--- Chris Pratt <[EMAIL PROTECTED]> wrote: > Only if we allow the container to process the JSTL EL. If we turn the > container off and process the JSTL EL inside of the Struts tag > library, the security hole vanishes.
So does my ability to use ${narnar} inside a JSP page, no? That's not something I'm willing to give up after waiting so long for JSP 2.0 to finally allow one of the most common use-cases ever. Dave --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]