This is an automated email from the ASF dual-hosted git repository.
asf-gitbox-commits pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/struts-site.git
The following commit(s) were added to refs/heads/asf-staging by this push:
new f43558b21 Updates stage by Jenkins
f43558b21 is described below
commit f43558b21140627b998c4c7e6715d9519553d82b
Author: jenkins <[email protected]>
AuthorDate: Sun Sep 13 08:31:43 2026 +0000
Updates stage by Jenkins
---
content/core-developers/csp-interceptor.html | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/content/core-developers/csp-interceptor.html
b/content/core-developers/csp-interceptor.html
index f3b3d6df1..b440e276b 100644
--- a/content/core-developers/csp-interceptor.html
+++ b/content/core-developers/csp-interceptor.html
@@ -204,11 +204,11 @@ deployments that do not want a session created for it:</p>
<p>Accepted values are <code class="language-plaintext
highlighter-rouge">session</code> (the default) and <code
class="language-plaintext highlighter-rouge">request</code>.</p>
<blockquote>
- <p>Note: releases before 6.12.0 and 7.4.0 shipped <code
class="language-plaintext highlighter-rouge">default.properties</code> with
this setting under the name
-<code class="language-plaintext
highlighter-rouge">struts.csp.nonceSource</code>, which the framework never
read — configuring it had no effect and the nonce always stayed
-in the session. Since 6.12.0 and 7.4.0 that name is honoured as well, so a
configuration carrying
-<code class="language-plaintext
highlighter-rouge">struts.csp.nonceSource=request</code> switches to
request-scoped nonces on upgrade. The camel-case name is deprecated
-and logs a warning; rename it to <code class="language-plaintext
highlighter-rouge">struts.csp.nonce.source</code>.</p>
+ <p>Note: releases before 7.4.0 shipped <code class="language-plaintext
highlighter-rouge">default.properties</code> with this setting under the name
<code class="language-plaintext
highlighter-rouge">struts.csp.nonceSource</code>,
+which the framework never read — configuring it had no effect and the nonce
always stayed in the session. Since
+7.4.0 that name is honoured as well, so a configuration carrying <code
class="language-plaintext
highlighter-rouge">struts.csp.nonceSource=request</code> switches to
+request-scoped nonces on upgrade. The camel-case name is deprecated and logs a
warning; rename it to
+<code class="language-plaintext
highlighter-rouge">struts.csp.nonce.source</code>.</p>
</blockquote>
<h2 id="report-action">Report action</h2>