INVALID_TOKEN_CODE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Handles processing of valid tokens. Stores the current invocation for
|
||||
* later use by {@link handleInvalidToken}.
|
||||
* See {@link org.apache.struts2.util.InvocationSessionStore#storeInvocation(String key, String token, ActionInvocation invocation)} for details.
|
||||
*
|
||||
* @param invocation
|
||||
*
|
||||
* @return
|
||||
* @throws Exception
|
||||
*/
|
||||
@Override
|
||||
protected String handleValidToken(ActionInvocation invocation) throws Exception {
|
||||
// we know the token name and token must be there
|
||||
String key = TokenHelper.getTokenName();
|
||||
String token = TokenHelper.getToken(key);
|
||||
String sessionTokenName = TokenHelper.buildTokenSessionAttributeName(key);
|
||||
InvocationSessionStore.storeInvocation(sessionTokenName, token, invocation);
|
||||
String sessionTokenName = TokenHelper.buildTokenSessionAttributeName(key);
|
||||
InvocationSessionStore.storeInvocation(sessionTokenName, token, invocation);
|
||||
|
||||
return invocation.invoke();
|
||||
}
|
||||
|
||||
@@ -134,6 +134,7 @@ public class PostbackResult extends StrutsResultSupport {
|
||||
|
||||
if (actionName != null) {
|
||||
actionName = conditionalParse(actionName, invocation);
|
||||
parseLocation = false;
|
||||
if (namespace == null) {
|
||||
namespace = invocation.getProxy().getNamespace();
|
||||
} else {
|
||||
|
||||
@@ -159,6 +159,7 @@ public class ServletActionRedirectResult extends ServletRedirectResult implement
|
||||
*/
|
||||
public void execute(ActionInvocation invocation) throws Exception {
|
||||
actionName = conditionalParse(actionName, invocation);
|
||||
parseLocation = false;
|
||||
if (namespace == null) {
|
||||
namespace = invocation.getProxy().getNamespace();
|
||||
} else {
|
||||
|
||||
@@ -250,13 +250,24 @@ public class ServletRedirectResult extends StrutsResultSupport implements Reflec
|
||||
* @throws IOException in case of IO errors
|
||||
*/
|
||||
protected void sendRedirect(HttpServletResponse response, String finalLocation) throws IOException {
|
||||
if (SC_FOUND == statusCode) {
|
||||
response.sendRedirect(finalLocation);
|
||||
} else {
|
||||
response.setStatus(statusCode);
|
||||
response.setHeader("Location", finalLocation);
|
||||
response.getWriter().write(finalLocation);
|
||||
response.getWriter().close();
|
||||
try {
|
||||
if (SC_FOUND == statusCode) {
|
||||
response.sendRedirect(finalLocation);
|
||||
} else {
|
||||
response.setStatus(statusCode);
|
||||
response.setHeader("Location", finalLocation);
|
||||
try {
|
||||
response.getWriter().write(finalLocation);
|
||||
} finally {
|
||||
response.getWriter().close();
|
||||
}
|
||||
}
|
||||
} catch (IOException ioe) {
|
||||
LOG.warn("Unable to redirect to: {}, code: {}; {}", finalLocation, statusCode, ioe);
|
||||
throw ioe; // Re-throw required to preserve existing default behaviour (no stacktrace in above warn for this reason)
|
||||
} catch (IllegalStateException ise) {
|
||||
LOG.warn("Unable to redirect to: {}, code: {}; isCommited: {}; {}", finalLocation, statusCode, response.isCommitted(), ise);
|
||||
throw ise; // Re-throw required to preserve existing default behaviour (no stacktrace in above warn for this reason)
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -122,6 +122,8 @@ public abstract class StrutsResultSupport implements Result, StrutsStatics {
|
||||
/** use UTF-8 as this is the recommended encoding by W3C to avoid incompatibilities. */
|
||||
public static final String DEFAULT_URL_ENCODING = "UTF-8";
|
||||
|
||||
protected boolean parseLocation = true;
|
||||
|
||||
private boolean parse;
|
||||
private boolean encode;
|
||||
private String location;
|
||||
@@ -200,7 +202,7 @@ public abstract class StrutsResultSupport implements Result, StrutsStatics {
|
||||
* @throws Exception if an error occurs while executing the result.
