This is an automated email from the ASF dual-hosted git repository.
asf-gitbox-commits pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/struts-site.git
The following commit(s) were added to refs/heads/asf-staging by this push:
new 04293b408 Updates stage by Jenkins
04293b408 is described below
commit 04293b408fe94d0194e88eef688a40f474c2dfec
Author: jenkins <[email protected]>
AuthorDate: Thu Sep 17 05:11:01 2026 +0000
Updates stage by Jenkins
---
content/plugins/tiles/index.html | 42 ++++++++++++++++++++++++++++++++++++++++
1 file changed, 42 insertions(+)
diff --git a/content/plugins/tiles/index.html b/content/plugins/tiles/index.html
index a5dbe1781..620ec19b8 100644
--- a/content/plugins/tiles/index.html
+++ b/content/plugins/tiles/index.html
@@ -159,6 +159,7 @@
<li><a href="#usage" id="markdown-toc-usage">Usage</a> <ul>
<li><a href="#accessing-struts-attributes"
id="markdown-toc-accessing-struts-attributes">Accessing Struts
attributes</a></li>
<li><a href="#i18n" id="markdown-toc-i18n">I18N</a></li>
+ <li><a href="#legacy-ognl-expressions"
id="markdown-toc-legacy-ognl-expressions">Legacy OGNL expressions</a></li>
</ul>
</li>
<li><a href="#example" id="markdown-toc-example">Example</a></li>
@@ -290,6 +291,28 @@ you can use <code class="language-plaintext
highlighter-rouge">I18N</code> prefi
<span class="nt"></definition></span>
</code></pre></div></div>
+<h3 id="legacy-ognl-expressions">Legacy OGNL expressions</h3>
+
+<p>The plugin also registers the <code class="language-plaintext
highlighter-rouge">OGNL</code> prefix, which comes from Tiles itself. Unlike
<code class="language-plaintext highlighter-rouge">S2</code>, it evaluates the
expression
+against the Tiles request rather than the <code class="language-plaintext
highlighter-rouge">ValueStack</code>, and it does not pass through the Struts
OGNL controls — the
+member access policy, the allowlist and the expression guard that every other
OGNL evaluation in Struts goes through.</p>
+
+<p>As from Struts 7.4.0 the <code class="language-plaintext
highlighter-rouge">OGNL</code> prefix is disabled by default. Evaluating an
<code class="language-plaintext highlighter-rouge">OGNL:</code> expression
fails with an
+<code class="language-plaintext highlighter-rouge">EvaluationException</code>
explaining that the evaluator is disabled, so a definition that still relies on
it is reported
+instead of rendering incorrectly. Migrate such expressions to <code
class="language-plaintext highlighter-rouge">S2:</code>, which is evaluated by
Struts with the full set of OGNL
+controls, or to ordinary Tiles attributes.</p>
+
+<p>If a migration cannot be completed immediately, the previous behaviour can
be restored for the affected web
+application only:</p>
+
+<div class="language-xml highlighter-rouge"><div class="highlight"><pre
class="highlight"><code><span class="nt"><constant</span> <span
class="na">name=</span><span
class="s">"struts.tiles.ognl.legacy.enabled"</span> <span
class="na">value=</span><span class="s">"true"</span><span
class="nt">/></span>
+</code></pre></div></div>
+
+<p>The constant is read from the Struts configuration of the web application
that owns the Tiles container, on the
+first <code class="language-plaintext highlighter-rouge">OGNL:</code>
evaluation, and a warning is logged once when the legacy evaluator is
activated. Both the constant and
+the legacy evaluator are deprecated and will be removed in a future major
release, so treat the constant as a
+migration aid rather than a configuration option.</p>
+
<h2 id="example">Example</h2>
<p>This example shows a Tiles layout page using Struts tags:</p>
@@ -315,6 +338,25 @@ you can use <code class="language-plaintext
highlighter-rouge">I18N</code> prefi
<p>This plugin does inherit settings from <a
href="https://tiles.apache.org/framework/config-reference.html">Tiles
configuration</a>.</p>
+<table>
+ <thead>
+ <tr>
+ <th>Setting</th>
+ <th>Description</th>
+ <th>Default</th>
+ <th>Possible Values</th>
+ </tr>
+ </thead>
+ <tbody>
+ <tr>
+ <td>struts.tiles.ognl.legacy.enabled</td>
+ <td>Restores the legacy <code class="language-plaintext
highlighter-rouge">OGNL</code> expression prefix, which evaluates without the
Struts OGNL controls. Deprecated, see <a href="#legacy-ognl-expressions">Legacy
OGNL expressions</a>.</td>
+ <td>false</td>
+ <td>true, false</td>
+ </tr>
+ </tbody>
+</table>
+
<h2 id="installation">Installation</h2>
<p>This plugin can be installed by copying the plugin jar into your
application’s <code class="language-plaintext
highlighter-rouge">/WEB-INF/lib</code> directory.