[
https://issues.apache.org/jira/browse/WW-5368?focusedWorklogId=935910&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-935910
]
ASF GitHub Bot logged work on WW-5368:
--------------------------------------
Author: ASF GitHub Bot
Created on: 23/Sep/24 17:57
Start Date: 23/Sep/24 17:57
Worklog Time Spent: 10m
Work Description: lukaszlenart closed pull request #1059: [WW-5368] Fixes
checking nonce of invalidated session
URL: https://github.com/apache/struts/pull/1059
Issue Time Tracking
-------------------
Worklog Id: (was: 935910)
Time Spent: 20m (was: 10m)
> Access warning when get resource bundle which its name starts with "label"
> --------------------------------------------------------------------------
>
> Key: WW-5368
> URL: https://issues.apache.org/jira/browse/WW-5368
> Project: Struts 2
> Issue Type: Bug
> Components: Core
> Affects Versions: 6.3.0
> Reporter: Alireza Fattahi
> Priority: Critical
> Fix For: 6.7.0
>
> Time Spent: 20m
> Remaining Estimate: 0h
>
> The below:
> {code:java}
> <s:select name="reasonOfTransactionCode" list="reasonOfTransactionList"
> listKey="top" listValue="%{getText('label.reasonOfTransaction.'+top)}"/>
> {code}
> generates this warning for each item in the list, so if the
> `reasonOfTransactionList` has seven items I see this error seven time:
> {code:java}
> ognl.SecurityMemberAccess: Access to non-public [protected java.lang.String
> org.apache.struts2.components.UIBean.label] is blocked!
>
> {code}
>
> But this works fine If I just rename resource bundle and removes `label`
> from its name
>
> {code:java}
> <s:select name="reasonOfTransactionCode" list="reasonOfTransactionList"
> listKey="top" listValue="%{getText('reasonOfTransaction.'+top)}"/> {code}
--
This message was sent by Atlassian Jira
(v8.20.10#820010)