I'm against to introduce this change in 2.5 branch. Users can relay on this behaviour and blocking possibility to allow modify them the excluded classes & packages can be a no-go for them.
Also this is totally against Struts philosophy to be flexible and configurable, with hardcoding those values and disallowing changing them by users we take control over they application and take responsibility over them. This is a huge blocker. Either we should leave it as is for now or add an option to allow modify the exclusions as mentioned in [WW-4807](https://issues.apache.org/jira/browse/WW-4807) [ Full content available at: https://github.com/apache/struts/pull/247 ] This message was relayed via gitbox.apache.org for [email protected]
