This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/struts-site.git


The following commit(s) were added to refs/heads/asf-staging by this push:
     new 8e74fc67b6 Updates stage by Jenkins
8e74fc67b6 is described below

commit 8e74fc67b6153a40074a730ccae5432dd5ad9728
Author: jenkins <[email protected]>
AuthorDate: Sat Oct 10 10:48:18 2026 +0000

    Updates stage by Jenkins
---
 content/core-developers/alias-interceptor.html     | 45 ++++++++++++++++++++++
 content/core-developers/default-properties.html    |  6 +--
 .../struts-parameter-annotation.html               |  4 ++
 content/plugins/json/index.html                    | 43 +++++++++++++++++++++
 4 files changed, 95 insertions(+), 3 deletions(-)

diff --git a/content/core-developers/alias-interceptor.html 
b/content/core-developers/alias-interceptor.html
index 459a647440..9cf922b799 100644
--- a/content/core-developers/alias-interceptor.html
+++ b/content/core-developers/alias-interceptor.html
@@ -213,6 +213,51 @@ before <code class="language-plaintext 
highlighter-rouge">conversionError</code>
 
 <p>There is no <code class="language-plaintext 
highlighter-rouge">overwrite</code> flag on this interceptor; the ordering 
above is the supported way to get that behavior.</p>
 
+<h2 id="parameter-authorization">Parameter Authorization</h2>
+
+<p>The value this interceptor copies onto the alias target can come from two 
different places, and
+each is authorized differently:</p>
+
+<ul>
+  <li><strong>The source name does not resolve anywhere on the value 
stack</strong>, so the interceptor falls back
+to the raw HTTP request parameter of that name — the behavior the <code 
class="language-plaintext highlighter-rouge">foo</code>/<code 
class="language-plaintext highlighter-rouge">bar</code> example above
+relies on. This path requires <a href="struts-parameter-annotation.html"><code 
class="language-plaintext highlighter-rouge">@StrutsParameter</code></a> on the
+target when <code class="language-plaintext 
highlighter-rouge">struts.parameters.requireAnnotations</code> is enabled (the 
default since Struts 7.0.0),
+the same as the <a href="parameters-interceptor.html">Parameters 
Interceptor</a>.</li>
+  <li>
+    <p><strong>The source name resolves on the value stack</strong> — 
typically a property an earlier action in a
+chain already holds. Copying this is the same category of operation as the
+<a href="chaining-interceptor.html">Chaining Interceptor</a>, so it follows 
the same opt-in constant:</p>
+
+    <div class="language-xml highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code><span class="nt">&lt;constant</span> <span 
class="na">name=</span><span 
class="s">"struts.chaining.requireAnnotations"</span> <span 
class="na">value=</span><span class="s">"true"</span><span 
class="nt">/&gt;</span>
+</code></pre></div>    </div>
+
+    <p>With this off (the default), a stack-resolved value is copied 
regardless of annotation, matching
+this interceptor’s traditional behavior. With it on, an unannotated target is 
rejected here too,
+not just on the request-parameter fallback.</p>
+  </li>
+</ul>
+
+<p>In both cases a rejected target is skipped and logged at <code 
class="language-plaintext highlighter-rouge">WARN</code>, and authorization 
uses the same
+<code class="language-plaintext highlighter-rouge">ParameterAuthorizer</code> 
service the Parameters and Chaining interceptors use. While an application is
+migrating,
+<a href="../../security/#defining-and-annotating-your-action-parameters"><code 
class="language-plaintext 
highlighter-rouge">struts.parameters.requireAnnotations.transitionMode=true</code></a>
+exempts non-nested alias targets, the same way it exempts any other non-nested 
setter, on both paths
+above. Nested targets — an alias map value such as <code 
class="language-plaintext highlighter-rouge">'bean.bar'</code> is valid — still 
need the
+annotation. In a custom stack that places <code class="language-plaintext 
highlighter-rouge">alias</code> after <code class="language-plaintext 
highlighter-rouge">modelDriven</code>, a target on the model gets the
+same <a href="struts-parameter-annotation.html#modeldriven-actions"><code 
class="language-plaintext highlighter-rouge">ModelDriven</code></a> exemption 
as the Parameters
+Interceptor.</p>
+
+<p>See also <a 
href="struts-parameter-annotation.html#where-authorization-applies">Where 
authorization applies</a>
+for an overview of the channels that can populate an action.</p>
+
+<h3 id="upgrading-an-existing-application">Upgrading an existing 
application</h3>
+
+<p>If an application already uses this interceptor’s documented pattern — the 
<code class="language-plaintext highlighter-rouge">foo</code>/<code 
class="language-plaintext highlighter-rouge">bar</code> example
+above — <code class="language-plaintext highlighter-rouge">bar</code> now 
needs <a href="struts-parameter-annotation.html"><code 
class="language-plaintext highlighter-rouge">@StrutsParameter</code></a> for 
the alias to
+keep working with <code class="language-plaintext 
highlighter-rouge">struts.parameters.requireAnnotations</code> enabled (the 
default). Without it, the
+alias is skipped and logged at <code class="language-plaintext 
highlighter-rouge">WARN</code> instead of setting <code 
class="language-plaintext highlighter-rouge">bar</code>.</p>
+
 <h2 id="extending-the-interceptor">Extending the Interceptor</h2>
 
