Kusal Kithul-Godage created WW-5268:
---------------------------------------

             Summary: Add configuration option to exempt classes from OGNL 
package exclusions
                 Key: WW-5268
                 URL: https://issues.apache.org/jira/browse/WW-5268
             Project: Struts 2
          Issue Type: Improvement
          Components: Core
            Reporter: Kusal Kithul-Godage


It is currently possible to exclude packages from OGNL evaluation using 
`struts.excludedPackageNamePatterns` and `struts.excludedPackageNames`.

There may exist a scenario where you wish to have certain packages 
excluded/blocklisted by default, but exempt specific classes from these 
packages that have been assessed to be safe.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to