Package org.apache.struts2.ognl
Class SecurityMemberAccessConfig
java.lang.Object
org.apache.struts2.ognl.SecurityMemberAccessConfig
- All Implemented Interfaces:
Initializable
Holds the parsed OGNL security configuration for one container.
SecurityMemberAccess is a Scope.PROTOTYPE bean, constructed once per value stack and
again for each OGNL context. Parsing the roughly ninety configuration entries on every one of those
was the dominant cost identified by WW-5667. This bean is a Scope.SINGLETON, so the parsing
happens once per container and each SecurityMemberAccess merely copies immutable references.
Dev-mode is resolved in init() rather than in a setter, because the container iterates
getDeclaredMethods(), whose order the JDK leaves unspecified. If init() never runs,
the normal production exclusions stay in force, which fails closed.
- Since:
- Struts 7.4.0
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidinit()Use this method to initialise your bean, the whole dependency graph was already builtbooleanbooleanbooleanbooleanboolean
-
Constructor Details
-
SecurityMemberAccessConfig
public SecurityMemberAccessConfig()
-
-
Method Details
-
init
public void init()Description copied from interface:InitializableUse this method to initialise your bean, the whole dependency graph was already built- Specified by:
initin interfaceInitializable
-
isAllowStaticFieldAccess
public boolean isAllowStaticFieldAccess() -
getExcludedClasses
-
getExcludedPackageNamePatterns
-
getExcludedPackageNames
-
getExcludedPackageExemptClasses
-
isEnforceAllowlistEnabled
public boolean isEnforceAllowlistEnabled() -
getAllowlistClasses
-
getAllowlistPackageNames
-
getAllowlistPackageNamesUnion
-
isDisallowProxyObjectAccess
public boolean isDisallowProxyObjectAccess() -
isDisallowProxyMemberAccess
public boolean isDisallowProxyMemberAccess() -
isDisallowDefaultPackageAccess
public boolean isDisallowDefaultPackageAccess()
-