This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/struts-site.git


The following commit(s) were added to refs/heads/asf-site by this push:
     new 072cfd6b9 Automatic Site Publish by Buildbot
072cfd6b9 is described below

commit 072cfd6b92bb25e335738757f8067b35600356d4
Author: buildbot <[email protected]>
AuthorDate: Thu Sep 17 05:17:44 2026 +0000

    Automatic Site Publish by Buildbot
---
 output/plugins/tiles/index.html | 42 +++++++++++++++++++++++++++++++++++++++++
 1 file changed, 42 insertions(+)

diff --git a/output/plugins/tiles/index.html b/output/plugins/tiles/index.html
index a5dbe1781..620ec19b8 100644
--- a/output/plugins/tiles/index.html
+++ b/output/plugins/tiles/index.html
@@ -159,6 +159,7 @@
   <li><a href="#usage" id="markdown-toc-usage">Usage</a>    <ul>
       <li><a href="#accessing-struts-attributes" 
id="markdown-toc-accessing-struts-attributes">Accessing Struts 
attributes</a></li>
       <li><a href="#i18n" id="markdown-toc-i18n">I18N</a></li>
+      <li><a href="#legacy-ognl-expressions" 
id="markdown-toc-legacy-ognl-expressions">Legacy OGNL expressions</a></li>
     </ul>
   </li>
   <li><a href="#example" id="markdown-toc-example">Example</a></li>
@@ -290,6 +291,28 @@ you can use <code class="language-plaintext 
highlighter-rouge">I18N</code> prefi
 <span class="nt">&lt;/definition&gt;</span>
 </code></pre></div></div>
 
+<h3 id="legacy-ognl-expressions">Legacy OGNL expressions</h3>
+
+<p>The plugin also registers the <code class="language-plaintext 
highlighter-rouge">OGNL</code> prefix, which comes from Tiles itself. Unlike 
<code class="language-plaintext highlighter-rouge">S2</code>, it evaluates the 
expression
+against the Tiles request rather than the <code class="language-plaintext 
highlighter-rouge">ValueStack</code>, and it does not pass through the Struts 
OGNL controls — the
+member access policy, the allowlist and the expression guard that every other 
OGNL evaluation in Struts goes through.</p>
+
+<p>As from Struts 7.4.0 the <code class="language-plaintext 
highlighter-rouge">OGNL</code> prefix is disabled by default. Evaluating an 
<code class="language-plaintext highlighter-rouge">OGNL:</code> expression 
fails with an
+<code class="language-plaintext highlighter-rouge">EvaluationException</code> 
explaining that the evaluator is disabled, so a definition that still relies on 
it is reported
+instead of rendering incorrectly. Migrate such expressions to <code 
class="language-plaintext highlighter-rouge">S2:</code>, which is evaluated by 
Struts with the full set of OGNL
+controls, or to ordinary Tiles attributes.</p>
+
+<p>If a migration cannot be completed immediately, the previous behaviour can 
be restored for the affected web
+application only:</p>
+
+<div class="language-xml highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code><span class="nt">&lt;constant</span> <span 
class="na">name=</span><span 
class="s">"struts.tiles.ognl.legacy.enabled"</span> <span 
class="na">value=</span><span class="s">"true"</span><span 
class="nt">/&gt;</span>
+</code></pre></div></div>
+
+<p>The constant is read from the Struts configuration of the web application 
that owns the Tiles container, on the
+first <code class="language-plaintext highlighter-rouge">OGNL:</code> 
evaluation, and a warning is logged once when the legacy evaluator is 
activated. Both the constant and
+the legacy evaluator are deprecated and will be removed in a future major 
release, so treat the constant as a
+migration aid rather than a configuration option.</p>
+
 <h2 id="example">Example</h2>
 
 <p>This example shows a Tiles layout page using Struts tags:</p>
@@ -315,6 +338,25 @@ you can use <code class="language-plaintext 
highlighter-rouge">I18N</code> prefi
 
 <p>This plugin does inherit settings from <a 
href="https://tiles.apache.org/framework/config-reference.html";>Tiles 
configuration</a>.</p>
 
+<table>
+  <thead>
+    <tr>
+      <th>Setting</th>
+      <th>Description</th>
+      <th>Default</th>
+      <th>Possible Values</th>
+    </tr>
+  </thead>
+  <tbody>
+    <tr>
+      <td>struts.tiles.ognl.legacy.enabled</td>
+      <td>Restores the legacy <code class="language-plaintext 
highlighter-rouge">OGNL</code> expression prefix, which evaluates without the 
Struts OGNL controls. Deprecated, see <a href="#legacy-ognl-expressions">Legacy 
OGNL expressions</a>.</td>
+      <td>false</td>
+      <td>true, false</td>
+    </tr>
+  </tbody>
+</table>
+
 <h2 id="installation">Installation</h2>
 
 <p>This plugin can be installed by copying the plugin jar into your 
application’s <code class="language-plaintext 
highlighter-rouge">/WEB-INF/lib</code> directory. 

Reply via email to