|
||||
*/
|
||||
public void execute(ActionInvocation invocation) throws Exception {
|
||||
lastFinalLocation = conditionalParse(location, invocation);
|
||||
lastFinalLocation = parseLocation ? conditionalParse(location, invocation) : location;
|
||||
doExecute(lastFinalLocation, invocation);
|
||||
}
|
||||
|
||||
|
||||
@@ -18,6 +18,9 @@
|
||||
*/
|
||||
package org.apache.struts2.util;
|
||||
|
||||
import org.apache.logging.log4j.LogManager;
|
||||
import org.apache.logging.log4j.Logger;
|
||||
|
||||
import javax.servlet.jsp.JspWriter;
|
||||
import java.io.*;
|
||||
import java.nio.ByteBuffer;
|
||||
@@ -35,6 +38,9 @@ import java.util.LinkedList;
|
||||
*
|
||||
*/
|
||||
public class FastByteArrayOutputStream extends OutputStream {
|
||||
|
||||
private static final Logger LOG = LogManager.getLogger(FastByteArrayOutputStream.class);
|
||||
|
||||
private static final int DEFAULT_BLOCK_SIZE = 8192;
|
||||
|
||||
private LinkedList<byte[]> buffers;
|
||||
@@ -144,7 +150,7 @@ public class FastByteArrayOutputStream extends OutputStream {
|
||||
// Append bytes to current buffer
|
||||
// Previous data maybe partially decoded, this part will appended to previous
|
||||
in.put(bytes, 0, length);
|
||||
// To begin of data
|
||||
// To begin processing of data
|
||||
in.flip();
|
||||
decodeAndWriteBuffered(writer, in, out, decoder, endOfInput);
|
||||
}
|
||||
@@ -158,7 +164,7 @@ public class FastByteArrayOutputStream extends OutputStream {
|
||||
if (in.hasRemaining()) {
|
||||
// Move remaining to top of buffer
|
||||
in.compact();
|
||||
if (result.isOverflow() && !result.isError() && !result.isMalformed()) {
|
||||
if (result.isOverflow() && !result.isError()) { // isError covers isMalformed and isUnmappable
|
||||
// Not all buffer chars decoded, spin it again
|
||||
// Set to begin
|
||||
in.flip();
|
||||
@@ -167,16 +173,24 @@ public class FastByteArrayOutputStream extends OutputStream {
|
||||
// Clean up buffer
|
||||
in.clear();
|
||||
}
|
||||
} while (in.hasRemaining() && result.isOverflow() && !result.isError() && !result.isMalformed());
|
||||
} while (in.hasRemaining() && result.isOverflow() && !result.isError()); // isError covers isMalformed and isUnmappable
|
||||
|
||||
if (result.isError()) {
|
||||
if (LOG.isWarnEnabled()) {
|
||||
// Provide a log warning when the decoding fails (prior to 2.5.19 it failed silently).
|
||||
// Note: Set FastByteArrayOutputStream's Logger level to error or higher to suppress this log warning.
|
||||
LOG.warn("Buffer decoding-in-to-out [{}] failed, coderResult [{}]", decoder.charset().name(), result.toString());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private static CoderResult decodeAndWrite(Writer writer, ByteBuffer in, CharBuffer out, CharsetDecoder decoder, boolean endOfInput) throws IOException {
|
||||
CoderResult result = decoder.decode(in, out, endOfInput);
|
||||
// To begin of decoded data
|
||||
// To begin processing of decoded data
|
||||
out.flip();
|
||||
// Output
|
||||
writer.write(out.toString());
|
||||
// clear output to avoid infinitive loops, see WW-4383
|
||||
// Clear output to avoid infinite loops, see WW-4383
|
||||
out.clear();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -20,6 +20,7 @@ package org.apache.struts2.util;
|
||||
|
||||
import com.opensymphony.xwork2.ActionContext;
|
||||
import com.opensymphony.xwork2.ActionInvocation;
|
||||
import org.apache.struts2.ServletActionContext;
|
||||
|
||||
import java.io.Serializable;
|
||||
import java.util.HashMap;
|
||||
@@ -55,11 +56,20 @@ public class InvocationSessionStore {
|
||||
return null;
|
||||
}
|
||||
|
||||
ActionInvocation savedInvocation = null;
|
||||
if (invocationContext.invocation != null) {
|
||||
savedInvocation = invocationContext.invocation;
|
||||
ActionContext.setContext(savedInvocation.getInvocationContext());
|
||||
ActionContext.getContext().setValueStack(savedInvocation.getStack());
|
||||
final ActionInvocation savedInvocation = invocationContext.invocation;
|
||||
if (savedInvocation != null) {
|
||||
// WW-5026 - Preserve the previous PageContext (even if null) and restore it to the
|
||||
// ActionContext after loading the savedInvocation context. The saved context's PageContext
|
||||
// would already be closed at this point (causing failures if used for output).
