Class SecurityMemberAccessConfig

java.lang.Object
org.apache.struts2.ognl.SecurityMemberAccessConfig
All Implemented Interfaces:
Initializable

public class SecurityMemberAccessConfig extends Object implements Initializable
Holds the parsed OGNL security configuration for one container.

SecurityMemberAccess is a Scope.PROTOTYPE bean, constructed once per value stack and again for each OGNL context. Parsing the roughly ninety configuration entries on every one of those was the dominant cost identified by WW-5667. This bean is a Scope.SINGLETON, so the parsing happens once per container and each SecurityMemberAccess merely copies immutable references.

Dev-mode is resolved in init() rather than in a setter, because the container iterates getDeclaredMethods(), whose order the JDK leaves unspecified. If init() never runs, the normal production exclusions stay in force, which fails closed.

Since:
Struts 7.4.0
  • Constructor Details

    • SecurityMemberAccessConfig

      public SecurityMemberAccessConfig()
  • Method Details

    • init

      public void init()
      Description copied from interface: Initializable
      Use this method to initialise your bean, the whole dependency graph was already built
      Specified by:
      init in interface Initializable
    • isAllowStaticFieldAccess

      public boolean isAllowStaticFieldAccess()
    • getExcludedClasses

      public Set<String> getExcludedClasses()
    • getExcludedPackageNamePatterns

      public Set<Pattern> getExcludedPackageNamePatterns()
    • getExcludedPackageNames

      public Set<String> getExcludedPackageNames()
    • getExcludedPackageExemptClasses

      public Set<String> getExcludedPackageExemptClasses()
    • isEnforceAllowlistEnabled

      public boolean isEnforceAllowlistEnabled()
    • getAllowlistClasses

      public Set<Class<?>> getAllowlistClasses()
    • getAllowlistPackageNames

      public Set<String> getAllowlistPackageNames()
    • getAllowlistPackageNamesUnion

      public Set<String> getAllowlistPackageNamesUnion()
    • isDisallowProxyObjectAccess

      public boolean isDisallowProxyObjectAccess()
    • isDisallowProxyMemberAccess

      public boolean isDisallowProxyMemberAccess()
    • isDisallowDefaultPackageAccess

      public boolean isDisallowDefaultPackageAccess()