Kusal Kithul-Godage created WW-5268:
---------------------------------------
Summary: Add configuration option to exempt classes from OGNL
package exclusions
Key: WW-5268
URL: https://issues.apache.org/jira/browse/WW-5268
Project: Struts 2
Issue Type: Improvement
Components: Core
Reporter: Kusal Kithul-Godage
It is currently possible to exclude packages from OGNL evaluation using
`struts.excludedPackageNamePatterns` and `struts.excludedPackageNames`.
There may exist a scenario where you wish to have certain packages
excluded/blocklisted by default, but exempt specific classes from these
packages that have been assessed to be safe.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)