|
||||
final ActionContext savedActionContext = savedInvocation.getInvocationContext();
|
||||
final ActionContext previousActionContext = ActionContext.getContext();
|
||||
ActionContext.setContext(savedActionContext);
|
||||
savedActionContext.setValueStack(savedInvocation.getStack());
|
||||
if (previousActionContext != null) {
|
||||
savedActionContext.put(ServletActionContext.PAGE_CONTEXT, previousActionContext.get(ServletActionContext.PAGE_CONTEXT));
|
||||
} else {
|
||||
savedActionContext.put(ServletActionContext.PAGE_CONTEXT, null);
|
||||
}
|
||||
}
|
||||
|
||||
return savedInvocation;
|
||||
|
||||
@@ -81,7 +81,7 @@ public class JBossFileManager extends DefaultFileManager {
|
||||
|
||||
@Override
|
||||
public void monitorFile(URL fileUrl) {
|
||||
if (isJBossUrl(fileUrl)) {
|
||||
if (reloadingConfigs && isJBossUrl(fileUrl)) {
|
||||
String fileName = fileUrl.toString();
|
||||
LOG.debug("Creating revision for URL: {}", fileName);
|
||||
URL normalizedUrl = normalizeToFileProtocol(fileUrl);
|
||||
|
||||
@@ -35,6 +35,7 @@ public class SetTag extends ContextBeanTag {
|
||||
|
||||
protected String scope;
|
||||
protected String value;
|
||||
protected boolean trimBody = true;
|
||||
|
||||
public Component getBean(ValueStack stack, HttpServletRequest req, HttpServletResponse res) {
|
||||
return new Set(stack);
|
||||
@@ -59,4 +60,21 @@ public class SetTag extends ContextBeanTag {
|
||||
public void setValue(String value) {
|
||||
this.value = value;
|
||||
}
|
||||
|
||||
public void setTrimBody(boolean trimBody) {
|
||||
this.trimBody = trimBody;
|
||||
}
|
||||
|
||||
@Override
|
||||
protected String getBody() {
|
||||
if (trimBody) {
|
||||
if (bodyContent == null) {
|
||||
return null;
|
||||
} else {
|
||||
return bodyContent.getString().trim();
|
||||
}
|
||||
} else {
|
||||
return (bodyContent == null ? null : bodyContent.getString());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -23,12 +23,16 @@ import ognl.OgnlException;
|
||||
|
||||
import com.opensymphony.xwork2.inject.Inject;
|
||||
import com.opensymphony.xwork2.ognl.OgnlUtil;
|
||||
import org.apache.logging.log4j.LogManager;
|
||||
import org.apache.logging.log4j.Logger;
|
||||
|
||||
/**
|
||||
* FIXME: remove?
|
||||
*/
|
||||
public class OgnlTool {
|
||||
|
||||
private static final Logger LOG = LogManager.getLogger(OgnlTool.class);
|
||||
|
||||
private OgnlUtil ognlUtil;
|
||||
|
||||
public OgnlTool() {
|
||||
@@ -43,6 +47,9 @@ public class OgnlTool {
|
||||
try {
|
||||
return Ognl.getValue(ognlUtil.compile(expr), context);
|
||||
} catch (OgnlException e) {
|
||||
if (e.getReason() instanceof SecurityException) {
|
||||
LOG.warn("Could not evaluate this expression due to security constraints: [{}]", expr, e);
|
||||
}
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -36,6 +36,9 @@ public class OptGroupTag extends ComponentTagSupport {
|
||||
protected String disabled;
|
||||
protected String listKey;
|
||||
protected String listValue;
|
||||
protected String listCssClass;
|
||||
protected String listCssStyle;
|
||||
protected String listTitle;
|
||||
|
||||
public Component getBean(ValueStack stack, HttpServletRequest req, HttpServletResponse res) {
|
||||
return new OptGroup(stack, req, res);
|
||||
@@ -50,6 +53,9 @@ public class OptGroupTag extends ComponentTagSupport {
|
||||
optGroup.setDisabled(disabled);
|
||||
optGroup.setListKey(listKey);
|
||||
optGroup.setListValue(listValue);
|
||||
optGroup.setListCssClass(listCssClass);
|
||||
optGroup.setListCssStyle(listCssStyle);
|
||||
optGroup.setListTitle(listTitle);
|
||||
}
|
||||
|
||||
public void setList(String list) {
|
||||
@@ -71,4 +77,16 @@ public class OptGroupTag extends ComponentTagSupport {
|
||||
public void setListValue(String listValue) {
|
||||
this.listValue = listValue;
|
||||
}
|
||||
|
||||
public void setListCssClass(String listCssClass) {
|
||||
this.listCssClass = listCssClass;
|
||||
}
|
||||
|
||||
public void setListCssStyle(String listCssStyle) {
|
||||
this.listCssStyle = listCssStyle;
|
||||
}
|
||||
|
||||
public void setListTitle(String listTitle) {
|
||||
this.listTitle = listTitle;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -219,4 +219,15 @@ struts.ognl.enableExpressionCache=true
|
||||
### Indicates if Dispatcher should handle unexpected exceptions by calling sendError()
|
||||
### or simply rethrow it as a ServletException to allow future processing by other frameworks like Spring Security
|
||||
struts.handle.exception=true
|
||||
|
||||
### Applies maximum length allowed on OGNL expressions for security enhancement (optional)
|
||||
###
|
||||
### **WARNING**: If developers enable this option (by configuration) they should make sure that they understand the implications of setting
|
||||
### struts.ognl.expressionMaxLength. They must choose a value large enough to permit ALL valid OGNL expressions used within the application.
