[ 
https://issues.apache.org/jira/browse/WW-5706?focusedWorklogId=1038662&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1038662
 ]

ASF GitHub Bot logged work on WW-5706:
--------------------------------------

                Author: ASF GitHub Bot
            Created on: 30/Aug/26 06:41
            Start Date: 30/Aug/26 06:41
    Worklog Time Spent: 10m 
      Work Description: lukaszlenart opened a new pull request, #1881:
URL: https://github.com/apache/struts/pull/1881

   6.x backport of #1880.
   
   `RestfulActionMapper` derived the action name directly from the request URI, 
whereas `DefaultActionMapper` normalizes and validates it through 
`cleanupActionName` against the `allowedActionNames` pattern. This change 
applies the same validation in `RestfulActionMapper` (honouring the 
`struts.allowed.action.names` and `struts.default.action.name` settings) so 
both mappers handle action names consistently. When the extracted name does not 
match the allowed pattern, the configured default action name is used and a 
warning is logged.
   
   `Restful2ActionMapper` already extends `DefaultActionMapper` and inherits 
this behaviour, so no change is needed there.
   
   Added regression tests covering both a rejected and an accepted action name.
   
   Fixes [WW-5706](https://issues.apache.org/jira/browse/WW-5706)
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)




Issue Time Tracking
-------------------

    Worklog Id:     (was: 1038662)
    Time Spent: 20m  (was: 10m)

> RestfulActionMapper does not apply the action name validation used by 
> DefaultActionMapper
> -----------------------------------------------------------------------------------------
>
>                 Key: WW-5706
>                 URL: https://issues.apache.org/jira/browse/WW-5706
>             Project: Struts 2
>          Issue Type: Bug
>            Reporter: Lukasz Lenart
>            Priority: Major
>             Fix For: 6.12.0, 7.4.0
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> {{RestfulActionMapper.getMapping()}} derives the action name directly from 
> the request URI ({{actionName = uri.substring(1, nextSlash)}}), whereas 
> {{DefaultActionMapper}} normalizes and validates the action name through 
> {{cleanupActionName}} against the {{allowedActionNames}} pattern.
> Align {{RestfulActionMapper}} with {{DefaultActionMapper}} so both apply the 
> same action-name handling.
> {{Restful2ActionMapper}} already extends {{DefaultActionMapper}} and inherits 
> this behaviour, so no change is needed there.
> Add a regression test covering the aligned handling.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to