Repository navigation
WW-5326 Upgrade OGNL to 3.5.0-BETA8 and introduce StrutsContext - #1654
Draft
lukaszlenart wants to merge 15 commits into
Draft
lukaszlenart wants to merge 15 commits into
lukaszlenart wants to merge 15 commits into
Conversation
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…utsContext> Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…h StrutsContext Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… StrutsContext construction Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…sContext Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Tiles accessors are called by OGNL internal machinery with raw OgnlContext, not within a Struts evaluation context, so they cannot use StrutsContext. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…ader with license
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…Context SecurityMemberAccessArrayTargetTest and CdiSecurityMemberAccessProxyTest still built a raw OgnlContext via Ognl.createDefaultContext and no longer compiled against the typed SecurityMemberAccess. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Struts registers its accessors in the JVM-global OgnlRuntime, including the method accessor for Object.class, and they are now typed with StrutsContext. Ognl.getValue(expr, root) builds a raw OgnlContext, so the legacy evaluator failed with a ClassCastException in the accessors' bridge methods whenever struts.tiles.ognl.legacy.enabled=true. The evaluator now builds a StrutsContext with the same public-members-only access that Ognl.createDefaultContext uses, so its behaviour is unchanged. Any other code in the same application that calls OGNL with its own raw OgnlContext hits the same globally registered accessors and must switch to a StrutsContext. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
lukaszlenart
force-pushed
the
feat/ognl-3.5-upgrade
branch
from
October 6, 2026 15:28
b039dc5 to
a6c9f27
Compare
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Fixes WW-5326
Upgrades OGNL from 3.4.15 to 3.5.0-BETA8 and introduces
StrutsContext extends OgnlContext<StrutsContext>as the framework's own OGNL evaluation context. Targeted at Struts 8.0.0; the PR stays in draft until OGNL 3.5.0 is released as GA.Changes
OgnlContext<StrutsContext>(@since 8.0.0)SecurityMemberAccess, accessors, null handler, type converters) are parameterized with<StrutsContext>OgnlUtilandOgnlValueStackbuildnew StrutsContext(...)instead of callingOgnl.createDefaultContext()OgnlContext. The deprecated legacyOGNLAttributeEvaluatornow evaluates with aStrutsContextthat allows public members only, which is whatOgnl.createDefaultContextgave it beforenew StrutsContext(sma), includingSecurityMemberAccessArrayTargetTestand the CDI plugin'sCdiSecurityMemberAccessProxyTest, which landed onmainafter this branch was startedCompatibility (8.0.0 migration notes)
Struts registers its accessors in OGNL's JVM-global
OgnlRuntime, including the method accessor forObject.class, and they now take aStrutsContext. Code in the same application that evaluates OGNL with its own rawOgnlContext(Ognl.getValue(expr, root),Ognl.createDefaultContext(...)) reaches those accessors and fails with aClassCastException. Such code has to evaluate with aStrutsContextinstead. This is what broke the legacy Tiles evaluator, and why it changed.The same applies to a plain
OgnlContextpassed toOgnlUtil'sgetValue/setValue/setPropertymethods: Struts now expects theStrutsContextit creates itself.Custom
PropertyAccessor/MethodAccessor/MemberAccess/TypeConverterimplementations have to move to the generic OGNL 3.5 signatures.Related
StrutsParameterAuthorizerwith OGNL's accessor-name resolution, and WW-5760 (WW-5760 Upgrade OGNL to version 3.4.15 #1993, OGNL 3.4.15). BETA8 carries the same OGNL changes, and the tests from both pass on it.Design decisions
Ognl.withBuilderProvider(): Struts owns the context lifecycle, and no global provider is installed for other OGNL users in the JVMReflectionContextStatemap entries to typedStrutsContextfields is Phase 2Test plan
test-compileon the default and-Pjakartaee11profiles🤖 Generated with Claude Code