|
||||
### Values larger than the 200-400 range have diminishing security value (at which point it is really only a "style guard" for long OGNL
|
||||
### expressions in an application. Setting a value of null or "" will also disable the feature.
|
||||
###
|
||||
### NOTE: The sample line below is *INTENTIONALLY* commented out, as this feature is disabled by default.
|
||||
# struts.ognl.expressionMaxLength=256
|
||||
|
||||
### END SNIPPET: complete_file
|
||||
|
||||
@@ -45,12 +45,7 @@
|
||||
java.lang.ClassLoader,
|
||||
java.lang.Shutdown,
|
||||
java.lang.ProcessBuilder,
|
||||
ognl.OgnlContext,
|
||||
ognl.ClassResolver,
|
||||
ognl.TypeConverter,
|
||||
ognl.MemberAccess,
|
||||
ognl.DefaultMemberAccess,
|
||||
com.opensymphony.xwork2.ognl.SecurityMemberAccess,
|
||||
sun.misc.Unsafe,
|
||||
com.opensymphony.xwork2.ActionContext" />
|
||||
|
||||
<!-- this must be valid regex, each '.' in package name must be escaped! -->
|
||||
@@ -60,15 +55,25 @@
|
||||
<!-- this is simpler version of the above used with string comparison -->
|
||||
<constant name="struts.excludedPackageNames"
|
||||
value="
|
||||
java.lang.,
|
||||
ognl.,
|
||||
javax,
|
||||
java.io.,
|
||||
java.net.,
|
||||
java.nio.,
|
||||
javax.,
|
||||
freemarker.core.,
|
||||
freemarker.template.,
|
||||
freemarker.ext.jsp.,
|
||||
freemarker.ext.rhino.,
|
||||
freemarker.ext.beans.,
|
||||
sun.misc.,
|
||||
sun.reflect.,
|
||||
javassist." />
|
||||
javassist.,
|
||||
org.apache.velocity.,
|
||||
org.objectweb.asm.,
|
||||
org.springframework.context.,
|
||||
com.opensymphony.xwork2.inject.,
|
||||
com.opensymphony.xwork2.ognl.,
|
||||
com.opensymphony.xwork2.security.,
|
||||
com.opensymphony.xwork2.util." />
|
||||
|
||||
<bean class="com.opensymphony.xwork2.ObjectFactory" name="struts"/>
|
||||
<bean type="com.opensymphony.xwork2.factory.ResultFactory" name="struts" class="org.apache.struts2.factory.StrutsResultFactory" />
|
||||
|
||||
@@ -21,27 +21,47 @@
|
||||
<#if parameters.optGroupInternalListUiBeanList??>
|
||||
<#assign optGroupInternalListUiBeans=parameters.optGroupInternalListUiBeanList />
|
||||
<#list optGroupInternalListUiBeans as optGroupInternalListUiBean>
|
||||
<optgroup
|
||||
<optgroup<#rt>
|
||||
<#if optGroupInternalListUiBean.parameters.label?has_content>
|
||||
label="${optGroupInternalListUiBean.parameters.label}"
|
||||
label="${optGroupInternalListUiBean.parameters.label}"<#rt>
|
||||
</#if>
|
||||
<#if optGroupInternalListUiBean.parameters.disabled!false>
|
||||
disabled="disabled"
|
||||
disabled="disabled"<#rt>
|
||||
</#if>
|
||||
<#include "/${parameters.templateDir}/${parameters.expandTheme}/dynamic-attributes.ftl" />
|
||||
>
|
||||
|
||||
<#list optGroupInternalListUiBean.parameters.list as optGroupBean>
|
||||
<#assign trash=stack.push(optGroupBean) />
|
||||
<#assign tmpKey=stack.findValue(optGroupInternalListUiBean.parameters.listKey) />
|
||||
<#assign tmpValue=stack.findValue(optGroupInternalListUiBean.parameters.listValue) />
