struts-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Greg Huber <gregh3...@gmail.com>
Subject lobal-allowed-methods
Date Mon, 14 Nov 2016 14:48:20 GMT
Although I have strict method switched on it allows me to call the save()
and delete() method on any class.

It seems that the one in struts-default adds these as a default:

<global-allowed-methods>execute,input,back,cancel,browse,save,delete,list,index</global-allowed-methods>

I can see why we want some, possibly only have methods that are required
for struts to function at a minimum.

<global-allowed-methods>execute</global-allowed-methods>

Mime
  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message