[ 
https://issues.apache.org/jira/browse/WW-5682?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Lukasz Lenart updated WW-5682:
------------------------------
    Component/s: Core

> Remove the deprecated SecurityMemberAccess configuration setters
> ----------------------------------------------------------------
>
>                 Key: WW-5682
>                 URL: https://issues.apache.org/jira/browse/WW-5682
>             Project: Struts 2
>          Issue Type: Improvement
>          Components: Core
>            Reporter: Lukasz Lenart
>            Priority: Major
>             Fix For: 8.0.0
>
>
> WW-5675 moved all OGNL security configuration parsing into a 
> container-singleton bean, {{SecurityMemberAccessConfig}}. The configuration 
> setters on {{SecurityMemberAccess}} lost their {{@Inject}} annotations and 
> were deprecated rather than removed, so that existing subclasses and direct 
> callers keep compiling in the 7.4.0 minor release.
> They are annotated {{@Deprecated(since = "7.4.0", forRemoval = true)}}. This 
> ticket removes them.
> h2. Methods to remove
> All on {{org.apache.struts2.ognl.SecurityMemberAccess}}:
> * {{useAllowStaticFieldAccess}}
> * {{useExcludedClasses}}
> * {{useExcludedPackageNamePatterns}}
> * {{useExcludedPackageNames}}
> * {{useExcludedPackageExemptClasses}}
> * {{useEnforceAllowlistEnabled}}
> * {{useAllowlistClasses}}
> * {{useAllowlistPackageNames}}
> * {{useDisallowProxyObjectAccess}}
> * {{useDisallowProxyMemberAccess}}
> * {{useDisallowDefaultPackageAccess}}
> Do _not_ remove {{useAcceptProperties}} or {{useExcludeProperties}}. Those 
> carry per-request state set by {{ParametersInterceptor}} through the 
> {{MemberAccessValueStack}} interface, are not configuration, and are not 
> deprecated.
> h2. Why this is not trivial
> At the time of writing roughly 110 call sites across {{core}} and the 
> {{spring}} and {{cdi}} plugins call these setters directly, almost all in 
> tests, to construct a {{SecurityMemberAccess}} in a particular configuration 
> without going through a container. Removing the setters means migrating every 
> one of those to configure a {{SecurityMemberAccessConfig}} instead. That 
> migration is the bulk of the work, not the deletion.
> Two of them carry behaviour worth preserving in whatever replaces them:
> * {{useAllowStaticFieldAccess(false)}} has a side effect: it also adds 
> {{java.lang.Class}} to the excluded classes.
> * The excluded-set setters accumulate onto the current value rather than 
> assigning. That is what makes them commutative, which is what makes them safe 
> against the container's unspecified {{getDeclaredMethods()}} injection order.
> h2. Related
> * WW-5675 deprecated them, and its design document records the reasoning: 
> {{docs/superpowers/specs/2026-08-14-WW-5675-security-member-access-config-sharing-design.md}}
> * WW-5678 is the sibling 8.0.0 cleanup for the package-matching helper naming 
> and visibility in the same class. Worth doing in the same pass.
> * Also consider {{allowlistPackageNames}} on {{SecurityMemberAccess}}, which 
> became write-only in production code after WW-5675 and survives only because 
> tests read it reflectively.
> Blocked by WW-5675 landing first.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to