|
||||
<#assign tmpKeyStr = tmpKey.toString() />
|
||||
<option value="${tmpKeyStr?html}"
|
||||
<#if tag.contains(parameters.nameValue, tmpKey) == true>
|
||||
selected="selected"
|
||||
<#assign optGroupItemCssClass = ''/>
|
||||
<#if optGroupInternalListUiBean.parameters.listCssClass??>
|
||||
<#assign optGroupItemCssClass= stack.findString(optGroupInternalListUiBean.parameters.listCssClass)!''/>
|
||||
</#if>
|
||||
>${tmpValue?html}
|
||||
</option>
|
||||
<#assign optGroupItemCssStyle = ''/>
|
||||
<#if optGroupInternalListUiBean.parameters.listCssStyle??>
|
||||
<#assign optGroupItemCssStyle= stack.findString(optGroupInternalListUiBean.parameters.listCssStyle)!''/>
|
||||
</#if>
|
||||
<#assign optGroupItemTitle = ''/>
|
||||
<#if optGroupInternalListUiBean.parameters.listTitle??>
|
||||
<#assign optGroupItemTitle= stack.findString(optGroupInternalListUiBean.parameters.listTitle)!''/>
|
||||
</#if>
|
||||
<option value="${tmpKeyStr?html}"<#rt>
|
||||
<#if tag.contains(parameters.nameValue, tmpKey) == true>
|
||||
selected="selected"<#rt>
|
||||
</#if>
|
||||
<#if optGroupItemCssClass?has_content>
|
||||
class="${optGroupItemCssClass?html}"<#rt/>
|
||||
</#if>
|
||||
<#if optGroupItemCssStyle?has_content>
|
||||
style="${optGroupItemCssStyle?html}"<#rt/>
|
||||
</#if>
|
||||
<#if optGroupItemTitle?has_content>
|
||||
title="${optGroupItemTitle?html}"<#rt/>
|
||||
</#if>
|
||||
>${tmpValue?html}<#t>
|
||||
</option><#lt>
|
||||
<#assign trash=stack.pop() />
|
||||
</#list>
|
||||
</optgroup>
|
||||
|
||||
@@ -29,9 +29,12 @@
|
||||
<#if parameters.listValueKey??>
|
||||
<#-- checks the valueStack for the 'valueKey.' The valueKey is then looked-up in the locale
|
||||
file for it's localized value. This is then used as a label -->
|
||||
<#assign itemValue = stack.findString(parameters.listValueKey)/>
|
||||
<#-- FIXME: find a better way to get the value than a call to @s.text -->
|
||||
<#assign itemValue><@s.text name="${itemValue}"/></#assign>
|
||||
<#assign valueKey = stack.findString(parameters.listValueKey)!''/>
|
||||
<#if valueKey?has_content>
|
||||
<#assign itemValue = struts.getText(valueKey) />
|
||||
<#else>
|
||||
<#assign itemValue = parameters.listValueKey />
|
||||
</#if>
|
||||
<#elseif parameters.listValue??>
|
||||
<#assign itemValue = stack.findString(parameters.listValue)/>
|
||||
<#else>
|
||||
|
||||
@@ -70,8 +70,8 @@
|
||||
<#if parameters.listValueKey??>
|
||||
<#-- checks the valueStack for the 'valueKey.' The valueKey is then looked-up in the locale file for it's
|
||||
localized value. This is then used as a label -->
|
||||
<#assign valueKey = stack.findString(parameters.listValueKey) />
|
||||
<#if valueKey??>
|
||||
<#assign valueKey = stack.findString(parameters.listValueKey)!'' />
|
||||
<#if valueKey?has_content>
|
||||
<#assign itemValue = struts.getText(valueKey) />
|
||||
<#else>
|
||||
<#assign itemValue = parameters.listValueKey />
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user