[ https://issues.apache.org/jira/browse/WW-5350?focusedWorklogId=890104&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-890104 ]
ASF GitHub Bot logged work on WW-5350: -------------------------------------- Author: ASF GitHub Bot Created on: 12/Nov/23 09:37 Start Date: 12/Nov/23 09:37 Worklog Time Spent: 10m Work Description: lukaszlenart commented on PR #781: URL: https://github.com/apache/struts/pull/781#issuecomment-1807072225 It would be good to document this new future to more visible to the users. Could you also add a section about this new _allow list_ [here](https://struts.apache.org/security/#internal-security-mechanism)? Issue Time Tracking ------------------- Worklog Id: (was: 890104) Time Spent: 2h 40m (was: 2.5h) > Implement optional strict class/package allowlist for OGNL > ---------------------------------------------------------- > > Key: WW-5350 > URL: https://issues.apache.org/jira/browse/WW-5350 > Project: Struts 2 > Issue Type: Improvement > Components: Core > Reporter: Kusal Kithul-Godage > Priority: Minor > Fix For: 6.4.0 > > Time Spent: 2h 40m > Remaining Estimate: 0h > > I think this will be more useful than WW-5345 -- This message was sent by Atlassian Jira (v8.20.10#820010)