 <p>This interceptor does not have any known extension points.</p>
diff --git a/content/core-developers/default-properties.html 
b/content/core-developers/default-properties.html
index 3dd7b87e78..f650141efb 100644
--- a/content/core-developers/default-properties.html
+++ b/content/core-developers/default-properties.html
@@ -452,9 +452,9 @@ struts.parameters.requireAnnotations=true
 ### Useful for transitioning legacy applications, but highly recommended to 
set to false as soon as possible!
 struts.parameters.requireAnnotations.transitionMode=false
 
-### Whether ChainingInterceptor enforces @StrutsParameter on the target action 
when copying properties.
-### Opt-in hardening; default false preserves legacy chaining behaviour. Only 
has effect when
-### struts.parameters.requireAnnotations is also enabled.
+### Whether ChainingInterceptor and AliasInterceptor enforce @StrutsParameter 
on the target action when
+### copying a value already resolved on the stack. Opt-in hardening; default 
false preserves legacy
+### chaining/aliasing behaviour. Only has effect when 
struts.parameters.requireAnnotations is also enabled.
 struts.chaining.requireAnnotations=false
 
 ### Whether to throw a RuntimeException when a property is not found
diff --git a/content/core-developers/struts-parameter-annotation.html 
b/content/core-developers/struts-parameter-annotation.html
index 4cddbdeb55..fe0a3de5d2 100644
--- a/content/core-developers/struts-parameter-annotation.html
+++ b/content/core-developers/struts-parameter-annotation.html
@@ -190,6 +190,10 @@ channel that can populate an action from request data:</p>
 (default, governed by <code class="language-plaintext 
highlighter-rouge">struts.parameters.requireAnnotations</code>).</li>
   <li><a href="chaining-interceptor.html">Chaining Interceptor</a> — 
value-stack copying during
 action chaining (opt-in via <code class="language-plaintext 
highlighter-rouge">struts.chaining.requireAnnotations</code>).</li>
+  <li><a href="alias-interceptor.html">Alias Interceptor</a> — its 
raw-request-parameter fallback follows
+<code class="language-plaintext 
highlighter-rouge">struts.parameters.requireAnnotations</code> like the 
Parameters Interceptor; copying a value already
+resolved on the stack follows <code class="language-plaintext 
highlighter-rouge">struts.chaining.requireAnnotations</code> like the Chaining 
Interceptor
+(since Struts 7.5.0 — see <a 
href="alias-interceptor.html#parameter-authorization">Parameter 
Authorization</a>).</li>
   <li><a href="cookie-interceptor.html">Cookie Interceptor</a> — cookie 
values.</li>
   <li><a href="../../plugins/json">JSON</a> and <a 
href="../../plugins/rest">REST</a> plugins — per-property
 authorization performed during deserialization, so an unauthorized property is 
not set on
diff --git a/content/plugins/json/index.html b/content/plugins/json/index.html
index 148bd3f269..67e66cf4ca 100644
--- a/content/plugins/json/index.html
+++ b/content/plugins/json/index.html
@@ -167,6 +167,7 @@
       <li><a href="#base-classes" id="markdown-toc-base-classes">Base 
Classes</a></li>
       <li><a href="#enumerations" 
id="markdown-toc-enumerations">Enumerations</a></li>
       <li><a href="#java-records-and-optional" 
id="markdown-toc-java-records-and-optional">Java records and Optional</a></li>
+      <li><a href="#using-registered-type-converters" 
id="markdown-toc-using-registered-type-converters">Using registered type 
converters</a></li>
       <li><a href="#compressing-the-output" 
id="markdown-toc-compressing-the-output">Compressing the output</a></li>
       <li><a href="#preventing-the-browser-from-caching-the-response" 
id="markdown-toc-preventing-the-browser-from-caching-the-response">Preventing 
the browser from caching the response</a></li>
       <li><a href="#excluding-properties-with-null-values" 
id="markdown-toc-excluding-properties-with-null-values">Excluding properties 
with null values</a></li>
@@ -522,6 +523,48 @@ therefore subject to <code class="language-plaintext 
highlighter-rouge">excludeN
 <div class="language-json highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code><span class="p">{</span><span 
class="nl">"name"</span><span class="p">:</span><span class="w"> </span><span 
class="s2">"Alice"</span><span class="p">,</span><span class="w"> </span><span 
class="nl">"nickname"</span><span class="p">:</span><span class="w"> 
</span><span class="kc">null</span><span class="p">}</span><span class="w">
 </span></code></pre></div></div>
 
