[
https://issues.apache.org/jira/browse/WW-5339?focusedWorklogId=895966&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-895966
]
ASF GitHub Bot logged work on WW-5339:
--------------------------------------
Author: ASF GitHub Bot
Created on: 17/Dec/23 14:59
Start Date: 17/Dec/23 14:59
Worklog Time Spent: 10m
Work Description: lukaszlenart commented on PR #806:
URL: https://github.com/apache/struts/pull/806#issuecomment-1859195214
Just tested the Showcase app and it doesn't look good ;-)
```
[WARN ] ognl.SecurityMemberAccess (SecurityMemberAccess.java:205) -
Declaring class [interface java.util.Map$Entry] of member type [public abstract
java.lang.Object java.util.Map$Entry.getKey()] is not allowlisted!
[WARN ] ognl.SecurityMemberAccess (SecurityMemberAccess.java:163) - Access
to non-public [final java.lang.Object java.util.HashMap$Node.key] is blocked!
[WARN ] ognl.SecurityMemberAccess (SecurityMemberAccess.java:163) - Access
to non-public [protected java.lang.String
org.apache.struts2.components.UIBean.key] is blocked!
[WARN ] ognl.SecurityMemberAccess (SecurityMemberAccess.java:205) -
Declaring class [interface java.util.Map$Entry] of member type [public abstract
java.lang.Object java.util.Map$Entry.getValue()] is not allowlisted!
[WARN ] ognl.SecurityMemberAccess (SecurityMemberAccess.java:163) - Access
to non-public [java.lang.Object java.util.HashMap$Node.value] is blocked!
[WARN ] ognl.SecurityMemberAccess (SecurityMemberAccess.java:163) - Access
to non-public [protected java.lang.String
org.apache.struts2.components.UIBean.value] is blocked!
...
```
Issue Time Tracking
-------------------
Worklog Id: (was: 895966)
Time Spent: 2h 50m (was: 2h 40m)
> Mitigate against custom class ASTMap node construction
> ------------------------------------------------------
>
> Key: WW-5339
> URL: https://issues.apache.org/jira/browse/WW-5339
> Project: Struts 2
> Issue Type: Improvement
> Components: Core
> Reporter: Kusal Kithul-Godage
> Priority: Minor
> Fix For: 6.4.0
>
> Time Spent: 2h 50m
> Remaining Estimate: 0h
>
> i.e. @<class_name>@{} syntax
--
This message was sent by Atlassian Jira
(v8.20.10#820010)