+<h3 id="using-registered-type-converters">Using registered type converters</h3>
+
+<blockquote>
+  <p>Since Struts 7.5.0</p>
+</blockquote>
+
+<p>A value type that has an <a 
href="../../core-developers/type-conversion.html#applying-a-type-converter-for-an-application">application-wide
 type converter</a>
+can be serialized with that converter instead of as a nested bean, so the JSON 
response shows the same string as
+the HTML view. This is off by default; enable it with a constant:</p>
+
+<div class="language-xml highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code><span class="nt">&lt;constant</span> <span 
class="na">name=</span><span 
class="s">"struts.json.writer.useTypeConverters"</span> <span 
class="na">value=</span><span class="s">"true"</span><span 
class="nt">/&gt;</span>
+</code></pre></div></div>
+
+<p>With a converter registered in <code class="language-plaintext 
highlighter-rouge">struts-conversion.properties</code>:</p>
+
+<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code>com.acme.Money = com.acme.MoneyConverter
+</code></pre></div></div>
+
+<p>a <code class="language-plaintext highlighter-rouge">Money</code> property 
is written as the string returned by the converter’s <code 
class="language-plaintext highlighter-rouge">convertToString()</code>:</p>
+
+<div class="language-json highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code><span class="p">{</span><span 
class="nl">"price"</span><span class="p">:</span><span class="w"> </span><span 
class="s2">"12.50 EUR"</span><span class="p">}</span><span class="w">
+</span></code></pre></div></div>
+
+<p>instead of:</p>
+
+<div class="language-json highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code><span class="p">{</span><span 
class="nl">"price"</span><span class="p">:</span><span class="w"> </span><span 
class="p">{</span><span class="nl">"amount"</span><span class="p">:</span><span 
class="w"> </span><span class="s2">"12.50"</span><span class="p">,</span><span 
class="w"> </span><span class="nl">"currency"</span><span 
class="p">:</span><span class="w"> </span><span class="s2">"EUR"</spa [...]
+</span></code></pre></div></div>
+
+<ul>
+  <li>Only converters registered <strong>per type</strong> are used — in <code 
class="language-plaintext 
highlighter-rouge">struts-conversion.properties</code> or with
+<code class="language-plaintext highlighter-rouge">@TypeConversion(type = 
ConversionType.APPLICATION)</code>. A converter registered for a superclass or 
an interface applies to its subtypes. Per-property
+mappings from <code class="language-plaintext 
highlighter-rouge">Foo-conversion.properties</code> are not used.</li>
+  <li>Types the plugin serializes natively are never converted: strings, 
numbers (including <code class="language-plaintext 
highlighter-rouge">BigDecimal</code>), booleans,
+characters, maps, collections, arrays, dates, <code class="language-plaintext 
highlighter-rouge">java.time</code> values, locales and enums. Use <code 
class="language-plaintext highlighter-rouge">@JSON(format)</code> or
+<code class="language-plaintext 
highlighter-rouge">struts.json.dateformat</code> for dates.</li>
+  <li>A <code class="language-plaintext 
highlighter-rouge">@JSONFieldBridge</code> on the property takes precedence 
over a registered converter.</li>
+  <li>If the converter throws or returns something other than a <code 
class="language-plaintext highlighter-rouge">String</code>, the value is 
serialized as a bean, as before.</li>
+  <li>A converted value is written as a single string, so <code 
class="language-plaintext highlighter-rouge">includeProperties</code> / <code 
class="language-plaintext highlighter-rouge">excludeProperties</code> patterns 
that point
+inside it, and <code class="language-plaintext highlighter-rouge">@JSON</code> 
annotations on its members, no longer apply to it. Make sure the converter’s 
output contains
+only what the response may expose.</li>
+</ul>
+
 <h3 id="compressing-the-output">Compressing the output</h3>
 
 <p>Set the <code class="language-plaintext 
highlighter-rouge">enableGZIP</code> attribute to true to gzip the generated 
json response. The request <strong>must</strong> include <code 
class="language-plaintext highlighter-rouge">gzip</code> 

Reply via email to